CSE’s management response to recommendations in NSIRA’s review of CSE’s Signals Intelligence data retention

Table of contents

Recommendation 1:

NSIRA recommends that CSE immediately delete the data determined to have no foreign intelligence value in inspection 1 and 4, as retaining this data is not reasonably necessary.

CSE response to Recommendation 1:

CSE disagrees with this recommendation.

CSE disagrees with the conclusion that the information collected has no foreign intelligence value. Under the foreign intelligence aspect of the Establishment’s mandate, CSE lawfully acquires, uses and analyses information authorized by the CSE Act and Ministerial Authorizations, in accordance with the Government of Canada’s foreign intelligence priorities, which are dynamic and subject to global events. All lawfully-collected foreign intelligence is valuable. A collected dataset may serve multiple foreign intelligence purposes and therefore, there is risk in deleting information prematurely based on its assessed lack of value for a specific intelligence purpose.

Recommendation 2:

NSIRA recommends that CSE amend the Mission Policy Suite to create a category for non-Canadian information determined to have no foreign intelligence value, and set a timeline for its deletion that ensures it is retained for no longer than reasonably necessary.

CSE response to Recommendation 2:

CSE disagrees with this recommendation.

Under the foreign intelligence aspect of the Establishment’s mandate, CSE lawfully acquires, uses and analyses information authorized by the CSE ACT and Ministerial Authorizations, in accordance with the Government of Canada’s foreign intelligence priorities, which are dynamic and subject to global events. All lawfully-collected foreign intelligence is valuable. A collected dataset may serve multiple foreign intelligence purposes and therefore, there is risk in deleting information prematurely based on its assessed lack of value for a specific intelligence purpose.

Recommendation 3:

NSIRA recommends that CSE establish a process for the handling of traffic items that contain both information with foreign intelligence value and information that must be deleted.

CSE response to Recommendation 3:

CSE agrees with this recommendation.

CSE has an established process for handling traffic items that employs multiple layers of controls to ensure protection of the information it acquires.

As technologies and our systems evolve, CSE will continue to look for new opportunities to improve the handling of traffic items, including at the most granular level possible.

Recommendation 4:

NSIRA recommends that CSE develop mechanisms and staff training to ensure that it stops targeting [Redacted] when intelligence analysts determine [Redacted] is no longer of foreign intelligence interest.

CSE response to Recommendation 4:

CSE agrees with this recommendation.

CSE already has mechanisms and provides training to ensure analysts stop targeting that no longer contributes to foreign intelligence requirements. CSE continuously reassesses to determine whether or not requirements for foreign intelligence relevance are met, and conducts periodic manual audits to ensure compliance.

Processes and training materials are continually updated to ensure they capture best practices. CSE will continue to look for ways to enhance analyst training and awareness.

Recommendation 5:

NSIRA recommends that CSE ensure that the information concerning retention of [Redacted] information in its applications for foreign intelligence authorizations reflects its actual retention practices. If CSE chooses to retain such information [Redacted] it must establish a mechanism to ensure it is retained for no longer than reasonably necessary.

CSE response to Recommendation 5:

CSE disagrees with this recommendation.

CSE's applications for Foreign Intelligence Authorizations request the authority to retain various types of information based on clear rationales which have been deemed reasonable by the Minister and the Intelligence Commissioner.

Recommendation 6:

NSIRA recommends that CSE update the Mission Policy Suite to eliminate ambiguity about SIGINT data stored in peripheral systems, and provide direction on how to ensure compliance with retention requirements.

CSE response to Recommendation 6:

CSE agrees with this recommendation.

CSE is currently updating the MPS FI to make it clear that the policy requirements and retention schedules must be applied to all SIGINT data regardless of media or location.

CSE has made significant efforts to consolidate SIGINT operational holdings. At all times, analysts must abide by the requirements in the MPS FI for the processing, handling, and analysis of that data, including its storage and retention.

Finding 10:

NSIRA found that CSE’s sharing of SIGINT data with other agencies, such as Five Eyes partners, limits its ability to directly ensure data is retained according to CSE policies.

CSE response to Finding 10:

CSE disagrees with this finding.

CSE has long-standing and effective layered compliance methods in place with its Five Eyes partners to ensure data is retained according to CSE policies.

Compliance alignment amongst the Five Eyes partners is achieved through shared technical standards for data exchange, interoperable incident reporting procedures, national policy knowledge accreditation requirements, and close partner engagement.

Shared technical standards allow data to be tracked, tagged and purged to meet compliance requirements and data purge requests. Interoperable incident reporting procedures allow analysts from each agency to report compliance incidents to partners.

Each agency imposes an annual policy knowledge re-accreditation obligation on its own analysts. Compliance executives meet annually to strengthen compliance collaboration, and compliance engagement occurs at management and working level through monthly teleconferences and ad-hoc information sharing.

Date modified: