Sécurité et conformité
Lynx Compliance - Provincial Privacy (PHIPA, PIPA AB, PIPA BC)
The three provincial privacy statutes that displace PIPEDA in their own jurisdictions - Ontario health information, Alberta and British Columbia private sector - under the existing Canadian Privacy add-on.
lynx_compliance_provincial_privacy
· v19.0.1.0.0
· Complément
Bêta
Ce que cela résout
Lynx Compliance - Provincial Privacy (PHIPA, PIPA AB, PIPA BC)
Three statutes, one module, and no new price line. This extends the existing Canadian Privacy add-on on the same precedent as Law 25 and PIPEDA sharing that feature.
That is a deliberate commercial decision, not an oversight. A Canadian organisation does not choose between these statutes: it is subject to whichever apply to where it operates and what data it holds. Charging separately for each would price a single obligation three times, and an Ontario clinic with staff in Alberta would pay twice for the same privacy programme.
They are kept as separate frameworks rather than merged into one catalogue, because the differences are exactly what an assessor looks for:
Alberta requires breach notification to the Commissioner on a real risk of significant harm, and the Commissioner rather than the organisation decides whether individuals must be told. British Columbia's duty arrived much later and is framed differently, so an organisation in both provinces cannot run one process and assume it satisfies the other.
Alberta and British Columbia both carve out employee personal information with its own consent rules. That carve-out is the main structural difference from PIPEDA and the one most often missed.
Ontario's PHIPA has neither concept. It has the circle of care, the lock-box, and electronic health record audit logging, which the other two do not.
Key Features
78 obligations across three frameworks - 29 for PHIPA, 25 for Alberta, 24 for British Columbia, coded by statutory section.
No new SKU - extends compliance.canadian_privacy, so an existing Canadian Privacy customer gets all three at no additional cost.
Cross-references that actually resolve - populated against real PIPEDA and Law 25 control codes rather than section numbers, so an existing Canadian privacy assessment propagates through the crosswalk instead of merely counting towards coverage.
The lock-box treated as a system capability - because a lock-box recorded as a chart note is overridden by whoever reads the record next, and that is the finding.
Employee personal information as its own function - the carve-out gets three controls per province rather than a footnote, including monitoring assessed against the reasonableness test.
The annual PHIPA statistics return included - it falls due whether or not you had a reportable breach, which is why organisations forget it.
Integrates With
lynx_compliance_pipeda and lynx_compliance_law25 - cross-referenced per control against real control codes, so one Canadian privacy programme answers all five statutes.
lynx_compliance_privacy - the DSAR, consent, PIA and breach registers are the evidence for most of this pack.
lynx_compliance_incident - notification assessments and Commissioner notifications.
Essayer Lynx Compliance - Provincial Privacy (PHIPA, PIPA AB, PIPA BC) de votre équipe.
Essai gratuit, sans carte de crédit. Parlez à l'équipe des ventes quand vous êtes prêt.