Shared Services Canada’s technology assessment for privacy implications
Contact Centre as a Service (CCaaS) – TTEC Solution
Description
Shared Services Canada (SSC) completed a Technology Assessment for Privacy Implications (TAPI) for the Government of Canada’s Contact Centre as a Service (CCaaS) solution delivered by TTEC as a managed service, leveraging a cloud-based platform built on Amazon Connect. The assessment evaluates the privacy implications of the technology itself.
Why a Technology Assessment for Privacy Implications (TAPI) was completed
Following Treasury Board Secretariat (TBS) updates in 2024, SSC developed a TAPI instrument to assess enterprise technologies, as the Standard on Privacy Impact Assessment applies to program-level activities rather than technologies. The TTEC CCaaS solution is a new service offered by SSC, and this TAPI outlines solution-level privacy considerations to support departments in completing their own Privacy Impact Assessments (PIAs).
Summary of privacy risks and mitigation measures
Key privacy risks identified include the collection of additional technical metadata (e.g., IP addresses, user activity logs), potential over-collection through reporting or transcripts, limitations in contractual privacy clauses, and challenges related to retention, user-account dormancy, and cross-border data exposure through sub-processors.
Mitigation measures include:
- Limiting collection to operational and authentication needs
- Ensuring clear delineation of departmental responsibilities for PIAs
- Establishing governance related to reporting and analytics outputs
- Implementing role-based access controls and least-privilege access
- Defining retention, disposition, and dormant account management practices
- Requiring encryption, monitoring, and contractual safeguards
The assessment also emphasizes the importance of user training and notice to ensure that personal information is handled appropriately within the solution.
Related personal information banks (PIBs)
The solution itself does not require a dedicated Personal Information Bank (PIB), as PIBs are generally associated with program activities. Instead, SSC accounts for personal information within a Class of Personal Information related to service desk activities.
Additional information
The CCaaS platform processes personal information related to callers and contact centre agents, including call detail records, identifiers, and interaction metadata necessary for routing, service delivery, and performance monitoring.
The solution is delivered as a Software-as-a-Service (SaaS) model, with responsibilities shared between SSC and the service provider. Data is required to reside in Canadian data centres when at rest at the Protected B level; however, the assessment notes that limited personal information (e.g., agent identifiers and IP addresses) may be accessible or processed by sub-processors outside Canada (e.g., in the United States).
The platform includes safeguards such as encryption (in transit and at rest), role-based access controls, logging and monitoring, and audit capabilities to support compliance with the Privacy Act and Treasury Board policies. It also enables retrieval of personal information to respond to Privacy Act requests.