Three independent federal watchdogs, working separately over roughly two years, have each found the same underlying problem: Ottawa cannot reliably show that contractors working on the ArriveCAN border app and related outsourced information-technology projects held the security clearances they needed, or that departments kept the paperwork proving it.
The most recent finding came March 12, when Privacy Commissioner Philippe Dufresne tabled a special report to Parliament on the Canada Border Services Agency’s contracting practices for ArriveCAN. The report examined nine contracts and 15 task authorizations covering 13 contractors who had access to the app’s production environment, where the personal and health information of roughly 60 million travellers was stored between April 2020 and October 2022.
The commissioner’s office found that one contractor worked without a valid security clearance for about 18 months, after an earlier clearance expired in January 2019 and was not renewed until October 2020. It also found that six of the 13 contractors granted access to the production environment did not require that access to do their jobs, and that one required security check was completed four years before the contract was actually awarded, raising questions about whether it still reflected the work being done. CBSA’s own procurement files, the report said, were missing required documentation of security clearance transfers for two other contractors.
The commissioner’s office said it found no evidence that personal information was used or disclosed improperly, and it deemed the underlying complaint, filed in March 2024, “not well-founded” on that specific question. CBSA accepted all of the office’s recommendations, which call on the agency to complete security assessments before contracts are awarded, define contractors’ work clearly enough to identify what access they actually need, and restrict data access to what is strictly necessary.
That report echoes findings the Office of the Procurement Ombud reached more than two years earlier. In a practice review of ArriveCAN’s contracting published in January 2024, the ombud’s office found that in at least one case, a contract calling for personnel to hold a Secret-level security clearance was carried out under a task authorization that required only the lower “reliability status” clearance. The review also found that while CBSA was ultimately able to produce records showing personnel security requirements had been confirmed for people who worked on ArriveCAN, those confirmations were “frequently not retained in the contract file,” and that only six of 27 applicable contract files initially showed proof they had been shared with the federal government’s central Contract Security Program, though the department later said most had been shared, not always on time.
Five months before the Privacy Commissioner’s report, the Auditor General’s office reached a similar conclusion at a larger scale. A June 2025 audit of federal professional-services contracts awarded to GC Strategies Inc., the Ottawa staffing firm at the centre of the original ArriveCAN controversy, examined 106 contracts worth $92.7 million awarded by 31 federal organizations between April 2015 and March 2024, four of them tied to ArriveCAN. The Auditor General’s office reported that in 21 per cent of the contracts examined, federal organizations lacked documentation on file showing valid security clearances for the people doing the work.
None of the three reviews alleges that classified information or Canadians’ personal data was actually compromised, and each covers a different, narrower slice of federal contracting rather than a single incident. But read together, they document a specific and recurring administrative failure, verifying and keeping records of who is cleared to access sensitive government systems and personal data, that has now been independently identified by three different oversight bodies over roughly two years, the most recent finding coming five months after the Auditor General’s report and about two years after the original Procurement Ombud review.
GC Strategies was barred from federal contracting for seven years in 2025 following the broader ArriveCAN controversy, CBC News has reported. CBSA has said it accepted the recommendations from all three reviews and has pointed to steps including mandatory procurement training and compliance reviews of contract files.
What remains unclear from the public record is whether the clearance-verification gaps identified in the Privacy Commissioner’s March report involve contracts awarded after CBSA’s earlier commitments to reform, or predate them. The Privacy Commissioner’s office has not published a timeline showing when each of the nine contracts it examined was awarded relative to CBSA’s response to the 2024 Procurement Ombud review. Resolving that question would require CBSA to release, or Parliament’s public accounts committee to request, contract-by-contract dates alongside the security clearance findings.









