Ottawa, October 24, 2013 — The Director of the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Gérald Cossette, issued the following statement today in response to the release of the Privacy Commissioner's 2013 audit on the measures taken by FINTRAC to protect personal information.
"Safeguarding the information entrusted to FINTRAC is an overarching and fundamental consideration in all aspects of our operations. We understand the protection of privacy is critical to maintaining Canadians' confidence in FINTRAC and the broader anti-money laundering and anti-terrorist financing regime. This is why clear principles for the protection of privacy are set out in our governing legislation and are reinforced by our own operational policies and security measures."
"It is important to note that FINTRAC does not have the authority or the means to access the bank accounts of Canadians or to monitor their financial activities. We build our financial intelligence from the information provided to us by reporting entities and we do so strictly in accordance with the law."
"We welcome the Privacy Commissioner's audit, which is called for by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act. We are pleased the audit recognizes that FINTRAC has in place a comprehensive approach to security, including controls to safeguard personal information."
"We are also pleased the Privacy Commissioner found no evidence that personal information had been used for any purpose other than that for which it was obtained, and that our disclosures were tightly controlled and made in accordance with our legislation."
"Finally, we are pleased the Privacy Commissioner acknowledged the enhancements we have made to our privacy management program, with the creation of a formal Chief Privacy Officer position, a privacy impact assessment process and increased awareness among our staff of core privacy principles."
"FINTRAC accepts all of the Privacy Commissioner's recommendations for improvement and the Centre is implementing changes to our systems and processes to address the outstanding issues. For example, in cases where we receive information that does not meet threshold requirements, we have put in place a process to segregate that information so that it cannot be used for analysis and thus cannot be disclosed to law enforcement or national security partners. We have also put in place a process to destroy information that does not meet legislated thresholds for reporting."
"As FINTRAC helps to protect the safety of Canadians and the integrity of Canada's financial system through the detection and deterrence of money laundering and terrorist activity financing, we will continue to ensure that we safeguard the personal information under our control."