The RGBB service modernization will continue to enable RGBB clients to use the RGBB for credit card and now also Interac as payment processing methods. The payment information is processed electronically using the RGBB service from RGBB clients' web sites (also known as storefronts) that accept electronic payments.
RGBB clients will continue to use the RGBB service as a means to process payments from individuals of the general public. The RGBB provides the necessary tools to allow RGBB clients to manage online, mail orders and /or in-person payment for goods or services, through the provision of authentication, and administration processes. The use of these processes facilitates secure and private exchange of customer payment data with payment processing service providers on behalf of RGBB clients.
The user community for the RGBB Service consists of:
The different clusters of personal information collected or used during the various RGBB business processes are as follows:
The application also collects and retains transaction data from the selling department that is required for processing the transaction. This information includes the selling department's ID, transaction type, departmental reference number, transaction amount and the language last used by the customer on the department's website (so that the RGBB web pages can be presented in the same language for consistency). Transaction data collected from the department is assigned a RGBB transaction ID and the data collected from the customer is appended to that record.
The new personal information collected or used during the various upgraded RGBB business processes is as follows:
Other information elements pertaining to the customers' online transactions are also collected or used, such as customer session logs, content of temporary cookies and signature verification logs. The architecture design specifications, however, do not permit these information elements to identify individuals or to be linked to individuals.
The customer is provided with the opportunity to review the RGBB privacy statement on the payment page where they are required to submit personal information. The privacy statement describes the reason for collection, the specific use, the retention period, disposal procedures and Personal Information Bank (PIB) where the personal information is stored.
The RGBB administrative web interface is used to perform the following:
Privacy risks and potential risk mitigation measures have been identified in the PIA report. These risks are summarized below.
A number of privacy risks have been identified with the RGBB upgrade service and are evaluated at 'low' in severity with a plan to mitigate these risks within an acceptable timeframe.
It is important to note that the RGBB basic business model has not changed only the service provider and the collection of two additional pieces of personal information which will ensure accurate and secure payments are processed. The introduction of a payment gateway with multiple options within the RGBB may raise privacy concerns. In that context, customers should be reminded that privacy protection was and remains a pivotal factor for the RGBB's choice of subcontracting to a PCI DSS Level 1 certified processing vendor. Customers who wish to further protect their privacy can also elect to procure RGBB client services using different payment options such as credit card and Interac, thereby rendering the Credit Card Number a payment processing specific identifier, and not a common identifier.