PIPEDA and Provincial Privacy Law for Home Care Agencies: Where Client Data Must Live

Updated August 28, 2026 · 6 min read

Sooner or later the question arrives, from a client's daughter, an RFP, or an insurance form: where exactly is our data stored, and what law protects it? Most Canadian home care agencies answer with the one privacy acronym they know, PIPEDA, and for many of them that answer is wrong twice, first about the law and then about what it requires. The real map has three layers, and an agency that understands it holds an advantage that compounds: privacy competence is checkable in a way most marketing claims are not, and the people who check, families, funders, brokers, remember who passed.

Layer one: which privacy statute actually governs you

PIPEDA is Canada's federal private-sector privacy law, and it applies by default. But the federal cabinet has declared three provinces' own laws substantially similar, which switches those provinces' organizations onto the provincial statute for activity inside the province: Alberta's PIPA and BC's PIPA, both by orders made in October 2004, and Quebec's private-sector act before them. Ontario's order is narrower, covering only health information custodians under its PHIPA. So an agency in Calgary is governed day to day by Alberta's PIPA; an agency in Halifax or Winnipeg, by PIPEDA; and everyone, everywhere, by PIPEDA for data that crosses provincial or national borders. This is not trivia. The provincial acts contain obligations PIPEDA lacks, and Alberta's, as we will see, reach directly into your software choices. It is also commercially load-bearing: Ontario's prequalification for publicly funded home care providers explicitly evaluates information management, privacy and cybersecurity practices, so for an agency with public-contract ambitions, privacy posture is not compliance overhead, it is bid eligibility.

Layer two: the health-information question, answered precisely

Client care records feel like health records, so agencies assume health-information legislation covers them. The statutes are more particular than the intuition. Health acts bind custodians and trustees, defined by lists, and in Alberta those lists name hospitals, continuing care home operators, health agencies, pharmacies, and individually regulated members of thirteen colleges; home care agencies appear nowhere, and neither do health care aides or LPNs. A private-pay agency's client records therefore live under PIPA, not the Health Information Act. The FAQ above walks through the two switches that change the answer: a public contract, which makes the agency an affiliate handling the custodian's information under the health act's rules, and an employed RN, who is a custodian personally. Saskatchewan and Manitoba mirror the pattern: sign a health-authority service agreement and the agency becomes a trustee under their health information acts, with everything that follows.

The design consequence is worth stating plainly: an agency that intends ever to take public contracts should run its records, from day one, to the standard the health acts demand, because the standard will attach retroactively to nothing, and reconstructing compliance is far costlier than starting with it.

Layer three: geography, the layer written for the software age

Alberta's PIPA contains the clearest thinking in Canada about data leaving the country, and it repays reading even outside Alberta because it names the real issue. Use a service provider outside Canada, and you owe individuals notice, before or at collection, pointing to written policies that must list the countries involved and the purposes the foreign provider is authorized for, plus a named contact who can answer questions. The definition of service provider reaches parents, subsidiaries, contractors and subcontractors, so a Canadian-branded platform running on US infrastructure counts. Alberta's Health Information Regulation goes further for custodians: health information stored outside Alberta, another province included, requires a written agreement with five mandatory terms covering control, risk, safeguards, monitoring and remedies. And Alberta's breach-reporting regime, the first mandatory private-sector one in North America, has been enforcing all of this posture since 2010.

One nuance in the breach machinery is worth knowing because it defines the relationship with your software vendor. The reporting duty sits on the organization with control of the information, the agency, not the platform; Alberta's regulator's 2024 guidance confirms it, while also allowing the organization to authorize a third party, its SaaS provider included, in writing, to report on its behalf. So the right conversation with any vendor is not "are you compliant?", which is a category error, but "what do you detect, what do you tell us, and how fast?", because their detection feeds your legal clock.

What a compliant agency actually has on the shelf

Strip the three layers down to artifacts and the list is short enough to build in a week. A named privacy contact whose title appears in your policies. Written policies that, if any service provider sits outside Canada, list the countries involved and what those providers are authorized to do. A collection notice that tells clients and staff what is gathered and why, including the advance notice Alberta requires for employee data such as GPS punches. A breach-response page that names which regulator you would call, with the reporting thresholds beside it. And, the day you take a public contract, the affiliate or trustee agreement your custodian will require, read rather than merely signed. None of this needs a law firm to start; all of it needs to exist before the day someone asks, because in privacy the asking and the emergency have a well-documented habit of arriving in the same week, and usually in that order.

An agency can comply with every word of that while hosting abroad. Or it can host in Canada and make the entire obligation set vanish, which is the choice Carelyst makes structurally: every agency runs on its own fully isolated database, hosted in Canada, with the family portal deliberately privacy-scoped to exclude medications, wellness observations and location coordinates, and photo messages stored on the tenant's private storage rather than public links. When the daughter, the RFP or the broker asks where the data lives, the answer is one sentence with no footnotes. If your current answer has footnotes, start a free 14-day trial and simplify it.

Frequently asked questions

It depends on your province, and the common assumption that PIPEDA covers everyone is wrong in three of them. Alberta, BC and Quebec each have private-sector privacy laws declared substantially similar to PIPEDA by federal order, Alberta's and BC's in October 2004 and Quebec's in 2003, so an agency's commercial activity inside those provinces is governed by the provincial statute: PIPA in Alberta and BC, Quebec's private-sector act there. Ontario's substantial-similarity order covers only health information custodians under PHIPA. Everywhere else, PIPEDA is the operative law, and PIPEDA also keeps governing interprovincial and international data flows for everyone. The practical consequence: an Alberta agency answering a privacy question by quoting PIPEDA is reading the wrong statute, and the differences, like Alberta's outside-Canada service provider notices, are exactly where it bites.

Usually not, and the analysis surprises people. Health information acts attach to custodians, and the custodian lists are specific: in Alberta, hospitals, continuing care home operators, health agencies, pharmacies and regulated members of thirteen designated colleges. A private-pay home care agency staffed by health care aides and LPNs is not on any of those lists, so its client records sit under ordinary private-sector privacy law, PIPA in Alberta. Two twists matter. First, take a public contract and the analysis flips: an agency delivering health-authority-contracted care handles that information as an affiliate of the custodian, under the health act's rules and its duty to report breaches to the custodian; Manitoba's and Saskatchewan's health information laws flip the same switch, making an agency under a health-authority agreement a trustee. Second, employ a registered nurse and she is individually a custodian for records in her custody, even though the agency is not.

Report it, promptly, and the duty has real teeth. Alberta wrote the template: under PIPA, an organization must notify the privacy commissioner without unreasonable delay wherever a reasonable person would see a real risk of significant harm, the commissioner can then require notification of affected individuals, and failing to report is an offence with fines up to $10,000 for individuals and $100,000 for organizations. Alberta has run this regime since 2010, eight years before the federal breach rules arrived in 2018, so it is mature and enforced. On the health-information side the numbers get bigger: an Alberta affiliate must notify its custodian as soon as practicable, and offences under the Health Information Act carry fines up to $200,000 for individuals and $1,000,000 for organizations. The operational lesson is boring and vital: know which regulator you would call, before the day you have to.

Legally yes, in most provinces, but Alberta shows what it costs administratively. Under Alberta's PIPA, an organization using a service provider outside Canada to collect or hold personal information must notify individuals before or at collection, in writing or orally, pointing to written policies that list the countries where the information may be stored and naming a contact person who can answer questions about it. "Service provider" is defined broadly enough to catch a US-hosted platform and a Canadian platform's US sub-processors alike. On the health-information side, an Alberta custodian must have a written agreement with five mandatory terms before health information is stored outside Alberta, even in another province. None of this is a ban; all of it is paperwork that exists only because of where the servers sit. Canadian hosting makes the entire obligation set disappear, which is why the question belongs in every software evaluation.

It is personal information too, and in Alberta it has its own category: personal employee information, which an employer may collect, use and disclose without consent where reasonably required to manage the employment relationship, provided current employees get reasonable advance notice of what is collected and why. A caregiver's certifications, schedules, performance notes and the GPS coordinates on her clock-ins all sit in that box, and the notice duty sits on the agency. The defensible design for location data is proportionality: capture it at the clock-in and clock-out moments, where it serves the legitimate purpose of verifying the visit, tell caregivers exactly that, and do not track movement continuously. An agency that can show a caregiver precisely when and why her location is recorded is compliant and, just as valuable, trusted by its own staff.

See Carelyst with your own clients and caregivers.

Start your 14-day free trial

No credit card to start · Cancel anytime