Privacy Legislation Compliance
When sending emails, you need to ensure that you are complying with all applicable privacy legislation, namely Canada's Anti-Spam Legislation (CASL), Access to Information Act (ATIA), Protection of Privacy Act (POPA), and Health Information Act (HIA) (university employees who are also custodians under HIA). The Information, Privacy and Records Management Office (IPRMO) manages access and privacy matters and provides advice and guidance in support of the requirements of ATIA and POPA.
Please note that although the U of A follows sound IT practices and due diligence to provide secure, private and reliable email services to its users, you must exercise caution when using email to communicate confidential or sensitive matters, especially when using third-party apps like Campaign Monitor.
Visit the IST website for more information about email privacy and the IPRMO’s POPA page.
ATIA (Access to Information Act)
ATIA is the provincial legislation that provides a legal right for individuals to request access to records held by public bodies, like the U of A, including a right of access to personal information about themselves, subject to limited and specific exceptions set out in ATIA.
POPA (Protection of Privacy Act)
POPA establishes the legal framework for how public bodies in Alberta collect, use and disclose personal information. It grants individuals the right to request corrections to their own personal information, and it governs the creation, use and disclosure of data derived from personal information and non-personal information under specific and limited circumstances.
CASL (Canadian Anti-Spam Legislation)
The Canadian Anti-Spam Legislation (CASL) prohibits the distribution of commercial electronic messages (CEMs) without the express or implied consent of the recipient.. This law can affect how the university uses email to communicate with external audiences for things like third-party advertising or if you are selling a product or service to an external audience/group.
If you have any specific questions about CASL, please contact the Office of General Counsel via gcounsel@ualberta.ca or review CASL related information on the OGC’s Resources web page.
Highly Sensitive Personal Information
When electronically transmitting sensitive health or financial data, share only the absolute minimum required on a strict need-to-know basis. Never use unencrypted email or open messaging tools - always encrypt attached files, redact unnecessary details (like bank details, SINs, or medical diagnoses), and double-check recipient addresses before sending.