Responses to NSIRA’s review: Annual Review of Select Canadian Security Intelligence Service Activities, 2024
Recommendation 2:
NSIRA recommends that CSIS evaluate all its publicly available and “referential” datasets for the presence of information which may attract a reasonable expectation of privacy, and that this evaluation be conducted by employees with the necessary expertise.
Related finding(s)
Finding 2: NSIRA found that CSIS is at risk of collecting information that is publicly available, but for which there may be a reasonable expectation of privacy, as was noted in NSIRA’s Review of CSIS Dataset Regime (21-15).
Finding 3: NSIRA confirmed that CSIS destroyed datasets that were no longer strictly necessary to retain as per Recommendation 7 in NSIRA’s Review of CSIS Dataset Regime (21-15).
Government response
CSIS partially agrees with Recommendation 2 and finding 2. CSIS agrees with Finding 3.
CSIS does not consider information that was made available to the public through unlawful means to be a publicly available dataset, but as a foreign or a Canadian dataset. CSIS assesses this at the point of collection and during the evaluation of each dataset.
CSIS agrees it should evaluate new publicly available datasets for the presence of information that may attract a reasonable expectation of privacy.
CSIS does not agree with re-evaluating its existing publicly available datasets for the presence of information that may attract a reasonable expectation of privacy.
CSIS already has a robust evaluation process, beginning with an initial assessment as to whether the dataset is a foreign, or a Canadian, or publicly available dataset. As an integral part of this evaluation, CSIS conducts a careful examination of the dataset to determine whether it contains any information that may be subject to a reasonable expectation of privacy, and takes steps to protect such information as required by law and CSIS policies.
Each dataset is evaluated by designated employees, who through specialized training and experience, have developed expertise in verifying the potential of hacked, leaked, and stolen data, as well as assessing the presence of personal information and the reasonable expectation of privacy. Designated employees adhere to applicable policy and procedures, and may consult experienced peers on complex cases. Designated employees may also proactively delete information from a publicly available dataset that is deemed irrelevant to CSIS’ mandate. CSIS will continue to ensure its designated employees receive the necessary specialized training and continue to develop their expertise to ensure proper evaluation and assessment of datasets.
Referential datasets, such as geographic names and maps, do not contain personal information and therefore does not attract a reasonable expectation of privacy. CSIS no longer treats IP addresses as referential datasets.
CSIS will continue to review and refine its policies and procedures to ensure a balance between national security and individual privacy rights.
Recommendation 3:
NSIRA recommends CSIS trigger the application of section 20(2) of the CSIS Act in relation to potentially unlawful conduct by CSIS employees, including potential violations of the Canadian Charter of Rights and Freedoms.
Related finding(s)
Finding 4: NSIRA found that CSIS may not have acted in compliance with the law when it failed to submit reports to the Minister under s. 20(2) of the CSIS Act regarding potentially unlawful conduct by CSIS employees, including potential violations of the Canadian Charter of Rights and Freedoms.
Government response
CSIS agrees with Recommendation 3.
Historically, CSIS has interpreted its s. 20(2) reporting obligation to the Minister of Public Safety to only include employee conduct that could be prosecuted as an offence. Following amendments to the CSIS Act, including the introduction of the Threat Reduction Measures (TRM) Regime and the justification framework, CSIS began to reassess its interpretation of s. 20(2).
In March 2025, the Director of CSIS approved broadening the interpretation of s. 20(2) reporting obligations to include conduct lacking statutory authority and potential Canadian Charter of Rights and Freedoms violations. This broadened interpretation will be implemented going forward. This is consistent with CSIS’ longstanding respect and adherence to the Canadian Charter of Rights and Freedoms in everything we do.
CSIS disagrees with Finding 4.
Prior to March 2025, CSIS would report to the Minister of Public Safety on any actions that could constitute a prosecutable offence—in line with CSIS’ historic interpretation of s. 20(2). In addition to such s. 20(2) reporting, instances regarding potentially unlawful conduct (including potential violations of the Charter) are submitted annually by CSIS to the Minister of Public Safety pursuant to s. 6(4) of the CSIS Act.
Recommendation 4:
NSIRA recommends that CSIS explicitly and adequately report on significant legal issues facing CSIS and efforts undertaken to address them in the Director’s Annual Report to the Minister on CSIS Activities, as set out in the Ministerial Direction on Accountability.
Related finding(s)
Finding 5: NSIRA found that there was insufficient attention dedicated to significant legal issues within the Director’s Annual Report to the Minister of Public Safety.
Finding 6: NSIRA found that CSIS introduces risks of stereotyping non-Canadian security clearance applicants from identified countries by issuing special country briefs in their security clearance assessment detailing generalized threat-related activities of the foreign government with no connection to the applicant besides their citizenship.
Government response
CSIS agrees with Recommendation 4 and Finding 5.
CSIS has long reported on legal issues through the Annual Report to the Minister on CSIS Operational Activities, but has not always labelled them explicitly as such.
In order to improve its reporting on legal issues, CSIS has explicitly outlined legal issues and explained its efforts to address them, through a dedicated new section in the 2024-25 Annual Report to the Minister on CSIS Operational Activities.
CSIS disagrees with Finding 6.
CSIS’ security assessments provide fact-based information about national security risks associated with certain countries. These assessments assist government departments, who may be targeted by hostile foreign actors, in making informed decisions on who may have access to classified information.
CSIS’ special country briefs are designed to reflect the current threat landscape, without bias or discrimination, and are updated regularly to ensure that they accurately capture evolving risks and threats posed.
Security assessments are just one component of sources of information a government department may consider in its decision-making process on a security clearance application.
Recommendation 5:
NSIRA recommends that CSIS: a) prioritize updating its governance and policies to align with Ministerial Directions, and b) collaborate with Public Safety to prioritize updating the 2020 Framework for Cooperation with Public Safety Canada and the Canadian Security Intelligence Service.
Related finding(s)
Finding 7: NSIRA found that certain CSIS policies and procedures do not fully align with the Ministerial Direction on Threats to the Security of Canada Directed at Parliament and Parliamentarians and the Ministerial Direction for Operations.
Government response
CSIS agrees with Recommendation 5 and Finding 7.
CSIS recognizes the importance of updating its policies and procedures to fully align with Ministerial Directions. As indicated in NSIRA’s review, CSIS has updated many policies, with several more in progress. CSIS will continue to focus its efforts on ensuring that its governance aligns with Ministerial Directions.
Public Safety Canada and CSIS have had preliminary discussions about the need to align the Framework for Cooperation between Public Safety Canada and the Canadian Security Intelligence Service with the 2019 Ministerial Direction on Accountability (MD). There is agreement that the first step would be to review the language of the MD to ensure that it continues to be fit-for-purpose. If changes are needed, the first step would be for the Minister to issue an updated MD, which would be followed by an updated and aligned Framework for Cooperation.
Recommendation 6:
NSIRA recommends that CSIS follow the governance protocol approved by the Minister in taking actions pursuant to the Ministerial Direction on Threats to the Security of Canada directed at Parliament and Parliamentarians.
Related finding(s)
Finding 8: NSIRA found that select operational activities carried out pursuant to the Ministerial Direction on Threats to the Security of Canada Directed at Parliament and Parliamentarians, did not meet all the requirements of the governance protocol supporting the Ministerial Direction.
Government response
CSIS agrees with Recommendation 6.
Since its implementation, CSIS has worked to follow all of the requirements of the governance protocol approved by the Minister in taking actions pursuant to the Ministerial Direction on Threats to the Security of Canada directed at Parliament and Parliamentarians.
CSIS disagrees with Finding 8.
The governance protocol was being implemented concurrently with certain select operational activities reviewed by NSIRA. In this circumstance, given the unique timing, the threat reduction measures reviewed by NSIRA was approved prior to the Protocol being finalized.
