Other: Standing Committee on Government Operations and Estimates—June 2, 2021
Document navigation for "Standing Committee on Government Operations and Estimates: June 2, 2021"
Contract security for visa application centres
Context
Media and members of Parliament (MPs) have raised the security of personal information at Canadian visa application centres (VAC) and its main supplier VFS Global being affiliated with China.
Suggested response
- Public Services and Procurement Canada (PSPC) is committed to maintaining the highest standards of security in order to protect Government of Canada sensitive information entrusted to contractors including at the VAC
- The protection of personal information is a paramount priority for my department throughout all of its operations, including within the visa application process
- My department is working closely with Immigration, Refugees and Citizenship Canada (IRCC) to review the security and privacy requirements for the contract related to VAC
If pressed on PSPC’s responsibilities:
- on an ongoing and annual basis, my department ensures the contractual compliance to a series of privacy and security requirements including:
- security measures deployed at the VAC
- access control procedures
- close circuit television surveillance system
- fire detection and suppression system
- alarms and intrusion detection system
- guard force management
- floor plan layout
- process integrity and data protection
- staff security screening
- cash handling
- crisis management and business continuity
If pressed on the verification process:
- my department undertook a corporate structure review of VFS Global and its corporate family in October 2020. Based upon the results of this review, there is no evidence that a subsidiary of the Chinese Investment Corporation would be in a position to exert control or influence over VFS Global Group under its current structure
- my department also verified that the supplier was not ineligible or suspended under the Government of Canada’s Integrity Regime prior to contract award
- VFS Global does not store any biometrics data related to a visa application. All data is purged from its systems in accordance with the privacy requirements prescribed by the Government of Canada and is encrypted and instantly transmitted to Canada. VFS continues to comply with all data protection and information technology (IT) security requirements set out in its contract with the federal government
- the biometric equipment housed at each Visa Application Centre belongs to Canada. The equipment was accredited by IRCC IT security in line with the security requirements from the Communications Security Establishment prior to being delivered
If pressed on the ownership of subcontractors within Chinese VACs:
- the federal government was aware that Beijing Shuangxiong Foreign Service Canada was the Beijing VAC subcontractor for VFS Global. However, we were not aware of the corporate ownership structure of the subcontractor in question
- a review of the ownership structure of subcontractors is not part of the regular processes associated with federal procurement
- under the contract, VFS Global must ensure that the privacy and security aspects of the contract are observed in all of their respective subcontracting arrangements
Background
The contract on VAC was awarded to VFS Global in February 2018 and the initial contract period will expire October 31, 2023 with an option to extend the contract by up to 3 additional years. A privacy impact assessment was conducted by IRCC to assess the risk of the contract. On August 20, 2018, VFS Global subcontracted their Beijing facility to Beijing Shuangxiong, the same subcontractor identified in the previous 2013 contract on VAC.
A personnel security verification was completed for each employee working at the visa centre in Beijing as per the provisions of the contract. This is an ongoing activity that began in 2013. The verification is done before employment starts at any visa centre. This requirement was included in both the 2013 contract and the 2018 contract. As per the provisions of the contract, VFS Global is responsible for verifying the reliability and trustworthiness of all employees at the visa centre in Beijing and employees working in support of the centre prior to employment. Assurances are provided to PSPC and IRCC that these checks have been completed, and are being kept informed of any findings that would affect the employees’ security status.
Prior to the contract award, the contractor provided site specific security plans that were reviewed and approved through a rigid evaluation process. All visa application centres are required to provide a threat and risk assessment to address any additional security and privacy mitigations that may be required. Annual security plans for each visa application centre are submitted and reviewed by PSPC Contract Security Program. All building plans are reviewed and approved by the Contract Security Program in conjunction with IRCC. Compliance visits are carried out regularly to ensure that all privacy and security requirements of the contract are being met.
All computers at each visa application centre including the self-serve workstations, have strict contract requirements to purge all information. There is no biometric information stored on any visa application centre computer; the information is transmitted to Canada. Any other personal information collected by the VAC (for example, name and phone number related to an appointment) must be erased or destroyed (purged) within 30 calendar days after services rendered to the applicant are complete. The contractor subcontracted its IT requirement to companies located in Canada who have been vetted and inspected by PSPC Contract Security Program.
All privacy and security incidents are reported to IRCC and PSPC for review and immediate resolution. Every year, oversight contract compliance visits of VACs are conducted by IRCC visa officers/biometric officers working in the field in partnership with the PSPC Contract Security Program. All visit reports were shared with PSPC for comment and to ensure compliance with security aspects of the contract. In addition, the last review of the Annual Security Report submitted by the contractor was conducted in December 2020 for all VACs located in China. Compliance on-site visits were conducted by IRCC in 2019 for 11 sites in Mainland China (Beijing, Chongqing, Chengdu, Shenyang, Nanjing, Kunming, Shanghai, Jinan, Hangzhou, Wuhan and Guangzhou). In 2021, so far, on-site visits were conducted by IRCC at Beijing and Guangzhou. VFS Global and their subcontractors have been compliant with all the security requirements set out in the 2018 VAC contract.
Document navigation for "Standing Committee on Government Operations and Estimates: June 2, 2021"
Page details
- Date modified: