This form is to be used by an organization that is notifying the Information and Privacy Commissioner (the Commissioner) of a privacy breach under section 34.1 of the Personal Information Protection Act (PIPA).
An organization having personal information under its control must, without unreasonable delay, provide notice to the Commissioner of any incident involving the loss of or unauthorized access to or disclosure of the personal information where a reasonable person would consider that there exists a real risk of significant harm to an individual as a result of the loss or unauthorized access or disclosure (section 34.1).
Notice to the Commissioner must meet the requirements of section 19 of the PIPA Regulation. This form assists Organizations with notifying the Commissioner in accordance with section 19 of the PIPA Regulation.
For general information about responding to a privacy breach, please contact the OIPC by telephone at (780) 422-6860, toll free at 1-888-878-4044, or by email at generalinfo@oipc.ab.ca.
Contacting the OIPC does not mean that an organization has fulfilled its legal obligation to notify the Commissioner about a privacy breach. Notification to the Commissioner about a privacy breach must meet the requirements of section 19 of the PIPA Regulation. Information provided by the OIPC does not constitute legal advice and is not binding on the Commissioner.
This electronic form is designed to be completed in one session. Ensure you have the required information identified below and allow 30 to 60 minutes to complete. It does not support saving or resuming.
Identify the types of personal information and list the data elements involved.
Describe the Organization’s assessment that a real risk of significant harm exists as a result of the privacy breach.
Whether real risk of significant harm exists must be more than mere speculation or conjecture. There must be a cause and effect relationship between the breach and the harm.