---
title: "Alberta PIPA — Personal Information Protection Act (Alberta) — KYE Protocol™ coverage"
description: "Alberta PIPA — Personal Information Protection Act (Alberta) coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it."
url: https://kyeprotocol.com/compliance/alberta-pipa/
lang: en
source: "KYE Protocol"
---

> Alberta PIPA — Personal Information Protection Act (Alberta) coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.

Alberta PIPA — Personal Information Protection Act (Alberta)

# Alberta PIPA — Personal Information Protection Act (Alberta) — 83% of in-scope requirements covered.

3 requirements · 3 in scope (2 enforced · 1 designed). The 83% is weighted over the in-scope base.

**Source:** Personal Information Protection Act, S.A. 2003, c. P-6.5 (Alberta), recognised as substantially similar to PIPEDA for the Alberta private sector, and notable as the first Canadian private-sector law to require mandatory breach notification to the Commissioner (s.34.1). Consent (ss.7-8), protection of personal information (s.34), and breach notification (s.34.1).

## By category

| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
| --- | --- | --- | --- | --- | --- | --- |
| Consent (ss.7-8) | 1 | 1 | 0 | 0 | 0 | **100%** |
| Protection of personal information (s.34) | 1 | 1 | 0 | 0 | 0 | **100%** |
| Breach notification (s.34.1) | 1 | 0 | 1 | 0 | 0 | **50%** |

## Every requirement → the KYE™ artefact that enforces it

| ID | Title | Status | KYE™ enforcement |
| --- | --- | --- | --- |
| `alberta-pipa.s7` | Sections 7-8 — Consent: an organisation must not collect, use or disclose personal information about an individual without consent, except as authorised by the Act | enforced | **audit\_events**: `kye.purpose.request.v1`, `kye.purpose.admissibility.v1` **engines**: `internal` **constitution\_refs**: `constitution/12-PURPOSE-PERMISSION.md` |
| `alberta-pipa.s34` | Section 34 — Protection of personal information: protect personal information by making reasonable security arrangements against risks such as unauthorised access, collection, use, disclosure, or disposal | enforced | **audit\_events**: `kye.purpose.admissibility.v1`, `kye.evidence.tool_call.v1` **engines**: `internal` **constitution\_refs**: `constitution/30-AUDIT-WORM-RETENTION.md` |
| `alberta-pipa.s34.1` | Section 34.1 — Breach notification: notify the Commissioner without unreasonable delay of an incident involving the loss of or unauthorised access to personal information where there is a real risk of significant harm | designed | **audit\_events**: `kye.signal.incident.opened.v1`, `kye.compliance.attestation.v1` **engines**: `internal`, `internal` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md` |

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/).
