<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy Impact Assessments &#8211; Office of the Information and Privacy Commissioner of Alberta</title>
	<atom:link href="https://oipc.ab.ca/resources/privacy-impact-assessments/feed/" rel="self" type="application/rss+xml" />
	<link>https://oipc.ab.ca</link>
	<description>Office of the Information and Privacy Commissioner of Alberta</description>
	<lastBuildDate>Thu, 02 Jul 2026 15:43:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://oipc.ab.ca/wp-content/uploads/2022/01/cropped-OIPC-Icon-32x32.png</url>
	<title>Privacy Impact Assessments &#8211; Office of the Information and Privacy Commissioner of Alberta</title>
	<link>https://oipc.ab.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Privacy Impact Assessment (PIA) Template and Completion Guide (POPA)</title>
		<link>https://oipc.ab.ca/resource/popa-pia-template-completion-guide/</link>
		
		<dc:creator><![CDATA[Chris Stinner]]></dc:creator>
		<pubDate>Mon, 09 Mar 2026 12:55:24 +0000</pubDate>
				<guid isPermaLink="false">https://oipc.ab.ca/?post_type=resource&#038;p=17354</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>Section 26 of the <em>Protection of Privacy Act</em> (POPA) requires a public body to prepare a privacy impact assessment (PIA) in prescribed circumstances and, if required by the regulations, submit the PIA to the Information and Privacy Commissioner in accordance with the regulations. In addition, as part of the Commissioner’s responsibility to monitor how POPA is administered to ensure that its purposes are achieved, the Commissioner may, as described in section 27(1)(j) of POPA, request a copy of a public body’s PIA.</p>
<p>Section 7(1) of the <em>Protection of Privacy Act</em> (Ministerial) <em>Regulation</em> (M-Regulation) lists the circumstances in which a public body must prepare and submit a PIA to the Commissioner.</p>
<p>This <strong>POPA PIA Template Completion Guide</strong> (“Completion Guide”) is a companion document to the <a href="https://oipc.ab.ca/popa/pia/template/" target="_blank" rel="noopener">POPA PIA Template</a>. The aim of this Completion Guide is to assist public bodies in completing the POPA PIA Template. This Completion Guide provides explanation or clarification, where necessary, for each question asked in the POPA PIA Template and describes what is expected of the public body in each question. We recommend that you complete the POPA PIA Template while consulting this PIA Completion Guide.<br />
The term “<strong>project</strong>” when used in this document means any administrative practice, program or service, or a change to any existing administrative practice, program or service that a public body plans to implement, which will involve the collection, use or disclosure of personal information and which includes one or more of the factors listed in section 7(5)(a) to (e) of the M-Regulation.</p>
<p>If a public body is unsure whether it is required to <span style="text-decoration: underline;">complete</span> a PIA or <span style="text-decoration: underline;">complete and submit</span> a PIA to the Information and Privacy Commissioner, the public body should consider using the <a href="https://oipc.ab.ca/popa/pia/tool/" target="_blank" rel="noopener">PIA Submission Assessment Tool</a> to make that determination.</p>
<p><span style="color: #ff0000;"><strong>Please note that sections in the POPA PIA Template with an asterisk (*) are mandatory and must be completed.</strong> <strong>Any PIA that does not complete the mandatory sections, </strong><strong>will be deemed incomplete and will not be accepted for review by the OIPC.</strong></span></p>
<p>If you encounter issues while using the completion guide or have questions, please <a href="https://oipc.ab.ca/about-us/contact-us/" target="_blank" rel="noopener">contact us</a>.</p>
<p><span style="color: #ff0000;"><strong>Note: Public bodies <u>should not</u> submit this completion guide to the OIPC as part of their PIA submission.</strong></span></p>
<p>Given that section 26(1) of POPA requires a public body to prepare a PIA in prescribed circumstances and, if required by the regulations, submit it to the Commissioner in accordance with the regulations, the head of a public body is legally required to sign off on POPA PIAs. However, 55(1) of POPA authorizes the head of a public body to delegate to any person any power, duty or function of the head under the Act, except the power to delegate under this section. Section 55(2) requires that a delegation under subsection (1) be in writing and may contain any conditions or restrictions the head of the public body considers appropriate. To this end, the Designate of a public body may sign off on the public body’s PIA if that Designate has been delegated such a power. A copy of the delegation of power should be included with the PIA.</p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div style="border: 1px solid #ccc; padding: 15px; border-radius: 5px;">
<p><strong>Table of Contents</strong></p>
<ul>
<li><a href="#general-information-public-body-existing-pias-project">A. General Information About the Public Body or Bodies, Existing PIAs, and the Project*</a></li>
<li><a href="#project-details">B. Details About the Project*</a></li>
<li><a href="#privacy-management-program">C. Information About Your Privacy Management Program (PMP)*</a></li>
<li><a href="#personal-information-authority-collection-use-disclosure">D. Identify Personal Information Involved and Your Authority to Collect, Use or Disclose the Information*</a></li>
<li><a href="#access-correction-accuracy-retention-disposition">E. Access, Correction, Accuracy, Retention, Disposition*</a></li>
<li><a href="#protection-of-information">F. Protection of Information*</a></li>
<li><a href="#service-providers">G. Service Providers*</a></li>
<li><a href="#project-risk-assessment-mitigation">H. Project Risk Assessment and Mitigation*</a></li>
<li><a href="#appendix-a-data-matching">Appendix A. Data Matching</a></li>
<li><a href="#appendix-b-common-integrated-program-service">Appendix B. Common or Integrated Program or Service</a></li>
<li><a href="#appendix-c-automated-systems-innovative-technology">Appendix C. Use of Automated Systems or Other Forms of Innovative Technology</a></li>
<li><a href="#appendix-d-pia-cover-letter">Appendix D. PIA Cover Letter*</a></li>
<li><a href="#appendix-e-pia-submission-checklist">Appendix E. PIA Submission Checklist*</a></li>
</ul>
</div>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="general-information-public-body-existing-pias-project"></a></p>
<h3>A. General Information about the public body or bodies, existing PIAs, and the project *</h3>
<p><em>Questions in this section are asked as a legislative requirement and to enable the OIPC in processing the PIA file.</em></p>
<p><strong> Question 1</strong></p>
<p>Section 26 of POPA requires a public body to prepare a PIA in the circumstances listed in section 7 of the M-Regulation, when a project involves the collection, use or disclosure of personal information. If a public body is not collecting, using or disclosing personal information as part of its project, there is no requirement under POPA to submit a PIA to the Commissioner for the project.</p>
<p><strong> Question 2</strong></p>
<p>The legislation is clear on when a public body is required to prepare a PIA, and only in the prescribed circumstances as listed in the POPA PIA template is a public body required under POPA to submit a PIA to the OIPC. Please note that the list of highly sensitive information identified under section 1 of the M-Regulation is not an exhaustive list. Other personal information may be of high sensitivity.</p>
<p>In this question, if only the last checkbox (the loss of, unauthorized access to or unauthorized disclosure of the personal information could result in significant harm) is selected, the public body may not be required to submit a PIA to the Commissioner. Nonetheless, the OIPC recommends that public bodies use the POPA PIA template while preparing PIAs under section 7(1)(a) of the M-Regulation as the Commissioner may request copies of those PIAs under section 27(1)(j) of POPA. Using the template will ensure that the public bodies complete their PIAs in alignment with the PIA requirements under POPA and the M-Regulation of which the PIA template is based on.</p>
<p><strong> Question 3</strong><br />
When submitting a PIA to the OIPC as required under section 26 of POPA, the OIPC needs to know certain information about the public body including who the head of the public body is at the time the PIA is submitted. This is because under POPA the head has specified duties including for protection of personal information (section 10(1)).</p>
<p><strong> Question 4</strong><br />
Section 7(4)(b) of the M-Regulation allows for two or more public bodies to submit a PIA for a common or integrated program or service, hence the need to know if the PIA is for such a project.</p>
<p><strong> Question 5</strong><br />
No additional explanation needed.</p>
<p><strong> Question 6 </strong><br />
No additional explanation needed.</p>
<p><strong> Question 7</strong><br />
Sometimes, a new PIA is related to a PIA which has already been submitted to the OIPC and is still under review. In such cases, it is important that the OIPC is aware of this PIA to ensure the recent PIA is not reviewed in isolation from the related PIA. There are also times where information in an existing PIA is referenced in a new PIA. It is also important to know if such a PIA exists or has been previously reviewed by the OIPC.</p>
<p><strong> Question 8</strong></p>
<p>A PIA amendment addresses privacy and security risks associated with changes to an existing project that impacts the collection, use and/or disclosure of personal information. A PIA amendment focuses on areas that have changed in an existing project, and how the public body has identified and addressed privacy and security risks associated with the change. An amendment to a previously submitted PIA requires that the updated or new PIA is reviewed in consultation with the previously submitted PIA.</p>
<p><strong>Question 9</strong><br />
Some public bodies have their own filing convention for their internal use. Providing this number ensures the OIPC, in addition to the OIPC’s file number, references this number in its communication with the public body.</p>
<p><strong>Question 10</strong></p>
<p>This informs the OIPC whether the project under consideration has been implemented or not.</p>
<p><strong>Question 11</strong><br />
This question aims to inform the public body which sections of the appendices to the POPA PIA template are relevant to their project as well as relevant resource expertise needed to assist the public body in completing the technical aspect of the PIA. The question also informs the OIPC what to consider regarding legislative requirements during the PIA review process as different projects may have unique compliance privacy and security issues to consider.</p>
<p>For projects that involve automated systems, section 7(3) of the M-Regulation states that a PIA must provide a level of detail commensurate with the complexity of the practice, program, project or service the PIA relates to. As such, the public body is required to also complete an Algorithm Impact Assessment (AIA). AIA is a tool used for identifying and addressing the risks and impacts of automated decision-making systems. Typically comprising of a set of questionnaires, the tool can be used to determine the impact level of an automated decision-making system including biases, human rights violations, ethical violations, marginalization and accessibility issues. The OIPC is in the process of developing an AIA tool. Once completed, it will be published on the <a href="https://oipc.ab.ca/">https://oipc.ab.ca</a> and a link to it will be added to the POPA PIA Template and this document. In the interim, the OIPC recommends that where a project involves automated systems, public bodies consult industry standard algorithm impact assessment guidelines in preparing and submitting their AIAs with their PIAs.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="project-details"></a></p>
<h3>B. Details About the Project*</h3>
<p><strong>Question 12</strong><br />
This information assists the OIPC in understanding the project, its business rationale and the purpose or objective it intends to achieve for the public body. This question also informs the OIPC on why the collection, use and/or disclosure of personal information is required by the public body to meet the needs of the project. It is imperative that the public body provides sufficient detail on the project. In addition, in this question, the public body is required to provide technical information about the project under consideration. For instance, if the public body is a police agency implementing a body worn camera (BWC), the public body is expected to describe each body worn camera unit, its associated features and IT infrastructure that operates the BWC. Also, information on BWC storage media, how information is transferred from the camera to the IT network, where information is stored and who is responsible for managing the information, etc. must be provided. In other words, the entire lifecycle of the personal information involved must be addressed in all aspects of the project. The public body should also consider attaching technical details of the project as necessary.</p>
<p><strong>Question 13</strong></p>
<p>An electronic information system has specific technical requirements, such as logging and auditing, access controls, that need to be considered and assessed to ensure the access and privacy rights of Albertans are upheld, which is why we need this information.</p>
<p><strong>Question 14</strong></p>
<p>Other stakeholders’ involvement in a project may determine who is collecting, using or disclosing personal information in the project and as a result shed some light on how the public body ought to consider the legal authority for each stakeholder to collect, use and/or disclose personal information involved in the project.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="privacy-management-program"></a></p>
<h3>C. Information About Your Privacy Management Program (PMP)*</h3>
<p><strong>Question 15</strong></p>
<p>Section 25(1) of POPA requires a public body to establish and implement a PMP and make it public or provide a copy of the PMP upon request pursuant to section 25(5). These requirements will come into effect on June 11, 2026. The public body’s policies and procedures must comply with the requirements of POPA and its regulations. The OIPC has developed guidance to assist public bodies in meeting their PMP obligations under POPA.</p>
<p>Not having a PMP leaves a gap in the completion of the PIA. This could potentially lead to non-compliance. It is important to provide the OIPC PMP file number of the public body’s most current PMP where applicable, as doing so saves the public body time and effort by referencing the already submitted PMP and avoids duplication. Also from a PIA review standpoint, it is relevant to review the PIA to assess the public body’s compliance with applicable legislation.</p>
<p><strong>For more information on PMPs please see the OIPC’s <a href="/popa/pmp/guide/" target="_blank" rel="noopener">Guidance for Public Bodies in Developing Privacy Management Programs</a>.</strong></p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="personal-information-authority-collection-use-disclosure"></a></p>
<h3>D. Identify Personal Information Involved and your Authority to Collect, Use or Disclose the Information*</h3>
<p><strong>Question 16</strong></p>
<p>This question ensures that the public body identifies the personal information that it intends to collect, use or disclose in the project. In doing so, the public body would have to start thinking about its legal authority to collect, use or disclose personal information and whether those authorities align with sections 4, 12 and 13 of POPA, respectively. In addition, the public body is required to consider the limitation principle under sections 12(4) and 13(4) of POPA. Under section 12(4) the public body needs to explain how the use of personal information in the project is <strong>only to the extent necessary</strong> to enable the public body to carry out its identified purposes in a <strong>reasonable manner</strong><em>. </em>Similarly, under section 13(4) of POPA, the public body needs to explain how the public body public disclosure of personal information is <strong>only to the extent necessary</strong> to enable the public body to carry out its identified purposes in <strong>a reasonable manner</strong>. Personal information means recorded information about an identifiable individual. Some examples of personal information include an individual’s name, home or business address, home or business email address, race, gender identity, fingerprints and financial history. For a complete listing of what is considered personal information, please see <strong>section 1(q) of POPA.</strong></p>
<p><strong>Question 17</strong><br />
Section 5 of POPA provides for the manner of collection of personal information. It is important that the collection of personal information for this project meets the requirements of section 5 of POPA. In this question, the public body needs to consider and explain how section 5(2) of POPA is complied with in this project if personal information is collected directly from the individuals who are the subjects of the information, including when and how a collection notice is provided to those individuals. In particular, the public body needs to explain whether section 5(2) of POPA applies to its project and how the public body complies with it.</p>
<p><strong>Question 18 </strong><br />
While there are legal authorities for public bodies in POPA to use or disclose personal information, there are situations where a public body may rely on individuals’ consent to use or disclose their personal information. Such consent must meet the prescribed requirements of section 2 of the Protection of Privacy Regulation (“the Regulation”). That is, the consent process for the project needs to clearly explain whether consent is obtained electronically or manually. Where consent is collected electronically, the public body should state how individuals give their consent. While a consent form is the implementation of the above consent requirements, public bodies need to have policies and procedures in place to collect and manage consent.</p>
<p><strong>Question 19 </strong><br />
There are circumstances where personal information can be collected indirectly, which means the collection comes from a source that is not the person whom the information is about. If that is the case in this project, this question gives the public body the opportunity to describe why, and how personal information is collected indirectly.</p>
<p><strong>Question 20</strong> – An information flow diagram is not the same as a business flow or a network diagram. An information flow diagram identifies the flow of specific pieces of information from one entity to another and when the entities involved are collecting, using or disclosing the information in question. It has arrows indicating the direction of flow of information between the entities. In some cases, information flow could be bi-directional between two entities. The information flows help in identifying the legal authority for collecting, using or disclosing personal information by each entity involved in the flow of the information. A network diagram depicts an IT network infrastructure or network segment and its associated components which may include, servers, routers, firewalls, databases, etc. A business flow diagram is a step-by-step process on how a specific business task is accomplished.</p>
<p><strong>Question 21 </strong><br />
No additional explanation needed.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="access-correction-accuracy-retention-disposition"></a></p>
<h3>E. Access, Correction, Accuracy, Retention, Disposition*</h3>
<p><strong>Question 22</strong></p>
<p>This question is asked to remind a public body to ensure it takes steps to make individuals aware of their rights to request access to their personal information that is in the custody or under the control of the public body. Usually, public bodies should be transparent by making their access to information request processes public, with specific contact information of a person or business unit that handles access to information requests. In certain circumstances, public bodies should make proactive disclosure to minimize the number of access requests they get.</p>
<p><strong>Question 23</strong><br />
While this may be addressed as part of the PMP, public bodies are required to have access request policies in place to ensure that Albertans can exercise their rights to access their information. Such a policy governs how a public body implements its access to personal information processes to ensure consistency in processing such requests.</p>
<p><strong>Question 24</strong></p>
<p>This question is asked to ensure a public body has established a process to make individuals aware of their right to request correction to their personal information involved in the project. Usually, public bodies should be transparent by making their correction to personal information request processes public with specific contact information of a person or business unit that handles correction requests.</p>
<p><strong>Question 25</strong></p>
<p>While this may be addressed as part of the PMP, public bodies are required to have correction request policies in place that govern how Albertans can exercise their rights to correct their personal information and to ensure consistency in processing such requests.</p>
<p><strong>Question 26</strong></p>
<p>Public bodies have an obligation to make every reasonable effort to ensure that information about individuals that the public body relies on to make decisions that affect those individuals is accurate and complete.</p>
<p><strong>Question 27</strong></p>
<p>It is important to understand how the public body complies with section 6(b) of POPA for this project by ensuring that there exists a retention and disposition policy for information used in this project to govern how long personal information must be retained.</p>
<p><strong>Question 28</strong></p>
<p>Implementing record retention and disposition policies into information systems ensures that information that has reached its retention period is automatically flagged by the system for disposition instead of it being a manual process that is prone to inconsistencies and human errors resulting in information being retained past its retention period. Information held longer than its retention period poses a risk of loss, unauthorized access, or unauthorized disclosure.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="protection-of-information"></a></p>
<h3>F. Protection of Information*</h3>
<p><strong>Question 29 </strong><br />
Information security classification means assigning security levels to information that are based on the sensitivity of the information in question. Classifying the information based on the public body’s information classification standard assists the public body to protect the information by implementing security controls that are proportionate to the classification levels of the information. Each public body is required to implement an information security classification system to assist the public body to classify information that it collects, uses or discloses as required under section 2(1) of the M-Regulation.<span style="color: #ff0000;"> Public bodies must meet this requirement before submitting their PIAs to the Commissioner for review.</span></p>
<p><strong>Question 30</strong><br />
The “reasonable security arrangements” standard set out in section 10(1) of POPA are determined by the security classification of the personal information involved in the project. If the security classification is high, then the security measures, i.e., the administrative, technical and physical safeguards, must be correspondingly high. Whereas, if the security classification is low, then fewer measures may suffice to meet the standard. <span style="color: #ff0000;">Section 6(2(b) of the M-Regulation requires public bodies having custody or control of a high volume of personal information or highly sensitive personal information to have documented safeguards</span>. POPA does not stipulate a threshold for “high volume” or “significant percentage of the population”. The interpretation of this section of the M-Regulation is contextual in relation to the project. Although Section 1 of the M-Regulation deems certain personal information to be highly sensitive (biometric and financial information, and personal information of minors and seniors), this list is not an exhaustive or exclusive list. Other types of personal information may be deemed to be highly sensitive in specific contexts.</p>
<ol>
<li>Administrative safeguards govern the implementation of other protective measures and ensures that such measures are implemented consistently during the life cycle of the project. Consistent implementation of protective measures reduces vulnerabilities usually caused by lack of good security governance.</li>
<li>No additional explanation needed.</li>
<li>The technical safeguards should directly protect the information involved in the project, not just the general technical safeguards implemented by the public body. For instance, access controls should be specific for the project and describe how such controls ensure only authorized individuals have the right level of access to information involved in the project. In addition, any security assessments results such as vulnerability assessment and penetration tests conducted specific to the project should be included as part of the public body’s PIA submission, as such results provide additional information on risks that were identified and how they were resolved as part of the project implementation.</li>
</ol>
<p><strong>Question 31</strong><br />
Continuous assessment and monitoring of safeguards assists the public body in ensuring that the safeguards are working as expected. For instance, employees should be required to take refresher trainings on privacy and security. Also, monitoring controls such as intrusion detection and prevention systems should be implemented.</p>
<p><strong>Question 32 </strong><br />
Section 6(1)(b) of the M-Regulation requires public bodies to establish policies and procedures that ensures they comply with the public body’s obligations under POPA such as responding to incidents (unauthorized access to, unauthorized disclosure of or loss of personal information). Section 6(1)(d) of the M-Regulation also requires public bodies to train their employees about the employee’s obligations under POPA. As part of that training, public bodies should make their employees aware of their obligations under POPA, which includes notifying the public body of incidents under section 10(2) of POPA.</p>
<p><strong>Question 33 </strong><br />
Access control policies ensure that access to the Electronic Information System (EIS) is consistently managed, including requests to access the EIS, account provisioning and revocation of account when an employee no longer needs access to the EIS. Through enforceable access control policies, a public body will be able to ensure that an employee only gains access to the information they require to perform their job functions.</p>
<p><span style="color: #ff0000;">If the project involves a high volume of personal information or highly sensitive personal information, a documented access control policy must be attached to the PIA submission.</span> POPA does not stipulate a threshold for “high volume” or “significant percentage of the population”. The interpretation of this section of the M-Regulation is contextual in relation to the project. Although Section 1 of the M-Regulation deems certain personal information to be highly sensitive (biometric and financial information, and personal information of minors and seniors), this list is not an exhaustive or exclusive list. Other types of personal information may be deemed to be highly sensitive in specific contexts.</p>
<p><strong>Question 34</strong><br />
Having an access requests process for the EIS ensures access requests are submitted by appropriate business heads for approval by the appropriate authority prior to processing and account provisioning. Each request should identify the permission level for employees requiring access and ensure the permission level gives the employee only the right access required for the specific job tasks.</p>
<p><strong>Question 35</strong><br />
All access requests to the EIS must be approved by the appropriate level of management, to ensure that employees who access the EIS are authorized to do so.</p>
<p><strong>Question 36 </strong><br />
It is important to ensure that access to the EIS is revoked in a timely manner when employees no longer need such access, to prevent potential unauthorized access to personal information. It is also to ensure dormant accounts are removed from the system, as such accounts pose security risks.</p>
<p><strong>Question 37</strong><br />
The access control table provides clarification on the access privileges of the users of the system including the kind of actions each user can take and what information the user can access, and how the permission limits users only to the information they need to perform their job tasks or functions. The public body’s information technology (IT) department plays a significant role in implementing access controls in systems and will be a good resource for assisting in completing this table.</p>
<p><strong>Question 38</strong><br />
Logging and auditing policies ensure that information systems are built and implemented to capture audit logs of activities that are occurring within the system, including unauthorized activities listed under section 10(2) of POPA. Such a policy also ensures proactive auditing of information systems to detect and manage incidents defined under section 10(2) of POPA.</p>
<p><span style="color: #ff0000;">If the project involves a high volume of personal information or highly sensitive personal information, a documented auditing and logging policy must be attached to the PIA submission.</span> POPA does not stipulate a threshold for “high volume” or “significant percentage of the population”. The interpretation of this section of the M-Regulation is contextual in relation to the project. Although Section 1 of the M-Regulation deems certain personal information to be highly sensitive (biometric and financial information, and personal information of minors and seniors), this list is not an exhaustive or exclusive list. Other types of personal information may be deemed to be highly sensitive in specific contexts.</p>
<p><strong>Question 39</strong><br />
Being able to capture and maintain audit logs of personal information means that the public body can identify and investigate unauthorized access to, unauthorized disclosure of, or loss of personal information in order to meet its obligations under section 10(2) and (3) of POPA and sections 4(3), (4) and (5) of the M-Regulation.</p>
<p><strong>Question 40</strong><br />
Proactive auditing is a way of monitoring access to an EIS to detect and respond to potential unauthorized access to, unauthorized disclosure of, or loss of personal information.</p>
<p><strong>Question 41</strong><br />
No additional explanation needed.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="service-providers"></a></p>
<h3>G. Service Providers*</h3>
<p><strong>Question 42 </strong><br />
Given that service providers, which includes corporations, are considered employees under section 1(h) of POPA, a public body is accountable for the service provider’s compliance with POPA. Therefore, it is important for the public body to consider privacy issues that may involve the service provider’s role in relation to any personal information it may collect, use, disclose or access as an “employee” of the public body.</p>
<p><strong>Question 43</strong><br />
If a service provider will have access to personal information as part of providing its services to the public body or if it will collect, use or disclose personal information on behalf of the public body, the public body must ensure it complies with POPA as it relates to these activities. Therefore, the contract with the public body must address all related compliance issues such that through the implementation of the terms of the contract agreed to between the public body and the service provider, the public body has confidence that the service provider will comply with POPA in providing its services concerning any personal information involved in service delivery. A service provider must also protect the personal information it has in its custody, or that it is otherwise responsible for, according to the terms of the contract which must ensure compliance with section 10(1) of POPA, i.e., the security of the personal information must at minimum align with the public body’s security safeguards for this type of information. The agreement must also set out how the service provider interacts with the public body’s privacy management program. Without an agreement that addresses all these compliance related issues, there is a risk of non-compliance by the public body as a result of the activities of its service provider. Consequently, as part of the PIA review, any agreement entered into with a service provider must be reviewed by our office as part of the PIA review process. This is because the service provider agreement plays a central role in determining whether the service provider-employee is positioned within the terms of the contract to comply with POPA.<span style="color: #ff0000;"> <strong>Submitting a copy of the agreement with your PIA is a mandatory requirement</strong>.</span></p>
<p>Section 7(6) of the M-Regulation provides that where a public body is required under POPA or the Regulation, to enter into an agreement relating to the practice, program, project or service the PIA relates to, the portions of the agreement relating to the protection of privacy must be submitted to the Commissioner together with the PIA. Under section 1(1)(h) of POPA, an “employee” includes those providing a service to the public body “under contract.” The contract with the service provider would demonstrate the public body’s authority under POPA to share personal information with the service provider or otherwise permit it to collect, use or disclose personal information on its behalf. Therefore, it is an essential part of the PIA submission.</p>
<p><strong>Question 44</strong><br />
A public body may delegate responding to access to information request responsibility to its service provider. However, the public body must ensure that its contractual agreement with the service provider adequately addresses access to information request processing and describe how the service will be provided to the public body.</p>
<p><strong>Question 45<br />
</strong>To ensure the public body is able to meet its obligations under POPA the public body must ensure it maintains control of the personal information involved in the project where this information is collected or accessible by the service provider. This is required to ensure the personal information remains subject to POPA and the <em>Access to Information Act</em> (ATIA) to preserve the rights of individuals concerning their personal information under these Acts. Failure to retain control of the personal information amounts to a disclosure, which is prohibited under POPA without authority for said disclosure. This means, that there is a high likelihood of a breach if a public body fails to retain control of personal information in an agreement and provides personal information to the service provider for the services. For this question, if the public body’s answer is yes, the public body must identify specific sections of its contract with the service provider that ensures the public body maintains control of the information for the project. <span style="color: #ff0000;"><strong>Public</strong> <strong>bodies must meet this requirement before submitting their PIAs to the Commissioner for review.</strong></span></p>
<p><strong>Question 46</strong><br />
For this question, refer to the information set out in the commentary above for Question 43.</p>
<p><strong>Question 47</strong><br />
Service providers are considered employees of the public body and should have appropriate training prior to accessing personal information and continue to have refresher training for the duration of their contract. Section 6(1)(d) of the M-Regulation.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="project-risk-assessment-mitigation"></a></p>
<h3>H. Project Risk Assessment and Mitigation*</h3>
<p>This section of the PIA template requires public bodies to identify the project’s privacy and security risks and associated administrative, technical and physical safeguards that address these risks. This completion guide provides some <strong>example descriptions</strong> of the types of risks identified in the POPA PIA Template risk table.</p>
<p><strong>Question 48</strong><br />
Conducting security vulnerability assessments (VA) during the implementation of an information system that processes identifying information ensures exploitable security vulnerabilities or weaknesses are identified, prioritized and addressed in a timely manner<strong>.</strong> A penetration test (pentest) is performed to test if security controls are working as expected. VA and pentest are part of an overall risk management strategy and should be conducted periodically. Other security assessments can also be conducted and included in the PIA. Providing copies of these assessments with your PIA goes on to demonstrate the public body’s commitment to protect personal information pursuant to section 10 of POPA.</p>
<p><strong>H1. General Risks (to be completed for all PIA submissions) *</strong></p>
<p><strong>Risk 1</strong><br />
E.g., personal information is collected by the public body and/or the information system is configured to accept personal information that does not relate directly to and is necessary for the project. Systems built for the global market have default configurations that allow for the collection of vast amounts of personal information. Such systems should be hardened by disabling data fields that are not required for specific project implementations to manage the risk of over collection.</p>
<p><strong>Risk 2</strong><br />
E.g., information that was collected for this project is used for a purpose not directly related to the project, contrary to section 12 of POPA.</p>
<p><strong>Risk 3</strong><br />
E.g., information that was collected for this project is disclosed contrary to section 13 of POPA. Personal information could be intercepted while in transit due to lack of appropriate security control, leading to unauthorized disclosure. There are also situations where the public body or its employees disclose personal information for secondary purposes without legal authority. Unauthorized disclosure could also be via insecure disposal of information processing media.</p>
<p><strong>Risk 4</strong><br />
E.g., information collected for this project is accessed by unauthorized users or malicious software due to lack of reasonable safeguards, contrary to section 10(1) of POPA.</p>
<p><strong>Risk 5</strong><br />
E.g., information collected for this project is lost as a result of human error or malicious software attacks, such as ransomware, which renders information inaccessible. This may lead to the inability of the public body to perform its business functions or respond to requests from individuals to access their information. Disgruntled employees can also deliberately destroy personal information. Also, changes to IT systems without proper IT change management process and lack of disaster recovery strategy could lead to loss of information.</p>
<p><strong>Risk 6</strong><br />
E.g., A public body loses control of electronic and/or paper-based information as a result of insufficient or absence of contractual agreements with a third-party service provider. Loss of custody may involve the theft of paper records or a server that contains personal information in the public body’s premises.</p>
<p><strong>Risk 7</strong><br />
E.g., information collected for this project is inadvertently or maliciously destroyed contrary to POPA and the policies of the public body, such that the public body is unable to respond to access to information requests or carry out its business functions. Lack of an enforceable record retention and disposition policy could also lead to unauthorized destruction.</p>
<p><strong>Risk 8</strong><br />
E.g., information collected for this project is rendered inaccurate, or incomplete, contrary to section 6(a) of POPA. This may occur if employees are not adequately trained on good data entry practices or if system changes do not follow industry standard change management processes or information is not reasonably protected from unauthorized modification.</p>
<p><strong>Risk 9</strong><br />
E.g., personal information collected for this project is retained contrary to section 6(b) of POPA or the project retention procedures as established by the public body (section 7(2)(f) of the M-Regulation). In some cases, this may be a consequence of the absence of a record retention policy or lack of enforcement of an existing record retention policy.</p>
<p><strong>Risk 10</strong><br />
E.g., individuals’ information is collected for this project without providing proper notice at the time of collection, contrary to section 5(2) of POPA. Notice fails to align with the manner of collection and the requirement of POPA such as collecting personal information directly from individuals by telephone but providing notice via the public body’s website.</p>
<p><strong>Risk 11</strong><br />
E.g., the public body fails to make individuals aware of their rights to request access to or correction of their personal information, and how to make such requests.</p>
<p><strong>Risk 12</strong><br />
E.g., lack of or inadequate privacy breach management means that privacy breaches will not be consistently detected and managed. In addition, affected individuals of privacy breaches/incidents, the Commissioner and the Minister will not be notified in a timely manner as required under section 10(2) of POPA.</p>
<p><strong>Risk 13</strong><br />
E.g. without assessing third parties’ controls, the public body is unable to attest whether the third party reasonably protects personal information in respect of the services provided to the public body in compliance with POPA and its regulations. As a result, the public body could fail to meet its obligations to protect personal information under section 10 of POPA.</p>
<p><strong>Risk 14</strong><br />
E.g. personal information collected for this project for purposes under section 12 of POPA is being used for secondary purposes (e.g. to train artificial intelligence (AI) or by the third party for quality improvement purposes) without authority.</p>
<p><strong>Risk 15 </strong><br />
E.g., inadequate or absence of logging capabilities of systems limits the ability of the public body to identify and manage privacy breaches of personal information. In addition, it limits the Commissioner’s ability to investigate access to personal information violations including investigating potential offences under section 60 of POPA.</p>
<p><strong>Risk 16</strong><br />
E.g., failure to have human oversight and validation measures for information systems could potentially lead to data accuracy and reliability issues.</p>
<p><strong>Risk 17</strong><br />
Failing to conduct a security vulnerability assessment means that the public body may not be aware of exploitable security vulnerabilities that exists in its environment and as a result, would not take steps to address those security vulnerabilities in a timely manner thereby exposing personal information to potential compromise.</p>
<p><strong>H2. Risks Associated with Cloud Computing</strong></p>
<p><strong>Risk 1</strong><br />
E.g. In a multitenant cloud environment, compromise of one environment could lead to the compromise of other environments due to inappropriate segregation and isolation of cloud resources. In addition, there could potentially be information leakage between environments leading to unauthorized disclosure of personal information.</p>
<p><strong>Risk 2 </strong><br />
E.g., lack of formalized contractual arrangements that specifically consider POPA requirements could lead to loss of custody and/or control of personal information stored in the cloud environment as well as gaps in security management and non-compliance with POPA.</p>
<p><strong>Risk 3</strong><br />
E.g. the absence of clear and good governance on privacy and security of personal information could result in gaps in privacy and security management leading to non-compliance with POPA.</p>
<p><strong>Risk 4</strong><br />
E.g., POPA requirements including privacy breach management is not addressed in the contractual agreement between the public body and the cloud provider, which could lead to non-compliance with section 10(2) of POPA.</p>
<p><strong>Risk 5</strong><br />
E.g. a cloud provider goes out of business or declares bankruptcy, making it impossible for the public body to access personal information in the provider’s environment.</p>
<p><strong>Risk 6</strong><br />
E.g., a cloud provider uses proprietary technologies, making it difficult for the public body to migrate services to another provider, locking-in the public body. A public body may want to change provider if the existing provider suffers multiple security incidents that have caused privacy breaches.</p>
<p><strong>Risk 7</strong><br />
E.g., the USA PATRIOT Act and Cloud Act allow the US government to access personal information held by US-based companies in the US (USA PATRIOT Act) and anywhere in the world (Cloud Act).</p>
<p><strong>Risk 8</strong><br />
E.g., a cloud provider uses personal information for their own purposes, such as de-identifying personal information and/or using the personal information for training their AI models.</p>
<p><strong>Risk 9</strong><br />
E.g., the cloud provider sells personal information or fails to securely sanitize information processing media prior to re-use or disposition leading to unauthorized disclosure of the personal information.</p>
<p><strong>Risk 10</strong><br />
E.g. lack of reasonable authentication and authorization controls such as failures to implement and enforce multifactor authentication could potentially lead to unauthorized access to personal information.</p>
<p><strong>Risk 11</strong><br />
E.g. weak or lack of encryption could lead to unauthorized access to and disclosure of personal information in transit and at rest.</p>
<p><strong>H3. </strong><strong>Risks Associated with Research</strong></p>
<p><strong>Risk 1</strong><br />
E.g., the public body fails to assess whether non-identifying data can be used to accomplish the research purpose prior to disclosing individually identifying personal information or has not obtained the Commissioner’s approval for such disclosure as required under section 15(a) of POPA.</p>
<p><strong>Risk 2 </strong><br />
E.g., the public body fails to perform a public interest analysis prior to disclosing personal information for research or statistical purposes where the information is involved in data matching.</p>
<p><strong>Risk 3</strong><br />
E.g. the public body fails to conduct an assessment of risk of harm prior to disclosing personal information for research or statistical purposes where the information is involved in data matching.</p>
<p><strong>Risk 4</strong><br />
E.g., the public body has not approved conditions relating to security and confidentiality, the removal or destruction of individual identifiers and prohibition of subsequent use or disclosure of the information without express authorization of the public body.</p>
<p><strong>Risk 5 </strong><br />
E.g., a research agreement has not been signed prior to the public body disclosing personal information or the research agreement in place does not meet the requirements of section 15(d) of POPA and section 4 of the Regulation.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="appendix-a-data-matching"></a></p>
<h3>Appendix A. Data Matching</h3>
<p><em>Only complete this section if the project involves data matching as defined under section 1(f) of POPA.</em></p>
<p><strong>Question 1</strong><br />
No additional explanation needed.</p>
<p><strong>Question 2</strong><br />
There are specific circumstances in which a public body may <em>c</em>arry out data matching as listed in section 17(1) of POPA. Any prescribed purposes will be found in the regulation otherwise such a purpose does not exist.</p>
<p><strong>Question 3</strong><br />
No additional explanation needed.</p>
<p><strong>Question 4</strong><br />
Prior to collecting personal information from another public body for the purpose of data matching, a public body must first create a governance structure that clearly identifies the responsibilities and accountability of each public body involved in carrying out the data matching to ensure access and privacy rights of Albertans are protected. The governance structure must clearly identify the responsibilities and accountability of each public body as it relates to:</p>
<ol>
<li>the custody and control of personal information,</li>
<li>the correction of errors or omissions in an individual’s personal information,</li>
<li>breach notifications, and</li>
<li>other duties imposed by the Act.</li>
</ol>
<p><span style="color: #ff0000;">Public bodies must meet this requirement before submitting their PIAs to the Commissioner for review.</span></p>
<p><strong>Question 5</strong> – The data matching agreement is required to ensure clarity regarding the roles and responsibilities of each public body involved in the data matching project as well as legislative compliance. The minimum requirements of the agreement are as follows:</p>
<p>the agreement must:</p>
<ol>
<li>identify</li>
</ol>
<p>(i) the authority under which the public body will carry out data matching, and</p>
<p>(ii) the purpose for which the public body will carry out data matching,</p>
<ol>
<li>identify each public body’s role and how each public body’s role relates to the purpose of the data matching to which the addendum relates,</li>
<li>describe how the personal information will be securely transmitted, matched or linked by the public bodies,</li>
<li>identify whether the data derived from the personal information used for data matching will be disclosed to the public body from whom the personal information was collected,</li>
<li>identify each public body’s responsibilities respecting reasonable security arrangements, including respecting administrative safeguards, physical safeguards and technical safeguards, for the protection of personal information against such risks as unauthorized access, collection, use, disclosure or destruction, and</li>
<li>establish a clear governance structure respecting the responsibilities and accountability of each public body.</li>
</ol>
<p><strong>Question 6</strong></p>
<p>This question requires that a public body participating in data matching identifies collections, uses or disclosures of personal information that only apply to that public body. In doing so, the public body is required, by law, to have an addendum for the unique collections, uses or disclosures to accompany the join PIA submitted for the project.</p>
<p><strong>Question 7 </strong><br />
No additional explanation needed.</p>
<p><strong>Question 8</strong></p>
<p><strong>Risk Assessment and Mitigation &#8211; Risks Associated with Data Matching. </strong></p>
<p><em>This Completion Guide will provide some examples of the description of the types of risks identified in the Risk Assessment and Mitigation table for risks related to data matching. </em></p>
<p><strong>Risk 1</strong></p>
<p>E.g. section 7(2)(g) of the M-Regulation requires the establishment of a <span style="color: #ff0000;">clear governance structure respecting the responsibilities and accountability</span> of two public bodies involved in data matching if one public body is collecting personal information from another public body for the purpose of data matching.</p>
<p><strong>Risk 2</strong></p>
<p>E.g., this risk assessment is to ensure that section 17 of POPA is complied with, given that this section prohibits public bodies, except for the Office of Statistics and Information, from collecting personal information directly from an individual for the purpose of data matching.</p>
<p><strong>Risk 3</strong><br />
E.g., section 6 of POPA requires a public body to make every reasonable effort to ensure that an individual’s personal information is accurate and complete before using such information to make a decision that directly affects that individual.</p>
<p><strong>Risk 4</strong><br />
E.g., as required by section 6 of POPA, the quality of the source data will play a significant part in the quality of the resulting data from data matching, so it is important for public bodies to ensure that the quality of the source is validated prior to conducting the data matching.</p>
<p><strong>Risk 5</strong><br />
E.g., data matching activities normally take place in a test environment. The resulting data is then migrated to the production environment. Therefore, the test environment security controls should be proportionate to the security classification of the data involved in data matching. Failure to implement reasonable and proportionate security arrangements to protect personal information within the public body’s data matching environment, exposes it to potential incidents under section 10 (2) of POPA especially given that a single test environment may be used for multiple projects and thus accessed by various users.</p>
<p><strong>Risk 6</strong><br />
E.g. this is about validating the final product. The public body should ensure that the final product is the desired outcome, and that no data errors are in the resulting data set, or if errors are identified, that they are addressed. (section 6 of POPA).</p>
<p><strong>Risk 7</strong><br />
E.g., this is about securely cleaning the test environment that was used for data matching by securely deleting personal information from that environment before it is used for other purposes or used by other users to prevent potential unauthorized access to personal information.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="appendix-b-common-integrated-program-service"></a></p>
<h3>Appendix B. Common or Integrated Program or Service</h3>
<p><strong>Question 1</strong><br />
A common or integrated program or service must comply with specific requirements under POPA and the M-Regulation. It is therefore important for the public body to carefully consider those requirements prior to implementing new common or integrated program or service or making changes to an existing common or integrated program or service.</p>
<p><strong>Question 2</strong></p>
<p>Since common or integrated program or services requires each public body to identify its responsibilities and accountabilities identifying each public body assist in determining the areas of responsibility and accountability for each public body.</p>
<p>For question 2c, if the PIA is for a change in an existing common or integrated program or service, providing an existing PIA file number assists the OIPC in making reference to relevant information in that file during the review of the current PIA as the public body focuses on addressing privacy and security risks associated with the change. The public body may also choose to use the existing Microsoft Word copy of the existing PIA to identify areas that have changed by striking the outdated information and entering updated or new information in a different-colour text.</p>
<p><strong>Question 3</strong></p>
<p>This question is about making sure that there is a governance structure in place for the common or integrated program or services. This governance structure <em>(a documented set of rules and processes that identify the roles, responsibilities and accountability for each public body participating in the integrated program or service), </em>that clearly identifies responsibilities and accountabilities <span style="color: #ff0000;">must be in place prior to the PIA being submitted to the Commissioner for review.</span></p>
<p>The governance structure must clearly identify the responsibilities and accountability of each public body as it relates to:</p>
<ol>
<li>the custody and control of personal information,</li>
<li>the correction of errors or omissions in an individual’s personal information,</li>
<li>breach notifications, and</li>
<li>other duties imposed by the Act.</li>
</ol>
<p><strong>Question 4</strong></p>
<p>This agreement is required to ensure each public body involved in a common or integrated program or service independently comply with POPA<strong>. </strong>The minimum requirements for such an agreement include:</p>
<ol>
<li>identify the purpose of the common or integrated program or service,</li>
<li>identify each public body’s roles and responsibilities respecting the common or integrated program or service and how the roles and responsibilities of each public body relate to the purpose of the common or integrated program or service, identify each public body’s responsibilities under the Act,</li>
<li>establish rules respecting reasonable security arrangements, including respecting administrative safeguards, physical safeguards and technical safeguards, for the protection of personal information against such risks as unauthorized access, collection, use, disclosure or destruction, and</li>
<li>establish a clear governance structure respecting the responsibilities and accountability of each public body.</li>
</ol>
<p><strong>Question 5</strong></p>
<p>This question requires that a public body participating in a common or integrated program or service identifies collections, uses or disclosures of personal information that only apply to that public body. In doing so, the public body is required, by law, to have an addendum PIA for the unique collections, uses or disclosures to accompany the joint PIA submitted for the project.</p>
<p><strong>Question 6</strong></p>
<p><strong>Risk Assessment and Mitigation &#8211; Common or Integrated Program or Service Risks</strong></p>
<p><em>This completion guide will provide some examples of the description of the types of risks identified in the Risk Assessment and Mitigation table for common or integrated program or service risks</em></p>
<p><strong>Risk 1</strong><br />
E.g., governance structure including policies are not in place or are inadequate leading to inconsistencies in the management of the program that creates exploitable privacy and security vulnerabilities.</p>
<p><strong>Risk 2</strong><br />
E.g., policies are not in place or are not clear on accountability for different aspects of the program including accountability for privacy.</p>
<p><strong>Risk 3</strong></p>
<p>E.g., the responsibilities of each public body involved in the common or integrated program including for privacy management are not clearly defined.</p>
<p><strong>Risk 4</strong></p>
<p>E.g., the information security classification for one or more public bodies do not align with the sensitivity of information, leading to gaps in the protection of personal information.</p>
<p><strong>Risk 5</strong><br />
E.g., the public bodies involved fail to make individuals aware of how they can exercise their access and privacy rights under applicable POPA and ATIA.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="appendix-c-automated-systems-innovative-technology"></a></p>
<h3>Appendix C. Use of Automated Systems or Other Forms of Innovative Technology</h3>
<p><strong>Question 1</strong></p>
<p>An Algorithm Impact Assessment (AIA), is a risk assessment or evaluation process that determines the impact of an automated system on individuals whose personal information is collected, used or disclosed in the use of automated systems such as artificial intelligence or other forms of innovative technology. Section 7(3) of the M-Regulation requires that a PIA contains a level of detail commensurate with the complexity of the practice, program, project or service the PIA relates to. As such, the public body is required to also complete an AIA. The OIPC is in the process of developing an AIA tool, which will be published on the OIPC website and a link included in the POPA PIA template and this document. In the interim, the OIPC recommends that where a project involves automated systems, public bodies consult industry standard algorithm impact assessment guidelines in preparing and submitting their AIAs with their PIAs.</p>
<p><strong>Question 2</strong></p>
<p><strong>Risks Associated with the use of Automated Systems or </strong><strong>other forms of innovative technology.</strong></p>
<p><strong>Risk 1</strong><br />
E.g. failure to maintain custody or control of personal information ingested by an automated system due to lack of controls to securely and automatically delete information from the automated system.</p>
<p><strong>Risk 2 </strong><br />
E.g. lack of or insufficient automated systems governance policies and procedures leads to inconsistent implementation and use of automated systems, resulting in automated systems-related vulnerabilities and privacy compliance issues.</p>
<p><strong>Risk 3</strong><br />
E.g. automated systems such as artificial intelligence, are known to hallucinate by fabricating results or outputs. Lack of monitoring including lack of oversight of AI systems leads to failures to detect and address hallucination issues.</p>
<p><strong>Risk 4</strong><br />
E.g. Using poor quality and unreliable training data leads to issues with automated systems results including hallucination. In addition, using training data that is not an accurate representation of the population where the automated systems will be deployed could potentially lead to inaccurate results and bias.</p>
<p><strong>Risk 5</strong><br />
E.g. if inputs in automated systems are not validated and protected, such inputs can be manipulated prior to processing by the automated system. This makes input vulnerable to tampering and the automated system vulnerable to faulty results.</p>
<p><strong>Risk 6</strong><br />
E.g., understanding whether the automated system model is static or dynamic, it may be difficult to implement the right monitoring mechanism for the models. For instance, while dynamic models continuously learn from new data sets in process, a static model is as good as its last update.</p>
<p><strong>Risk 7</strong><br />
E.g., Underfitting an automated system model with its training data means that the automated system model is trained to be too broad in its generalization making the model prone to false positives when processing new data.</p>
<p><strong>Risk 8</strong><br />
E.g., Overfitting an automated system model with its training data means that the automated system model is trained too closely aligned with its training data, leading to lack of generalization by the model and making the model prone to false negatives when it processes new data.</p>
<p><strong>Risk 9</strong><br />
E.g., misconfiguration of an automated system is a security vulnerability that could be exploitable, leading potential to unauthorized access to or disclosure of personal information.</p>
<p><strong>Risk 10</strong><br />
E.g., lack of processes for individuals to be made aware of and appeal decisions made by automated systems could infringe on individuals’ access and privacy rights.</p>
<p><strong>Risk 11</strong> – E.g., insufficient logging and auditing means that the activities of the automated system cannot be reasonably monitored to ensure it is working as expected or to detect potential compromise of the system.</p>
<p><strong>Risk 12 </strong><br />
E.g., lack of monitoring of the automated system based on established policies and processes means that issues with the functioning of the automated system cannot be detected and addressed in a timely manner.</p>
<p><strong>Risk 13</strong><br />
E.g., without conducting a vulnerability assessment means that exploitable vulnerabilities associated with an automated system cannot be identified and addressed. A copy of the results of the assessment should form part of the PIA to demonstrate the public body’s commitment to protect personal information pursuant to section 10 of POPA.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>


	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="appendix-d-pia-cover-letter"></a></p>
<h3>Appendix D. PIA Cover Letter *</h3>
<p>While the head of a public body may assign privacy responsibilities to other individuals within the public body, the head of the public body is ultimately accountable for meeting the public body’s obligations under POPA. To this end, the PIA must include a cover letter signed by the head of the public body.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>

<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
<a id="appendix-e-pia-submission-checklist"></a></p>
<h3>Appendix E. PIA Submission Checklist *</h3>
<p>This checklist is there to ensure the public body reviews its PIA and ensures all sections of the PIA have been considered, relevant sections completed, and all supporting document included in the PIA submission.</p>
<p style="font-size: 0.9em; color: grey;"><a href="#">Back to top of the page</a></p>

		</div>
	</div>
<br />

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>
March 2026</p>

		</div>
	</div>
<br />

<table id="tablepress-2" class="tablepress tablepress-id-2">
<tbody class="row-striping">
<tr class="row-1">
	<td class="column-1"><p><strong>Disclaimer</strong><br><br />
This document is not intended as, nor is it a substitute for, legal advice, and is not binding on the Information and Privacy Commissioner of Alberta. Responsibility for compliance with the law (and any applicable professional or trade standards or requirements) remains with each organization, custodian or public body. All examples used are provided as illustrations. The official versions of the laws <a href="https://oipc.ab.ca/legislation/" target="_blank" rel="noopener">the OIPC oversees</a> and their associated regulations should be consulted for the exact wording and for all purposes of interpreting and applying the legislation. The Acts are available on the website of <a href="https://www.alberta.ca/alberta-kings-printer.aspx" rel="noopener" target="_blank">Alberta King's Printer</a>.</p><br></td>
</tr>
</tbody>
</table>
<!-- #tablepress-2 from cache --></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Letter from OIPC to Ministers of PPHS and HSHS regarding Bill 11 &#8211; December 1 2025</title>
		<link>https://oipc.ab.ca/resource/letter-from-oipc-to-ministers-of-pphs-and-hshs-regarding-bill-11-december-1-2025/</link>
		
		<dc:creator><![CDATA[Elaine Schiman]]></dc:creator>
		<pubDate>Mon, 01 Dec 2025 22:26:38 +0000</pubDate>
				<guid isPermaLink="false">https://oipc.ab.ca/?post_type=resource&#038;p=17186</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Scribe PIA Guidance</title>
		<link>https://oipc.ab.ca/resource/ai-scribe-pia-guidance/</link>
		
		<dc:creator><![CDATA[Elaine Schiman]]></dc:creator>
		<pubDate>Wed, 03 Sep 2025 18:15:51 +0000</pubDate>
				<guid isPermaLink="false">https://oipc.ab.ca/?post_type=resource&#038;p=17030</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Health Information Act Engagement 2024</title>
		<link>https://oipc.ab.ca/resource/health-information-act-engagement-2024/</link>
		
		<dc:creator><![CDATA[Elaine Schiman]]></dc:creator>
		<pubDate>Fri, 14 Feb 2025 18:02:30 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca/?post_type=resource&#038;p=16641</guid>

					<description><![CDATA[The Office of the Information and Privacy Commissioner (OIPC) of Alberta conducted an engagement project in late 2024 regarding the&#8230;]]></description>
										<content:encoded><![CDATA[<p>The Office of the Information and Privacy Commissioner (OIPC) of Alberta conducted an engagement project in late 2024 regarding the <em>Health Information Act</em> (HIA). The OIPC conducted a number of surveys asking members of the public, researchers and custodians (including members of regulated professional colleges) about their interactions with HIA.</p>
<p>The Government of Alberta had informed the OIPC in the fall of 2024 that as part of its restructuring of the health care system, it was planning to amend HIA to address any changes needed due to the restructuring and it would also consider modernizing the legislation at that time. The OIPC was invited to provide comments and recommendations on amendments to HIA.</p>
<p>To inform any comments and recommendations the OIPC might provide to government, the Commissioner initiated an engagement process with HIA stakeholders. As a result of this engagement process, the OIPC produced several reports.</p>
<p>The report that reflects the views of members of the public who were surveyed can be seen <a href="https://oipc.ab.ca/wp-content/uploads/2025/02/OIPC-HIA-Public-Engagement-Survey-Topline-Report.pdf" target="_blank" rel="noopener">here</a>.</p>
<p>The report that reflects the College of Physicians &amp; Surgeons of Alberta members&#8217; survey can be seen <a href="https://oipc.ab.ca/wp-content/uploads/2025/02/2024-HIA-engagement-CPSA-Members-Survey-Analysis-and-Summary-Final.pdf" target="_blank" rel="noopener">here</a>.</p>
<p>The report that reflects the survey of colleges of regulated health professionals in Alberta under the <em>Health Information Act</em> can be seen <a href="https://oipc.ab.ca/wp-content/uploads/2025/02/2024-HIA-engagement-Regulatory-Colleges-Survey-Analysis-and-Summary-Public-Final.pdf" target="_blank" rel="noopener">here</a>.</p>
<p>The report that summarizes the HIA engagement project can be seen <a href="https://oipc.ab.ca/wp-content/uploads/2025/02/2024-OIPC-Health-Information-Act-Surveys-Engagement-Report-Final.pdf" target="_blank" rel="noopener">here</a>.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Letters from OIPC to Government of Alberta regarding Bills 33 and 34 &#8211; November 20, 2024</title>
		<link>https://oipc.ab.ca/resource/letters-from-oipc-to-government-of-alberta-regarding-bills-33-and-34-november-20-2024/</link>
		
		<dc:creator><![CDATA[Elaine Schiman]]></dc:creator>
		<pubDate>Wed, 20 Nov 2024 19:05:09 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca/?post_type=resource&#038;p=16546</guid>

					<description><![CDATA[On November 20, 2024, the Office of the Information and Privacy Commissioner provided comments to the Government of Alberta regarding&#8230;]]></description>
										<content:encoded><![CDATA[<p>On November 20, 2024, the Office of the Information and Privacy Commissioner provided comments to the Government of Alberta regarding Bills 33 and 34, which were tabled in the Legislative Assembly of Alberta on November 6, 2024. The bills are designed to create two new pieces of legislation to replace the existing public sector access and privacy law, the <em>Freedom of Information and Protection of Privacy Act</em> (FOIP Act).</p>
<p>Please click <a href="https://oipc.ab.ca/wp-content/uploads/2024/11/20241120-Letter-to-Minister-Glubish-regarding-Bill-33-the-Protection-of-Privacy-Act-OIPC-comments-and-recommendations_Final-Unsigned.pdf">here</a> to read the OIPC&#8217;s letter and comments to the Minister of Technology and Innovation, Nate Glubish, on Bill 33.</p>
<p>Please click <a href="https://oipc.ab.ca/wp-content/uploads/2024/11/20241120-Letter-to-Minister-Nally-regarding-Bill-34-the-Access-to-Information-Act-OIPC-comments-and-recommendations_Final-Unsigned.pdf">here</a> to read the OIPC&#8217;s letter and comments to the Minister of Service Alberta and Red Tape Reduction, Dale Nally, on Bill 34.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Privacy Impact Assessment (PIA) Process Update &#8211; April 2026</title>
		<link>https://oipc.ab.ca/resource/changes-to-privacy-impact-assessment-process-now-in-effect-as-of-october-1-2024/</link>
		
		<dc:creator><![CDATA[Elaine Schiman]]></dc:creator>
		<pubDate>Tue, 01 Oct 2024 15:15:33 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca/?post_type=resource&#038;p=16473</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<p>In September 2024, the Office of the Information and Privacy Commissioner (OIPC) of Alberta announced that changes were coming soon to the OIPC process for managing Privacy Impact Assessments (PIAs). These changes came into effect as of October 1, 2024.</p>
<p>This affects custodians under the <em>Health Information Act</em> (HIA), public bodies under the <i>Protection of Privacy Act </i>(POPA) and private sector organizations under the <em>Personal Information Protection Act</em> (PIPA).</p>
<p>Please read below for more information. You may also view our PIA Frequently Asked Questions page <a href="https://oipc.ab.ca/resource/privacy-impact-assessments-frequently-asked-questions/" target="_blank" rel="noopener">here</a>.</p>
<h3><strong><u>Background on Privacy Impact Assessments (PIAs)</u></strong></h3>
<p>Privacy Impact Assessments (or PIAs) help to identify and address potential privacy risks that may occur in a project. A PIA is used for information systems, administrative practices and policy proposals that relate to the collection, use, or disclosure of individually identifying health and personal information.</p>
<p>Custodians under HIA are required to submit PIAs to the OIPC for review and comment before implementing proposed new administrative practices or information systems (section 64, HIA). Public bodies under POPA are required to complete PIAs in prescribed circumstances and, if required by the Regulation, to submit specific PIAs to the Commissioner. While private sector organizations under PIPA are not required by law to submit PIAs to the OIPC, the OIPC highly recommends and encourages organizations to contact the OIPC if they wish to voluntarily submit PIAs for review and comments.</p>
<h3><strong><u>What has changed?</u></strong></h3>
<ul>
<li>PIAs will no longer be accepted, conditionally accepted, or not accepted.</li>
<li>Instead, PIAs will be reviewed and a closing letter with comments and recommendations will be issued.</li>
<li>The OIPC will be reviewing PIAs as submitted.</li>
<li>If the PIA submission is incomplete or insufficient, the OIPC will close the file and notify the submitter of that. Generally, the OIPC will not be asking additional questions as this causes delays in the review process; however, the submitter will be asked to consider re-submitting the PIA, especially for custodians under HIA, who are required to submit PIAs to the OIPC.</li>
<li>PIAs received by our office prior to October 1, but the review has not yet been completed, will be reviewed under the new process. You may receive clarifying questions if the PIA reviewer has any. Closing letters will be issued and will include comments and recommendations, if required.</li>
</ul>
<h3><strong><u>Why were these process changes made?</u></strong></h3>
<ul>
<li>The changes better align with section 64(2) of the <em>Health Information Act, </em>which authorizes the Commissioner to review and comment on PIAs.</li>
<li>The changes are designed to better support privacy compliance by focusing on identifying and communicating compliance gaps to custodians, public bodies and organizations for remediation in a timely manner.</li>
<li>PIA submissions to the OIPC have increased exponentially since the OIPC’s <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>Privacy Impact Assessment Requirements Guide</em></a> was first published in 2010. The current review process is no longer sustainable.</li>
<li>The high volume of PIA submissions has led to a backlog of files, resulting in delays in reviewing and providing timely feedback to custodians, public bodies, and organizations.</li>
<li>The changes to this process will increase efficiency in our reviews, enable timely resolution of PIA files, help reduce backlogs in processing these files, and allow the OIPC to allocate resources to PIA files that require increased attention.</li>
<li>These changes align with the OIPC strategic priority, found in our 2024-2027 Business Plan, of enhancing internal processes to support our legislative mandate and to improve timelines.</li>
</ul>
<h3><strong><u>Additional information</u></strong></h3>
<ul>
<li>Changes to the <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>Privacy Impact Assessment Requirements Guide</em></a> and the development of new PIA resources to assist custodians, public bodies and organizations in completing and submitting PIAs to the OIPC are in progress.</li>
<li>New and updated PIA resources will be published on our website when completed. Please continue to use the existing <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf" target="_blank" rel="noopener"><em>Privacy Impact Assessment Requirements</em> <em>Guide</em></a> while completing your PIAs.</li>
<li>The OIPC looks forward to working with all parties to improve the timeliness and efficiency of its work in regard to these revised processes.</li>
<li>In March 2026, the OIPC launched a <a href="/popa/pia/template/" target="_blank" rel="noopener">PIA Template</a> and a <a href="/popa/pia/guide/" target="_blank" rel="noopener">PIA Completion Guide</a> that align with the current requirements of the <em>Protection of Privacy Act</em> (POPA) and its regulations, in order to assist public bodies in meeting their PIA obligations under POPA.</li>
</ul>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Privacy Impact Assessments (PIAs): Frequently-Asked Questions (HIA)</title>
		<link>https://oipc.ab.ca/resource/privacy-impact-assessments-frequently-asked-questions/</link>
		
		<dc:creator><![CDATA[Elaine Schiman]]></dc:creator>
		<pubDate>Tue, 01 Oct 2024 15:13:37 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca/?post_type=resource&#038;p=16472</guid>

					<description><![CDATA[A privacy impact assessment (PIA) is a process for identifying and addressing privacy risks associated with the implementation of an&#8230;]]></description>
										<content:encoded><![CDATA[<p>A privacy impact assessment (PIA) is a process for identifying and addressing privacy risks associated with the implementation of an administrative practice or information system that collects, uses, discloses, stores or processes identifying personal or health information. Depending on the type of administrative practice or information system, completing a PIA may be challenging.</p>
<p>This page addresses some of the most frequently asked questions that the Office of the Information and Privacy Commissioner (OIPC) has received about PIAs. The questions are set out in the categories of:</p>
<ul>
<li>General</li>
<li>Virtual Care</li>
<li>Netcare</li>
<li>CII/CPAR</li>
<li>PIA Amendments and Updates</li>
<li>Information Management Agreements</li>
<li>Opening Multiple Clinics</li>
<li>PIA Reviews</li>
<li>Changes to PIA Process</li>
<li>PIA Training</li>
</ul>
<h3><strong><u>General </u></strong></h3>
<ol>
<li><strong>When do I need to submit a PIA?</strong></li>
</ol>
<p><strong>Answer</strong>: The <a href="https://oipc.ab.ca/legislation/"><em>Health Information Act</em></a> (HIA) section 64 requires each custodian to prepare a PIA that describes how proposed <strong>administrative practices and information systems</strong> relating to the collection, use and disclosure of individually identifying health information may affect the privacy of the individuals who are the subjects of the information. HIA requires custodians to submit PIAs to the Commissioner for review and comment before implementing proposed administrative practices or information systems (or changes to existing administrative practices or systems) that involve the processing of identifying health information.</p>
<p>While public bodies under the <em>Freedom of Information and Protection of Privacy Act</em> (FOIP Act) and private sector organizations under the <em>Personal Information Protection Act</em> (PIPA) are not required by law to submit PIAs to the Commissioner, the OIPC highly recommends and encourages public bodies and organizations to voluntarily submit PIAs for review and comments.</p>
<ol start="2">
<li><strong>What do I need to include in my PIA?</strong></li>
</ol>
<p><strong>Answer</strong>: Currently, PIAs submitted by custodians under HIA need to meet the requirements set out in our <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>Privacy Impact Assessment Requirements Guide, 2010</em></a>.</p>
<ol start="3">
<li><strong>What if my PIA submission does not follow the </strong><a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><strong><em>Privacy Impact Assessment Requirements Guide, 2010</em></strong></a><strong>?</strong></li>
</ol>
<p><strong>Answer:</strong> If your PIA does not meet the <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>Privacy Impact Assessment Requirements Guide, 2010</em></a>  and does not contain sufficient information to enable the OIPC to review and comment on it, your PIA will not be reviewed by the OIPC. Your PIA file will be closed. If your PIA does not follow the guide but contains sufficient information about the administrative practice and/or information system, the OIPC will review and comment on it.</p>
<ol start="4">
<li><strong>Is there a PIA template available online? </strong></li>
</ol>
<p><strong>Answer</strong>: At this time, our office does not have a PIA template. We recommend following our <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>Privacy Impact Assessment Requirements Guide, 2010</em></a>.</p>
<ol start="5">
<li><strong>I am opening a new clinic and will be implementing different systems such as an electronic medical record (EMR), secure messaging tool, patient portal and Netcare. Should I submit one PIA that describes my organizational controls and the implementation details related to each of these systems? </strong></li>
</ol>
<p><strong>Answer</strong>: You should submit one PIA for each information system. This allows a timelier review by the OIPC, and if one system has privacy or security issues, then it will not affect the OIPC’s ability to review and comment on the PIAs for the other systems.</p>
<p>The first PIA should describe your organizational controls (policies and procedures) and the implementation details related to the main system such as an EMR, including specific policies and procedures for that information system.</p>
<p>For each subsequent PIA you submit for other information systems, you do not need to address your organizational controls, if those controls described in the first PIA have not changed.  Rather, you just need to reference your previously submitted PIA OIPC file number and the section of the PIA where you described those controls.</p>
<p>If it has been several years since you submitted your organizational controls including policies and procedures, it is recommended that you review them and submit updated copies to the OIPC with your new PIA submission. Going forward, you would then cite these updated organization controls in your future PIA submissions.</p>
<ol start="6">
<li><strong>Can I hire a PIA consultant to prepare my PIA? </strong></li>
</ol>
<p><strong>Answer: </strong>Yes. You may hire a consultant to prepare your PIA; however, the custodian(s) are accountable for the PIA and all the information described therein. The custodian should be actively involved in the PIA development.</p>
<ol start="7">
<li><strong>What if my administrative practice or information system is about sharing non-identifying health information? Do I need to submit a PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: <em>Non-identifying</em> health information is defined in HIA section 1(1)(r). As per the requirement in s. 64 of HIA, a PIA may not be required in this case; however, there may be risks of re-identification especially when it comes to the process that was used to make the identifying information non-identifiable. If you submit a PIA to our office, our review may help you identify risks that you may not have considered or potential areas of non-compliance with HIA.</p>
<ol start="8">
<li><strong>What is the best way to submit a PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: The OIPC prefers email submissions using the <a href="mailto:pia@oipc.ab.ca">pia@oipc.ab.ca</a> email address, although the OIPC still accepts PIAs submitted by mail.</p>
<ol start="9">
<li><strong>HIA says <u>each</u> custodian must submit a PIA to the Commissioner. Can a group of custodians working in a single setting submit one PIA to the Commissioner? </strong></li>
</ol>
<p><strong>Answer</strong>: While HIA does state that “each” custodian must submit a PIA, the OIPC does allow one PIA to be submitted by multiple custodians practicing in a common environment, under the same administrative practices, which implement the same health information system, policies and procedures.</p>
<p>All custodians must agree to the PIA, and all custodians must sign off on the PIA. Each custodian is still accountable for compliance with HIA and the health information that the custodian collects, uses or discloses.</p>
<p>When submitting a PIA from multiple custodians, please indicate who the primary contact (custodian) is for the PIA, so OIPC correspondence can be directed to that individual. It will be up to this primary contact to provide copies of the OIPC correspondence to all participating custodians of the PIA.</p>
<ol start="10">
<li><strong>Who needs to sign the cover letter for the PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: The custodian or custodians submitting the PIA must sign the PIA. If a group of custodians submit a PIA, all the custodians participating in the PIA submission must be signatories to the cover letter for the PIA.</p>
<ol start="11">
<li><strong>Can a</strong><strong>n affiliate of a custodian sign the PIA?</strong></li>
</ol>
<p><strong>Answer:</strong> Generally, no. Custodians must sign their PIA submissions, as compliance with HIA lies with the custodian. Privacy officers or a representative of the custodian [i.e. consultants hired by the custodian(s) to write the PIA or answer questions on behalf of the submitted PIA], or their affiliates <strong><u>cannot</u> sign the cover letter </strong>for the custodian.</p>
<p>However, for custodians as described in section 1(1)(f)(iv), (ix.1), (ix.2), (xii) and (xii.1) (e.g. Alberta Health, Recovery Alberta, Ministry of Mental Health and Addiction, etc.), a responsible affiliate who has been delegated appropriate authority may sign off on a PIA on behalf of the custodian.</p>
<ol start="12">
<li><strong>Can anyone at the clinic submit a PIA by email to the OIPC or does it have to be the custodian? </strong></li>
</ol>
<p><strong>Answer</strong>: While the custodian must complete and sign the PIA, a representative of the custodian, such as the privacy officer or any other individual, may submit the PIA to the OIPC on behalf of the custodian.</p>
<p>The PIA submission requires the custodian’s full contact information. This includes full name, title, physical mailing address, <strong>email address</strong> and phone number. Our office requires custodian contact details in order to open the PIA file. Submitting a PIA without the custodian’s full contact information may result in delays with processing the PIA file.</p>
<ol start="13">
<li><strong>Can I email you a link so you can retrieve my PIA submission (e.g. cloud storage) or does it need to be attached to the email? </strong></li>
</ol>
<p><strong>Answer</strong>: No. Please attach the PIA and cover letter to the email.</p>
<ol start="14">
<li><strong>How do I know if the OIPC has received my PIA submission? </strong></li>
</ol>
<p><strong>Answer</strong>: If a submission is sent to our PIA email address (pia@oipc.ab.ca), you will receive an email acknowledging receipt of your submission. If you do not receive a confirmation email, and you are concerned, please contact us (phone 780-422-6860 or toll free at 1-888-878-4044 or email <a href="mailto:generalinfo@oipc.ab.ca">generalinfo@oipc.ab.ca</a>) to confirm we received your submission. If you submit your PIA by mail or fax, we do not send confirmation of receipt.</p>
<p>Once a PIA file has been created, you will receive correspondence with your PIA file number. If there are issues with the submission (e.g. missing PIA requirements), we may not open a file and any hard copy submissions will be returned. You will be informed if your PIA is not processed.</p>
<ol start="15">
<li><strong>What should I expect after submitting a PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: After you receive the initial email confirming receipt of your email submission and the letter with your file number, you will either be contacted by the PIA reviewer about questions regarding the PIA or you will receive a letter with comments and recommendations (if applicable). The letter may require the custodian to follow up with the reviewer on the implementation of the recommendations.</p>
<ol start="16">
<li><strong>Can the custodian’s representative such as a privacy officer or a PIA consultant be the point of contact for questions on the PIA?</strong></li>
</ol>
<p><strong>Answer</strong>: If the PIA describes who to contact regarding questions on the PIA, the PIA reviewer will contact that individual for clarifying questions. However, our office requires contact information, including full name, title, physical mailing address, email address and phone number, for the custodian, so that formal correspondence can be directly sent to the custodian. A custodian’s representative may be copied on OIPC formal correspondence, if the custodian has provided that contact information.</p>
<ol start="17">
<li><strong>How long does the OIPC take to review a PIA?</strong></li>
</ol>
<p><strong>Answer</strong>: Based on the current PIA backlog and available resources, it may take up to 12 months to have your PIA reviewed and to receive comments. We are working to implement improvements in the way that we process PIAs and we anticipate that these changes will shorten our turnaround times.</p>
<ol start="18">
<li><strong>If I would like to know the status of my PIA, can I or my representative contact the OIPC for an update? </strong></li>
</ol>
<p><strong>Answer</strong>: Yes. The custodian (or one of the participating custodians) who submitted and signed off on the PIA can contact our office for an update. Where the PIA has identified an affiliate responsible for privacy compliance (i.e. privacy officer), the affiliate or representative may inquire on behalf of the custodian(s).</p>
<ol start="19">
<li><strong>Once I submit my PIA, can I start using my information system or do I have to wait for the OIPC to complete its review? </strong></li>
</ol>
<p><strong>Answer</strong>: Section 64 of HIA requires the custodian to submit the PIA prior to implementing the information system or administrative practice. If you are implementing a high-risk information system and require preliminary feedback from the OIPC, we encourage you to engage with our office early on in the project so that we can review and comment prior to the implementation.</p>
<ol start="20">
<li><strong>My PIA was accepted but I can’t find it. Does the OIPC retain the PIA documentation and, if so, can the OIPC send me a copy of my PIA, the OIPC’s acknowledgment letter, and the PIA review letter?</strong></li>
</ol>
<p><strong>Answer</strong>: Each custodian is responsible for maintaining accurate records of their PIA(s) and the related OIPC correspondence. While the OIPC has assisted in providing custodians with copies of PIAs in the past, the OIPC has since stopped that practice. It is not within the OIPC mandate to provide this service.</p>
<ol start="21">
<li><strong>Once I submit my PIA and receive OIPC comments, are my obligations satisfied?</strong></li>
</ol>
<p><strong>Answer: </strong>The custodian must review their PIAs regularly and ensure amendments to their PIAs are submitted as appropriate. In order to do this review, each custodian should have a copy of the PIAs and the OIPC PIA correspondence related to the review of each PIA.</p>
<h3><strong><u>Virtual Care</u></strong></h3>
<ol>
<li><strong>Do I need to submit a PIA if I am providing care virtually?</strong></li>
</ol>
<p><strong>Answer: </strong>Yes. The PIA should describe your administrative practices and any information systems used to provide virtual care. There are additional considerations that you must address in your virtual care PIA, including:</p>
<ul>
<li>whether the custodian meets the definition of a custodian under HIA, s. 1(1)(f);</li>
<li>how the custodian has custody and/or control of the health information in the virtual care platform and how this is maintained;</li>
<li>how the custodian is collecting, using and disclosing health information, reflected in the PIA’s information flow and legal authorities’ tables (if the custodian is using a third-party vendor to provide virtual care, this data flow may include information flows under the <em>Personal Information Protection Act</em>);</li>
<li>the Information Manager Agreement requirement under section 66 of HIA and section 7.2 of the <em>Health Information Regulation</em>; and</li>
<li>policies and procedures that reflect HIA compliance with respect to this type of care model.</li>
</ul>
<h3><strong><u>Netcare </u></strong></h3>
<ol>
<li><strong>I am a care provider but not a custodian, as defined in HIA s. 1(1)(f). I own a clinic and my staff need Netcare access. Can I submit an Expedited Netcare PIA to get access to Netcare?</strong></li>
</ol>
<p><strong>Answer</strong>: Alberta Health has described the requirements for obtaining Netcare Access. Only <em>authorized custodians</em> as per section 56.1(b) can request access to Netcare. Custodians may submit an Expedited Netcare PIA following the OIPC Expedited Netcare PIA Requirements found <a href="https://oipc.ab.ca/resource/netcare-pia-process/">here</a>. Additional information on Netcare can be found at Alberta Health’s Netcare Learning Centre website: <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__www.albertanetcare.ca_learningcentre_Privacy-2DSecurity.htm&amp;d=DwMFAg&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=u048qISGEj3NA3aNw-NwLA&amp;m=78vM27JXT-1GgFl3z89e20BhRQ7ypzPYbX2CqkG_ZJzV3Pa_MX9BJeEk7AgYjN8o&amp;s=GVvZmxdObaM8V4X4Y-kq9niihZ0FjKy7XwF0hF4IGos&amp;e=">Privacy &amp; Security, Netcare Learning Centre (albertanetcare.ca)</a> or contact Alberta Health directly.</p>
<ol start="2">
<li><strong>What is an Expedited Netcare PIA? </strong></li>
</ol>
<p><strong>Answer: </strong>In 2006, Alberta Health in consultation with the OIPC implemented an expedited process for custodians to submit PIAs for the Alberta Netcare Portal (ANP). Under this process, custodians attest they understand their duties and responsibilities in relation to Alberta Netcare, as described in the Alberta Netcare PIA submitted to the OIPC, on custodians’ behalf, by Alberta Health.</p>
<ol start="3">
<li><strong>What kind of change in my administrative practices may trigger an amendment to my Expedited Netcare PIA for access to the ANP? </strong></li>
</ol>
<p><strong>Answer</strong>: Some examples of changes to administrative practices that may trigger amendments are:</p>
<ul>
<li>if you are adding new custodians to the PIA (e.g. a group of custodians submitted a PIA and additional custodians are joining the practice), then a PIA amendment to the existing Expedited Netcare PIA is required (please be sure to reference the original PIA file number); and</li>
<li>if there is a change to the organizational privacy policy manual.</li>
</ul>
<ol start="4">
<li><strong>What should I do if there is a change to the custodian who submitted the Expedited Netcare PIA?</strong></li>
</ol>
<p><strong>Answer: </strong>If there is a change to the custodian who submitted the Expedited Netcare PIA (may be referred to as the lead custodian in the PIA) such as closing a practice or transferring or selling it to another custodian, a new Expedited Netcare PIA must be submitted under the new (or successor) custodian. In addition, the custodian should contact Alberta Heath to terminate existing Netcare access.</p>
<ol start="5">
<li><strong>If I already have an Expedited Netcare PIA accepted by the OIPC but I want to change my electronic medical record (EMR), do I need to submit a new Expedited Netcare PIA along with my new EMR PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: No. You will not need to resubmit your Expedited Netcare PIA unless there is a change to your organizational information management practices that will impact your Netcare PIA. However, pursuant to section 64 of HIA, you are required to submit a PIA for the new EMR.</p>
<ol start="6">
<li><strong>If I am submitting PIAs on an electronic medical record (EMR) and Netcare, is it best to combine those in one PIA or submit separate PIAs? </strong></li>
</ol>
<p><strong>Answer</strong>: It is best to submit these PIAs separately, each with its own cover letter. Expedited Netcare PIAs are reviewed on an expedited basis by the OIPC.  If an Expedited Netcare PIA is included in another PIA describing the implementation of other systems (such as an EMR, secure messaging, etc.), the review of that PIA may not be expedited.</p>
<ol start="7">
<li><strong>If I live outside Alberta and provide virtual care to Albertans, can I submit an Expedited Netcare PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: You may submit an Expedited Netcare PIA if you are a custodian as defined under HIA and associated regulations and if you provide health care services to Albertans. To be an authorized custodian, among other requirements detailed in s. 56.1 of HIA, you must meet the definition of a custodian. For example, if you are a physician you must be a member of the College of Physicians and Surgeons of Alberta.</p>
<h3><strong><u>Community Information Integration (CII)/Central Patient Attachment Registry (CPAR)</u></strong></h3>
<ol>
<li><strong>Do I need to submit a separate CII/CPAR PIA for each custodian practicing at our clinic? Can I submit one PIA listing all the custodians practicing at our clinic? </strong></li>
</ol>
<p><strong>Answer</strong>: While each custodian is required to submit a PIA (HIA s.64), if the custodians implement the same policies, procedures, processes and electronic medical record implementation (EMR), you may submit one PIA for all the custodians. However, each custodian must sign off on the PIA.</p>
<ol start="2">
<li><strong>Do I need to update the OIPC when there is a new custodian joining our clinic and participating in the CII/CPAR initiative? </strong></li>
</ol>
<p><strong>Answer</strong>:  Yes. You need to update that with the OIPC. If the new custodian adopts the existing policies and procedures at the clinic and uses the same implementation of the EMR, one of the custodians of the existing CII/CPAR PIA may send a letter to the OIPC, which should include the following information:</p>
<ul>
<li>the new custodian’s name and contact information;</li>
<li>that the new custodian is being added to the existing PIA (include the OIPC file number of the existing PIA); and</li>
<li>that the new custodian has reviewed the existing PIA and will abide by the controls described in the PIA.</li>
</ul>
<p>The letter must be signed by both the new custodian and the existing custodian.</p>
<ol start="3">
<li><strong>The CII/CPAR template requires a custodian to reference their PIA details for their EMR. What if I don’t have an EMR PIA or if I submitted a PIA for my EMR but haven’t received my file number yet? </strong></li>
</ol>
<p><strong>Answer</strong>: If you do not have an EMR PIA, please do not submit the CII/CPAR PIA, as the PIA will not be reviewed. If you have submitted your EMR PIA to the OIPC but have not heard back from the OIPC regarding your file number, please include this information in your CII/CPAR PIA submission for consideration by the OIPC.</p>
<ol start="4">
<li><strong>If I change my EMR, do I need to submit a PIA for my new EMR and also submit a new CII/CPAR PIA? </strong></li>
</ol>
<p><strong>Answer</strong>: Yes. If a custodian implements a new EMR, the custodian is required to submit a PIA to the OIPC pursuant to section 64 of HIA. In addition, the custodian will need to submit a new CII/CPAR PIA that references the new EMR, because CII/CPAR requires connectivity to the EMR.</p>
<h3><strong><u>PIA Amendments and PIA Updates</u></strong></h3>
<ol>
<li><strong>What is a PIA amendment? </strong></li>
</ol>
<p><strong>Answer</strong>: A PIA amendment is a PIA under section 64 of HIA. A PIA amendment addresses privacy and security risks associated with <strong>changes</strong> to an existing administrative practice and/or information system that impacts the collection, use and/or disclosure of identifying health information. A PIA amendment focuses on areas that have changed in an existing administrative practice or information system, and how the custodian has identified and addressed privacy and security risks associated with the change. The amendment must still follow the OIPC <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>PIA Requirements Guide</em> 04-14-10 (oipc.ab.ca)</a>. Page 12 of the guide describes when a PIA amendment may be appropriate.</p>
<ol start="2">
<li><strong>Can I use a copy of my existing PIA to identify and strike what has changed and add new information using a different colour font? </strong></li>
</ol>
<p><strong>Answer:</strong>  Yes. You may use that approach. Remember to ensure all sections affected by the change are addressed.</p>
<ol start="3">
<li><strong>What are some examples of changes to administrative practices or an information system that require PIA amendments?</strong></li>
</ol>
<p><strong>Answer: </strong>Some examples of changes to administrative practices or an information system that require PIA amendments include:</p>
<ul>
<li>migration of an on-premise (locally implemented) electronic medical record (EMR) to the cloud;</li>
<li>adding a new module to an existing EMR;</li>
<li>addition of a new custodian to an existing group of custodians in a practice using the same EMR and information management policies and procedures. The amendment must describe how each custodian has agreed to the details in the PIA, entered into agreements with information managers, etc.; and</li>
<li>transferring health records from a retiring custodian to another custodian (successor custodian). The retiring custodian should submit an amendment to his or her existing PIA describing the steps taken to ensure privacy and security compliance during the transfer to the successor custodian. The successor custodian will need to submit his or her own PIA regarding HIA compliance associated with the acquisition of the information.</li>
</ul>
<ol start="4">
<li><strong>I am a custodian who is looking at closing my practice. What do I need to do with my existing PIA(s)?</strong></li>
</ol>
<p><strong>Answer: </strong>If you are closing your practice, you must submit a PIA amendment addressing the steps you have taken to protect health information in your custody and/or control, including:</p>
<ul>
<li>informing patients about the closure of the practice;</li>
<li>facilitating the transfer of patient health information to new health care providers to ensure continuity of care;</li>
<li>responding to access to information requests from patients;</li>
<li>securely transferring health information to a successor custodian;</li>
<li>if there is no successor custodian, steps taken to secure health information in your custody and/or control;</li>
<li>securely decommissioning your EMR, including the proper termination of any agreements and the termination of access to health information;</li>
<li>ensuring your information manager has securely removed health information from its environment; and</li>
<li>securely disposing of health information when the retention period expires.</li>
</ul>
<p>Custodians are accountable for the health information of their patients, and they must ensure HIA compliance. This includes responding to access to information requests until they transfer the health records to another custodian or until the end of the retention period, after which the records are securely destroyed.</p>
<ol start="5">
<li><strong>What is a PIA update?</strong></li>
</ol>
<p><strong>Answer</strong>: Changes to an existing PIA that do not affect the collection, use, disclosure or protection of health information are considered PIA updates. Our office manages these types of submissions differently than PIAs and PIA amendments. A custodian will often notify our office of changes such as:</p>
<ul>
<li>clinic address;</li>
<li>clinic name change;</li>
<li>removing participating custodians from a PIA submitted by a group of custodians; and</li>
<li>change of privacy officer.</li>
</ul>
<p>These changes must be submitted by the custodian and the letter must be signed by the custodian. Once the OIPC receives these PIA updates, we will update your PIA file. No new file is opened and no letter is sent confirming the update. However, if there is an issue or a question, we will contact the custodian.</p>
<ol start="6">
<li><strong>What changes <em>do not require a PIA submission</em> (including a PIA, PIA amendment or a PIA update)?</strong></li>
</ol>
<p><strong>Answer</strong>: If a change does not impact the collection, use, disclosure or protection of health information, you are not required to submit a PIA. While custodians may need to update their PIA so the OIPC can contact them and have up-to-date organizational information, other information is not critical to provide to the OIPC. For example, the OIPC does not need to know if there is a:</p>
<ul>
<li>change to staff (affiliates) &#8211; If there are no changes to the roles or access procedures then this change likely would not need a PIA submission. The custodians need to ensure the new staff are appropriately trained as described in their existing PIAs.</li>
<li>change to janitorial services or shredding company. Custodians need to ensure the steps described in the PIA on HIA compliance by these services are implemented with the new organization. These steps may include the signing of confidentiality and/or non-disclosure agreements.</li>
</ul>
<h3><strong><u>Information Manager Agreements </u></strong></h3>
<ol>
<li><strong>What is an information manager?</strong></li>
</ol>
<p><strong>Answer:</strong>  Section 66(1) of HIA includes a description of the following services that, if performed by a person or body, makes that person or body an information manager for purposes of HIA:</p>
<p><em>66(1) In this section, “information manager” means a person or body that</em></p>
<ol>
<li><em>(a) processes, stores, retrieves or disposes of health information,</em></li>
<li><em>(b) in accordance with the regulations, strips, encodes or otherwise transforms individually identifying health information to create non-identifying health information, or</em></li>
<li><em>(c) provides information management or information technology services.</em></li>
</ol>
<p>2<strong>. When do I need an information manager agreement (IMA)?</strong></p>
<p><strong>Answer:</strong>  Pursuant to section 66 of HIA, custodians are required to enter into an IMA prior to providing health information to an information manager. Information managers must comply with HIA and its regulations as well as the agreement they enter into with the custodian in respect of the information provided to the information manager by the custodian. Custodians may not have the authority to disclose health information to providers of information management services without appropriate written agreement.</p>
<ol start="3">
<li><strong>Who needs to sign an IMA? </strong></li>
</ol>
<p><strong>Answer:</strong> IMAs must be signed by custodians. Agreements signed by individuals who are not custodians are not valid IMAs under HIA.</p>
<ol start="4">
<li><strong>What needs to be included in an IMA? </strong></li>
</ol>
<p><strong>Answer: </strong>Section 7. 2 of the<em> Health Information Regulation</em> specifies what IMAs <u>must</u> address:</p>
<p><em>7.2 For the purposes of section 66(2) of the Act, an agreement between a custodian and an information manager must</em></p>
<p><em>(a) identify the objectives of the agreement and the principles to guide the agreement,</em></p>
<p><em>(b) indicate whether or not the information manager is permitted to collect health information from any other custodian or from a person and, if so, describe that health information and the purpose for which it may be collected,</em></p>
<p><em>(c) indicate whether or not the information manager may use health information provided to it by the custodian and, if so, describe that health information and the purpose for which it may be used,</em></p>
<p><em>(d) indicate whether or not the information manager may disclose health information provided to it by the custodian and, if so, describe that health information and the purpose for which it may be disclosed,</em></p>
<p><em>(e) describe the process for the information manager to respond to access requests under Part 2 of the Act or, if the information manager is not to respond to access requests, describe the process for referring access requests for health information to the custodian itself,</em></p>
<p><em>(f) describe the process for the information manager to respond to requests to amend or correct health information under Part 2 of the Act or, if the information manager is not to respond to requests to amend or correct health information, describe the process for referring access requests to amend or correct health information to the custodian itself,</em></p>
<p><em>(g) describe how health information provided to the information manager is to be protected, managed, returned or destroyed in accordance with the Act,</em></p>
<p><em>(h) describe how the information manager is to address an expressed wish of an individual relating to the disclosure of that individual’s health information or, if the information manager is not to address an expressed wish of an individual relating to the disclosure of that individual’s health information, describe the process for referring these requests to the custodian itself, and</em></p>
<p><em>(i) set out how an agreement can be terminated.</em></p>
<p>Please note that your IMA must include all of the provisions listed above from (a) to (i). Omitting any of these sections will make your IMA non-complaint with HIA.</p>
<p>Section 8.4 of the<em> Health Information Regulation</em> also specifies that when health information is going to be stored, used or disclosed by a person in a jurisdiction outside of Alberta, the custodian must enter into a written agreement with that person prior to the storage, use or disclosure of the information.</p>
<ol start="5">
<li><strong>Should I attach a copy of my IMA(s) to my PIA?</strong></li>
</ol>
<p><strong>Answer: </strong>You may attach a copy of your IMA(s) to your submission. You should review your IMA(s) and confirm in your PIA submission if your IMA(s) meet(s) the requirements outlined above. In the event you do not provide your IMA(s), the PIA reviewer may ask to see a copy of your IMA(s), so you should be prepared to provide that documentation if requested.</p>
<ol start="6">
<li><strong>My vendor has provided an IMA. If I sign that, is it adequate?</strong></li>
</ol>
<p><strong>Answer: </strong>While a vendor may provide an IMA for the custodian to sign, custodians must ensure that any IMAs they sign meet the requirements of section 7.2 of the <em>Health Information Regulation.</em></p>
<ol start="7">
<li><strong>I have left my practice and can’t get access to my health records. What should I do?</strong></li>
</ol>
<p><strong>Answer:  </strong>When custodians do not directly sign agreements with their EMR vendors, they may find themselves in the unfortunate position of not being able to exercise control over health information they need to provide health services. Custodians remain accountable for the health information they collect, use and disclose and must ensure they are playing an active role in determining how that information is managed (see OIPC <a href="/wp-content/uploads/2022/01/H2013-IR-01.pdf" target="_blank" rel="noopener">Investigation Report H2013‐IR‐01</a>.</p>
<p>Note: Custodians working in a practice with other custodians should all have their own agreements with information managers and understand what will happen should they leave the clinic (e.g. process for obtaining copies of their patients’ health records).</p>
<h3><strong><u>Opening Multiple Clinics</u></strong></h3>
<ol>
<li><strong>I am adding a new clinic at another location, and I have already submitted a PIA for the prior clinic. Do I need to submit a PIA for this new clinic? </strong></li>
</ol>
<p><strong>Answer:</strong> Yes. A new PIA should be submitted. A custodian or group of custodians may open multiple locations for their practice. While each clinic may follow the same policies and procedures, the PIA should clearly describe whether there are any differences besides address for the new clinic location(s). Some elements to consider are whether the same or different custodians will be working in the new clinic, differences in the clinic set-up, privacy and security governance in each clinic, systems implemented in each clinic, differences in physical and technical safeguards in each clinic, use of different service providers, etc.</p>
<h3><strong><u>PIA Reviews</u></strong></h3>
<ol>
<li><strong>Sometimes I receive comments and recommendations and sometimes I just receive a closing letter from the OIPC. Why does this happen?</strong></li>
</ol>
<p><strong>Answer: </strong>The way we review PIAs can be different depending on the complexity of the administrative practice or system and the content of the PIA submissions. PIAs on complex systems or novel approaches may result in more comments than a PIA describing a system that is commonly implemented in Alberta. PIAs that describe the implementation of a system or administrative practice that is likely to impact a large segment of the population may have significant impacts on individuals’ privacy and require a more thorough review of legislative compliance and may result in more comments and recommendations.</p>
<ol start="2">
<li><strong>Can I talk to the PIA reviewer during the PIA review?</strong></li>
</ol>
<p><strong>Answer: </strong>Yes. You can speak with PIA reviewers during the review process. There are times when follow-up questions may be asked over the phone or in writing. If you wish to speak to someone about your PIA and it has already been assigned to a manager for review, contact the manager directly or email <a href="mailto:generalinfo@oipc.ab.ca">generalinfo@oipc.ab.ca</a> with your PIA file number.</p>
<ol start="3">
<li><strong>My vendor says they have an accepted PIA. Why do I need to submit a PIA if they already have one that has been accepted?</strong></li>
</ol>
<p><strong>Answer: </strong>It is the custodian/public body/organization’s responsibility to ensure they are complying with the applicable privacy legislation to protect health information or personal information in their custody or control. HIA describes the custodian’s duty to prepare and submit a PIA. While vendors may provide documentation to support the PIA review process, the custodian is responsible for submitting a PIA (s. 64 of HIA). The custodian will need to describe the system they are implementing and how the system will be used (who will use it, what it will be used for, type of information it will process, how it will be customized, what agreements are entered into, clinic privacy policies and procedures, etc.). Vendors are able to support the PIA submission by providing the technical details on how the system works and what they offer for technical, physical and administrative safeguards but they are not required by law to submit a PIA to the OIPC.</p>
<h3><strong><u>Changes to PIA Process</u></strong></h3>
<ol>
<li><strong>What is changing about the current PIA process?</strong></li>
</ol>
<p><strong>Answer: </strong>On October 1, 2024, the OIPC changed the way PIAs are reviewed. PIAs will no longer be accepted, conditionally accepted, or not accepted. Instead, PIAs will be reviewed and a closing letter with comments and recommendations will be issued, when required; otherwise just a closing letter will be issued.</p>
<ol start="2">
<li><strong>Why did the PIA review process change?</strong></li>
</ol>
<p><strong>Answer: </strong>The change better aligns with section 64(2) of the <em>Health Information Act, </em>which authorizes the OIPC to review and comment on PIAs. The change is designed to better support privacy compliance by focusing on identifying and communicating compliance gaps to custodians, for remediation in a timely manner.</p>
<p>PIA submissions to the OIPC have increased exponentially since the OIPC’s <em>Privacy Impact Assessment Requirements Guide</em> was first published in 2010. The current review process is no longer sustainable. The high volume of PIA submissions has led to a backlog of files, resulting in delays in reviewing and providing timely feedback to custodians.</p>
<p>The changes to this process will increase efficiency in our reviews, enable timely resolution of PIA files, help reduce backlogs in processing these files, and allow the OIPC to allocate resources to PIA files that require increased attention. These changes align with the OIPC strategic priority of enhancing internal processes to support our legislative mandate and to improve timelines.</p>
<ol start="3">
<li><strong>What does this mean for PIAs that were submitted before the change?</strong></li>
</ol>
<p><strong>Answer: </strong>PIAs received by our office prior to the change, but where the review has not been completed, will be reviewed under this new process. You may receive clarifying questions if the PIA reviewer has any. Closing letters will be issued and will include comments and recommendations, if required.</p>
<ol start="4">
<li><strong>The </strong><a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><strong><em>Privacy Impact Assessment Requirements Guide, 2010</em></strong></a><strong> still says PIAs will be accepted, not accepted or conditionally accepted. Why is this the case if you aren’t accepting PIAs anymore?</strong></li>
</ol>
<p><strong>Answer: </strong>Changes to the <em>Privacy Impact Assessment Requirements Guide</em> and the development of new PIA resources to assist custodians, public bodies and organizations in completing and submitting PIAs to the OIPC are in progress. New and updated PIA resources will be published on our website when completed. Please continue to use the existing <a href="https://oipc.ab.ca/wp-content/uploads/2022/03/PIA-Requirements-2010.pdf"><em>Privacy Impact Assessment Requirements</em> <em>Guide, 2010</em></a> while completing your PIAs, until the new resources are available.</p>
<ol start="5">
<li><strong>If you aren’t sending acceptance letters anymore, what can I expect when are you finished reviewing my PIA?</strong></li>
</ol>
<p><strong>Answer: </strong> You will receive a closing letter that may contain comments and recommendations. If the letter contains recommendations, you will be asked to indicate if you accept or reject the recommendations by a certain date. This information may be published on the PIA Registry located on our website.</p>
<ol start="6">
<li><strong>Some PIAs require a PIA acceptance in order to get access to a system, such as Alberta Netcare Portal, Community Information Integration and Central Patient Attachment Registry (CII/CPAR). Will this OIPC process change affect my ability to get access to these systems? </strong></li>
</ol>
<p><strong>Answer</strong>: According to the new OIPC process, a closing letter that may contain comments and recommendations will be sent to the custodian. Questions related to Netcare and CII/CPAR access should be directed to Alberta Health and its eHealth team.</p>
<h3><strong><u>PIA Training</u></strong></h3>
<ol>
<li><strong>Can my professional college or association provide PIA training?</strong></li>
</ol>
<p><strong>Answer: </strong>You can contact your professional college or association to request OIPC PIA training for your members. You can also use the speaking engagement form on our website to request OIPC training <a href="https://oipc.ab.ca/wp-content/uploads/2024/02/Form-Speaking-Request-2014-Feb-2.pdf">here</a>.</p>
<p>The OIPC website also has a <a href="https://oipc.ab.ca/resources/a-to-z/">resources page</a> that includes information on topics including cloud computing, artificial intelligence, and electronic health system requirements, which may assist in the completion of a PIA.</p>
<p>&nbsp;</p>

<table id="tablepress-2-no-2" class="tablepress tablepress-id-2">
<tbody class="row-striping">
<tr class="row-1">
	<td class="column-1"><p><strong>Disclaimer</strong><br><br />
This document is not intended as, nor is it a substitute for, legal advice, and is not binding on the Information and Privacy Commissioner of Alberta. Responsibility for compliance with the law (and any applicable professional or trade standards or requirements) remains with each organization, custodian or public body. All examples used are provided as illustrations. The official versions of the laws <a href="https://oipc.ab.ca/legislation/" target="_blank" rel="noopener">the OIPC oversees</a> and their associated regulations should be consulted for the exact wording and for all purposes of interpreting and applying the legislation. The Acts are available on the website of <a href="https://www.alberta.ca/alberta-kings-printer.aspx" rel="noopener" target="_blank">Alberta King's Printer</a>.</p><br></td>
</tr>
</tbody>
</table>
<!-- #tablepress-2-no-2 from cache -->
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Privacy Impact Assessment (PIA) Requirements Guide (HIA)</title>
		<link>https://oipc.ab.ca/resource/privacy-impact-assessment-requirements/</link>
		
		<dc:creator><![CDATA[ssibbald]]></dc:creator>
		<pubDate>Tue, 01 Mar 2022 18:30:45 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca?post_type=resource&#038;p=2464</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Electronic Health Record Systems Guidance</title>
		<link>https://oipc.ab.ca/resource/electronic-health-record-systems/</link>
		
		<dc:creator><![CDATA[ssibbald]]></dc:creator>
		<pubDate>Fri, 25 Feb 2022 20:48:27 +0000</pubDate>
				<guid isPermaLink="false">https://staging.oipc.ab.ca?post_type=resource&#038;p=2360</guid>

					<description><![CDATA[This document is meant for custodians and their information managers (service providers) to assess the safeguards in electronic health record&#8230;]]></description>
										<content:encoded><![CDATA[<p><span dir="ltr" role="presentation">This document is meant for custodians and their information managers (service providers) to assess the safeguards in electronic health record systems. It is available as a PDF and editable Word document:</span></p>
<ul>
<li><a href="/wp-content/uploads/2022/02/Electronic-Health-Record-Systems-2016.docx">Guidance for Electronic Health Record Systems</a> (DOC)</li>
<li><a href="/wp-content/uploads/2022/02/Electronic-Health-Record-Systems-2016.pdf" target="_blank" rel="noopener">Guidance for Electronic Health Record Systems</a> (PDF)</li>
</ul>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
