Privacy Impact Assessment for Self-Identification Modernization
The Office of the Chief Human Resources Officer (OCHRO) supports the Treasury Board in its role as the employer by driving excellence in people management and ensuring the appropriate degree of consistency across the public service. OCHRO fulfills this mandate in a manner that is compatible with primary deputy head accountability and responsibility.
In 2020, in keeping with its mandate to support equity, diversity and inclusion in the public service, OCHRO launched its Self-Identification Modernization Project. Its purpose was to review and assess employee self-identification processes, practices, and systems, and to update the Government of Canada’s Self-Identification Questionnaire.
Why a Privacy Impact Assessment was completed
OCHRO elected to undertake a PIA in relation to the Self-Identification Modernization Project and the development of the new Self-Identification Questionnaire. Although information collected from the Self-Identification Questionnaire through Phase 1 of the Project will not be used to make decisions that directly affect federal employees, the Self-Identification Questionnaire will collect personal information. The Self-Identification Modernization Project will also impact the manner in which personal information is collected and processed by TBS and the Government of Canada.
In 2024, an Addendum to the original Phase 1 PIA was completed for this Project to support the integration of an alternative format Self-ID Questionnaire (AFSI) and a protocol for the distribution, collection, storage, and data entry of the AFSI Questionnaire.
The implementation of the AFSI questionnaire enables the inclusion of employees who cannot complete their self-identification in the centralized, online Self-ID Application due to:
- a disability-related accommodation need that is not being met by the accessibility features in the application
- an operational situation that prevents the employee from accessing the application at any point in the fiscal year (for example, working in remote areas without reliable internet access)
The Phase 1 PIA and the Addendum were completed under the direction of OCHRO’s Experimentation and Partnerships group and approved by TBS’s Director of Access to Information and Privacy (DAIP), TBS’s delegate for administering section 10 of the Privacy Act.
Additional information
Phase 1, Self-Identification Modernization PIA:
- Lack of clarity around OCHRO’s legislative authority to collect an expanded set of equity, diversity and inclusion (EDI) information for administrative or non‑administrative purposes - risk mitigated - OCHRO has established that it has the authority to collect EDI information through the new Self‑ID Questionnaire to fulfill the Treasury Board’s obligations as employer under the Employment Equity Act and to support its responsibility for effective human resource management under the Financial Administration Act.
- Lack of clarity on whether the protection of an individuals’ rights under the Canadian Charter of Rights and Freedoms has been given sufficient consideration – risk mitigated – Self-ID information is being collected from individuals on a voluntary basis and with proper legal authority.
- Lack of documented evidence of due diligence, including formalized public policy or documented decisions – risk mitigated – A robust operational and policy framework has been established by OCHRO to ensure that the Self-ID Modernization Project is properly managed and that accountability and responsibility for privacy issues arising from the Project are assigned and documented.
- The purpose of collection, use and disclosure of EDI personal information has not been clearly identified and supported by documented policy and procedures – risk mitigated – Privacy notifications have been developed and finalized for inclusion in the online Self-Identification Application, which resides on the TBS Application Portal.
- Multiple retention and disposition policies in place for employment equity data collected by OCHRO, Public Service Commission and the Core Public Administration HRIS – risk mitigated – Self-ID information will be retained by the Government of Canada for a minimum of two years and a maximum of 10 years following an employee’s departure from the federal public service. This is in keeping with the identified retention and disposal schedules and authorities associated with the personal information.
- Risk of over-collection through the use of open text boxes – risk mitigated – Open text boxes have a limited character count (50) to discourage the entry of excess detail. Furthermore, a footnote is including, asking individuals to avoid including sensitive personal information such as medical history, names of individuals or accounts of workplace issues.
- At the time of drafting the PIA, an up-to-date and viable threat risk assessment (TRA) or security assessment and authorization (SA&A) in relation to the application had not been performed – risk mitigated – Both the TBS Application Portal (TAP), which will house the Self-ID Questionnaire, and its supporting Self-Identification application/database have undergone TBS’s SA&A process and have received an Authority to Operate (ATO).
- The use and disclosure of the EE / EDI personal information during an administrative use of the data could reveal information about the individual that was not publicly known and may present a risk to the individual, which could be manifested in a variety of ways including, but not limited to, personal safety and security – risk mitigated – As stated above, both the TBS Application Portal (TAP), which is to house the Self-ID Questionnaire, and its supporting database, the SIDB, have undergone TBS’s SA&A process and have received an Authority to Operate (ATO). Security and vulnerability testing will continue throughout the systems’ use, in keeping with TBS security policies.
Addendum to Phase 1 Self-Identification Modernization PIA: Alternate Format Self-ID (AFSI) Questionnaire, policies and procedures
- There may be variation in how each department carries out its responsibilities for managing the distribution, collection, storage, and data entry of the AFSI Questionnaire – risk mitigated – Messaging will be sent prior to the release of the Self-ID App to ensure that all department heads of human resources (HHR) and all AFSI stewards are aware of their responsibilities and accountability.
- Departments may assign the duties of AFSI steward to employees who do not have the appropriate security clearance – risk mitigated – The AFSI Protocol and the Self-ID ISA both specify that all departmental AFSI stewards, including students and contractors, have a reliability level security clearance.
- Employees assigned to fulfill the duties of AFSI steward may not have sufficient knowledge about how to handle and safeguard personal information in compliance with the Privacy Act – risk mitigated – The AFSI Protocol and the Self-ID ISA both specify that all departmental AFSI stewards, including students and contractors, must complete training in privacy and data stewardship, such as the Canada School of Public Service course: Privacy in the Government of Canada.
- Employees using the AFSI Questionnaire may not be aware of the purpose of self-ID data collection, use and disclosure of EDI personal information – risk mitigated – The AFSI questionnaire will include the same information that appears in the online Self-ID App about the purpose, collection, and management of self-ID data as well as a formal long-form privacy notice (Appendix D). This information will appear on the pages that precede the questionnaire, modified where necessary to reflect any AFSI-specific procedures for the management of self-ID information.
- There is a risk of over- and under-collection through the entry of information by AFSI stewards that employees provide in the open text boxes in the AFSI Questionnaires – risk mitigated – AFSI stewards are required to enter in all text provided by employees in the open text boxes of the AFSI Questionnaire to ensure that this data is treated in the same way as data entered directly by employees in the online Self-ID Application during the data sorting and sanitization process. To limit collection of information outside the scope of the Self-ID Questionnaire, the AFSI Questionnaires contain the same privacy reminders described in the primary Self-ID Phase I PIA.
- Employees who need to use an AFSI Questionnaire to complete their self-identification may have concerns about how to modify or delete their self-ID data from the centralized Self-ID Database – risk mitigated – The AFSI Protocol includes procedures and notification templates for AFSI stewards to let employees know how they can modify their self-ID information.
Related personal information banks
Self-Identification Modernization
Bank number: TBS PCU 760
For more information about this Privacy Impact Assessment
Michael Wesley-James
Director, EDI Tools and Data Policy
