Back to privacy assessments

Privacy assessment

Transfer Safeguards and Controls

Contractual, technical, and organizational safeguards that govern CIC transfers, including documented but not yet exercised procedures.

Status
Draft for external legal and privacy review
Version
0.9
Classification
Public
Last reviewed
12 August 2026
Next review
12 November 2026
Effective date
Pending approval
Owner
Privacy, security, and operational control owners - confirmation required
Approval
Executive owner and privacy counsel - pending
Supersedes
None - initial publication
Download PDF
Document controlValue
Document IDCIC-PIA-TIA-006
Version0.9
Superseded versionNone - initial publication
StatusDraft for external legal and privacy review
Publication classificationPublic
OwnerPrivacy, security, and operational control owners - confirmation required
ApproverExecutive owner and privacy counsel - pending
Effective datePending approval
Last reviewed12 August 2026
Next review12 November 2026 or earlier after a material change

Purpose

This report describes safeguards relevant to CIC international transfers and distinguishes implementation evidence from documented procedures. A safeguard reduces transfer risk only where it applies to the actual data, recipient, purpose, location, and technical architecture.

Status meanings:

  • Implemented: repository or durable governance evidence supports the control design; production effectiveness still requires owner attestation where noted.
  • Documented, not yet exercised: a usable procedure exists, but no drill or completed operating record was required or reviewed for this publication.
  • Confirmation required: source evidence is insufficient to claim the control applies to every relevant provider or transfer.

Contractual safeguards

ControlRequired operationCurrent evidence state
Data processing termsDefine roles, instructions, confidentiality, security, subprocessors, rights support, incidents, deletion, audit, and liability.Governance requirement documented; executed provider agreements require confirmation.
EU SCCsSelect the correct module, complete annexes, assess local law, and flow obligations to onward recipients.Procedure documented; provider-specific executed clauses require confirmation.
UK IDTA or AddendumComplete the selected UK instrument and transfer risk assessment.Procedure documented; executed instruments require confirmation.
Nigerian transfer safeguardRecord adequate protection or another lawful basis and supporting evidence.Procedure documented; entity and provider decisions require confirmation.
Canadian comparable protectionUse contractual and operational means, transparency, monitoring, and accountability.Governance baseline documented; provider-specific evidence requires confirmation.
Government-request commitmentsRequire notice where lawful, request scrutiny, challenge, minimization, transparency, and disclosure records.Required for vendor diligence; contract coverage requires confirmation.
Subprocessor controlsPrior notice, equivalent protection, objection process, location inventory, and deletion obligations.Vendor process documented; active subscriptions and lists require confirmation.
Termination and deletionExport required records, revoke access, delete or return data, and address backups.Policy baseline documented; provider-specific certification requires confirmation.

Technical safeguards

ControlRisk reducedCurrent evidence state
Transport encryptionInterception during transferEncrypted web transport is part of the deployed application architecture; provider-specific internal links require confirmation.
Encryption at restStorage compromiseProvider capability and application design are evidenced; service-specific configuration and keys require owner evidence.
Application-level restricted-field encryptionDatabase exposure of selected financial or national identifiersImplemented for selected fields; field coverage and production key management require controlled verification.
Masking and secure revealUnnecessary exposure in admin and review workflowsImplemented for selected identifiers with reason-gated reveal and audit events.
Role-based accessUnauthorized workforce, reviewer, support, or administrator accessImplemented in application roles; periodic production access certification requires operating evidence.
Least-privilege service credentialsExcessive integration or deployment accessEnvironment-based secret use and service separation are present; provider scopes and credential inventories require confirmation.
Audit trailsUndetected sensitive-data access and decision changesCompliance and administrative audit designs are evidenced; retention and alert coverage require production verification.
Data minimizationExcess data available to importersWorkflow-level minimization and notification rules are documented; payload-by-payload verification remains required.
Pseudonymous referencesDirect identification in wallet and ledger support workflowsPublic transaction and ledger references are designed to avoid exposing database identifiers.
Retention and deletionLong-lived exposureRetention analysis and dry-run capability are evidenced; approved schedules and production execution records require confirmation.
Environment segregationProduction data or credentials entering development and testsGovernance and workflow separation are documented; provider sandbox isolation requires owner verification.
Secure webhooksForged or replayed provider eventsIntegration-specific verification and idempotency are evidenced in selected workflows; every active provider requires confirmation.

Organizational safeguards

ControlRequired operationCurrent evidence state
Transfer registerMaintain exporter, importer, data, purpose, location, mechanism, safeguards, risk, owner, and review date.Public inventory created; controlled reconciliation is outstanding.
Vendor diligenceRisk-tier before onboarding and review high-risk vendors at least annually.Policy documented; operating records require confirmation.
Access reviewReview privileged and Restricted-data access on a defined schedule and after role change.Process documented; production review evidence requires confirmation.
Workforce location inventoryRecord countries from which employees, contractors, reviewers, approvers, and support personnel access CIC systems.Required by this assessment; inventory not reviewed.
Training and confidentialityTrain authorized personnel and bind them to confidentiality and acceptable-use terms.Policy documented; completion evidence requires confirmation.
Data-subject rightsIntake, authenticate, search providers, respond, correct, delete, restrict, and record outcomes.Public policy and application workflows evidenced; provider response testing requires confirmation.
Incident responseDetect, contain, investigate, preserve evidence, assess notifications, communicate, remediate, and review.Procedure documented, not yet exercised for TIA publication.
Transfer suspensionPrevent new Restricted-data transfers when mechanism or safeguards fail.Decision rule documented; technical provider-by-provider switch capability requires confirmation.
Legal-change monitoringReview adequacy, certification, surveillance law, regulator guidance, and provider terms.Review triggers documented; named owner and monitoring record require confirmation.
Exception governanceTime-limit exceptions, state compensating controls, record acceptance, and prohibit silent renewal.Governance process documented; no TIA exception approval was reviewed.

Documented response procedures

The following procedures are complete enough to operate but were not represented as completed drills:

Government access request

  • Route the request immediately to the legal, privacy, and security owners.
  • Authenticate the requester and preserve the original request and handling record.
  • Prohibit voluntary disclosure beyond a documented lawful obligation.
  • Evaluate jurisdiction, authority, scope, necessity, proportionality, conflicts of law, and available challenge.
  • Seek narrowing, protective measures, delayed disclosure, or challenge where lawful and reasonable.
  • Notify the exporter or affected parties where lawful and contractually required.
  • Disclose only the minimum responsive data through an approved secure channel.
  • Record data, recipient, legal basis, decision, approvers, timing, and any prohibition on notice.
  • Assess regulatory notification, individual notice, transfer suspension, and reassessment triggers.

Status: Documented, not yet exercised for this assessment.

Provider transfer-mechanism failure

  • Mark the affected transfer as Not approved for new Restricted data.
  • Disable or narrow the affected workflow where operationally available.
  • Preserve existing records according to legal and integrity requirements.
  • Identify an alternative mechanism, recipient, region, or technical safeguard.
  • Notify relevant internal owners and affected users where required.
  • Record the decision, compensating controls, expiration, and reapproval conditions.

Status: Documented, technical switch coverage requires confirmation.

New subprocessor or country

  • Capture the change notice and objection deadline.
  • Identify service, data, access, destination, and onward recipients.
  • Complete vendor, jurisdiction, mechanism, and safeguard review.
  • Approve, conditionally accept, object, or replace before the deadline.
  • Update the transfer register, notices, risk register, and review schedule.

Status: Documented, subscription coverage requires confirmation.

Supplementary-measure decision rules

Encryption is effective against a recipient or public-authority access risk only if the data remains unintelligible to the relevant party and keys are not available to that party. Where a provider must process plaintext to deliver the service, encryption at rest alone does not eliminate lawful-access risk. CIC must then rely on a combination of minimization, field separation, pseudonymization, short retention, strict access, contract commitments, request scrutiny, transparency, and alternative architecture where proportionate.

Restricted identity documents, national or financial identifiers, bank data, recordings, and broad database access require the strongest controls. If CIC cannot establish an effective mechanism and safeguards, new transfers of those data must stop.

Control effectiveness evidence

For each control, the controlled evidence register should retain the design source, owner, test method, test date, result, exception, remediation, and next test. Public evidence may describe the control, but raw logs, secrets, account exports, identity records, request details, and security topology remain restricted.

Current conclusion

CIC has meaningful application and governance safeguards, especially around selected identifier encryption, masking, audited reveal, role separation, corrections, appeals, notification controls, and retention analysis. The most important remaining control gaps are provider-specific contracts and mechanisms, production regions, workforce access locations, comprehensive key and field coverage, recurring access and vendor operating evidence, and technical suspension capability.

Limitation

This report was prepared with AI assistance. It does not certify operating effectiveness, legal adequacy, or provider compliance; authorized owners must supply and approve the controlled evidence.