This Privacy Impact Assessment (PIA) is in relation to a proposal to substantially modify Personal Information Bank (PIB) PWGSC PPU 015. Among the changes to the PIB is a thorough description of the consistent uses of personal information collected by the Industrial Security Program (ISP) of the Canadian Industrial Security Directorate (CISD). In addition to sharing personal information with the RCMP, CSIS, and credit bureaus in furtherance of determining a person's eligibility in the ISP, the consistent uses of personal information includes sharing some personal information (i.e. screening and security clearance information) to a select group of authorized persons. Those authorized persons include: PWGSC Procurement Officers, Project Authority Officials, and authorized Security Officials; authorized Security Officials are the following government officials: Departmental Security Officers and Unit Security Officers; and the following private sector officials: Company Security Officers and Alternate Company Security Officers.
The disclosure of “screening and security clearance information” will be done via two methods: telephonically and through the future expansion of the Online Inquiry Service (OIS), a web-based application currently used by some of the authorized persons in obtaining the needed “screening and security clearance information”. The expansion of OIS will include the inclusion of authorized persons who are currently not users of the system. Also, it will include the release of additional information that is not currently available to existing authorized users.
Moreover, the revised PIB includes a reference to the sharing of personal information with PWGSC’s Controlled Goods Program (CGP), which is also referenced in their PIB, PWGSC PIB PPU 045.
The purpose of the ISP is to safeguard Protected and Classified information and assets entrusted to industry for contracts administered by PWGSC and, on request, for contracts administered by other government departments (OGDs). Part of that mandate is to assess a person's eligibility for a screening or security clearance level to work for the government, on a government contract, or to respond to a Request for Proposal (RFP).
A person typically applies for a screening or security clearance level through a Departmental Security Officer (a government authorized Security Official) or a Company Security Officer (a private sector authorized Security Official). When applying, a person's signature authorizes the sharing of personal information to facilitate the investigation of the person's eligibility to hold a particular screening or security clearance level. Once the screening or security clearance level is granted, the person's status/clearance level is “held” by the organization (governmental department or private sector company) that submitted the application.
In furtherance of it's goal to assist in facilitating the awarding of government contracts to authorized persons, it has historically been common practice for CISD to release details of a person's screening status or security clearance level regardless of which organization held the clearance. The information was released to authorized Security Officials, PWGSC Procurement Officers, and Project Authority Officials only, and contained the least amount of information possible for these persons to staff government contracts and/or respond/award bids to an RFP.
In October 2008, CISD implemented a short-term solution that required consent forms from individuals, as well as attestation forms from authorized Security officials (stating they would not misuse the information). While addressing this short-term solution PWGSC PIB PPU 015 was identified as falling far short of what is required of a PIB.
In addition to better explaining the personal information collected and its consistent uses, the scope of this project is to eliminate the need for consent forms, while also revising PIB PPU 015 (referenced on all security forms) so that it succinctly and precisely spells out the personal information collected and how and why CISD uses it.
In essence, this project desires “screening and security clearance information” to be released to authorized Security Officials, PWGSC Procurement Officers, and Project Authority Officials upon their request (after validation of their identity). The screening and security clearance information desired to be released to these persons would be done through CISD’s Call Centre, as well as the expansion of a web-based application (Online Inquiry Service) to allow users the ability to verify the information electronically. OIS would be expanded, but would also include mandatory search criteria to eliminate random searching by such indiscrete fields as “first name”.
This resulted in meetings between multiple agencies who have related PIBs involving personnel security. These meetings involved Public Works and Government Services Canada (PWGSC) (specifically CISD), Treasury Board Secretariat (TBS), Royal Canadian Mounted Police (RCMP), and Department of Defence (DND) in reference to the following PIBs:
A collaborative effort is underway among these agencies to revise Treasury Board security clearance forms (TBS/SCT 330-23 and TBS/SCT 330-60) while also aligning each agency’s PIBs with similar language. Therefore, the revised PIB may be amended to accommodate this parallel effort with TBS, DND, and RCMP. Moreover, changes to the Privacy Act Statement and consent declaration of TBS/SCT 330-23 and TBS/SCT 330-60 in Annex D and E may also occur.
For private sector authorized Security officials the information is provided only if the person in whom they are inquiring about is an employee of their organization, or the person has provided an appropriate consent form.
The information is obtained by contacting the Call Centre, who validates the identity of the authorized individual, verifies consent is provided (if necessary), and emails the information in the following table to the authorized individual. The Call Centre requires the authorized security official to provide the individual's name and date or birth; or name and personnel identification number. As most individuals do not know their personnel identification number, the use of an individual's date of birth is the only means available to properly identify an individual from the 350,000+ persons in the database.
For some authorized users, the information can also be obtained through the Online Inquiry Service (OIS). For private industry persons, the security currently in place allows private sector authorized Security Officials access to their own employees only. OIS capabilities are expanded for PWGSC users, wherein they can view the name of the organization that holds the clearance.
CISD proposes to provide to authorized Security Officials, PWGSC Procurement Officers, and Project Authority officials on all persons in the Industrial Security Program.
An authorized person could obtain this information from the Call Centre in the same manner that is used currently, or through OIS. OIS would be expanded to include the data fields/elements below.
To avoid private companies from randomly searching on competitors, mandatory search criteria will be used. A determination regarding the types of mandatory search criteria will be determined at a later date.
Data Field | Explanation of Data Field/Data Values | |
---|---|---|
Name | Name of Individual | |
Date of Birth | Individual’s date of birth | |
Personnel ID # | Number assigned to individual by CISD and associated to CISD file. | |
Name of Organization Holding Person’s Screening/Clearance |
Company that submitted the individual’s screening/clearance application. All users of OIS would be able to search on/view this information. |
|
Individual Level |
|
|
Individual Status |
|
|
Individual Type |
|
|
Date Initiated | Date security forms were submitted to CISD | |
Date Completed | Date eligibility assessment was completed | |
Date Granted | Date the level was granted | |
Date of Renewal | Date the level requires renewal |
As with the current practice, it is imperative to note that the status of “Denied” is not permitted to be released to anyone. Although the status is used by CISD for those persons whose application was denied, privacy issues preclude CISD from releasing that status. For those person’s whose status has been denied, CISD releases the status of “Close-Out”.
As indicated in the table, CISD wishes to continue using the same data elements with the addition of releasing the name of the organization that holds the individual’s clearance. By including this additional data element, companies that are bidding on government RFPs are able to check the status of a person’s screening or clearance, as well as the name of the organization that holds the clearance. This data is necessary in order for the many types of companies to submit a bid to an RFP, submit proposed personnel to an open contract competition, and for the Government of Canada to ensure that properly cleared individuals and companies are being chosen to perform work on contracts that include security considerations. Moreover, in some fields where government contracts include a prime contractor and multiple layers of subcontractors, it is important for the prime contractor to verify security clearance information on sub-contractors.
Through this PIA and the parallel effort of amending Treasury Board forms and the PIBS of PWGSC, TB, RCMP, and DND, CISD desires to eliminate the need for the consent forms that have been in place since October 21, 2008.
During this Privacy Impact Assessment several privacy risks were identified. In fact, privacy risks were the driving force behind the CISD management's decision to halt the current, yet long-standing practices, of the ISP. In revising the PIB and completing the PIA, the following risks were identified and addressed:
To conclude, the privacy risks that exist with the current PIB and the accompanying operating procedures of CISD are being addressed as a result of this PIA, and the revised PIB, and proper communication to those affected will be ensured.