Annual Report to Parliament on the Administration of the Privacy Act 2025-2026
Public Safety Canada

Introduction

Purpose of the Privacy Act

The Privacy Act came into force on July 1, 1983. Its purpose is to protect the privacy of individuals by imposing obligations on government institutions subject to the Act. These obligations limit the collection, retention, use, disclosure and disposal of personal information held by these government institutions. It also gives individuals the right of access to their own personal information, with limited and specific exemptions, and the rights to request the correction of that information. Individuals who are not satisfied with an institution's handling of their personal information or any matter related to a formal request made under the PA are entitled to complain to the Privacy Commissioner of Canada.

Tabling of this Report

This report is tabled in Parliament in accordance with section 72 of the Privacy Act under the direction of the Minister of Public Safety. The report describes how Public Safety Canada (Public Safety) administered and fulfilled its obligations under the Act between April 1, 2025, and March 31, 2026.

Mandate of Public Safety

Public Safety was created in 2003 to ensure coordination across all federal departments and agencies responsible for national security and the safety of Canadians. Our mandate is to keep Canadians safe from a range of risks such as natural disasters, crime and terrorism. Our mission is to build a safe and resilient Canada. Our vision is to, through outstanding leadership, achieve a safe and secure Canada and strong and resilient communities.

Legislation governing the department sets out three essential roles:

  1. Support the Minister's responsibility for all matters related to public safety and emergency management not assigned to another federal organization;
  2. Exercise leadership at the national level for national security and emergency preparedness; and
  3. Support the Minister's responsibility for the coordination of entities within the Public Safety Portfolio.

The Department's three core responsibilities are: national security, community safety and emergency management.

Organizational Structure

Public Safety

During the 2025-2026 fiscal year, the department was organized into five branches: Emergency Management and Programs, Crime Prevention, Portfolio Affairs and Communications, National and Cyber Security, and Corporate Management. The department also has a Chief Audit and Evaluation Executive and is supported by the Legal Services Unit.

Five Regional Offices represent the Atlantic, Quebec and Nunavut, Ontario, Prairies and Northwest Territories, and British Columbia and Yukon. These offices are the primary point of contact for the department at the regional level. Our regional offices provide support to departmental policy, program and operational areas across the organization, delivering core programs at the regional level, providing regional input and perspective, and supporting the coordination of federal responses to emergency events. Their networks of partnerships with provincial and territorial officials, other federal departments and agencies, and diverse communities and stakeholders, are essential to the Department's work.

The Public Safety Portfolio: Partner Agencies and Review Bodies

The Canada Border Services Agency (CBSA) manages the nation's borders by enforcing Canadian laws governing trade and travel, as well as international agreements and conventions. CBSA facilitates legitimate cross-border traffic and supports economic development while stopping people and goods that pose a potential threat to Canada.

The Canadian Security Intelligence Service (CSIS) investigates and reports on activities that may pose a threat to the security of Canada. CSIS also provides security assessments, on request, to all federal departments and agencies.

The Correctional Service of Canada (CSC) helps protect society by encouraging offenders to become law-abiding citizens while exercising reasonable, safe, secure and humane control. CSC is responsible for managing offenders sentenced to two years or more in federal correctional institutions and under community supervision.

The Parole Board of Canada (PBC) is an independent body that grants, denies or revokes parole for inmates in federal prisons and provincial inmates in provinces without their own parole board. The PBC helps protect society by facilitating the timely reintegration of offenders into society as law-abiding citizens.

The Royal Canadian Mounted Police (RCMP) is Canada's national police service and is the police of jurisdiction for all provinces and territories except Ontario and Quebec. The RCMP works at the community, provincial, territorial and federal levels to prevent crime; enforce the law; investigate offences; keep Canadians, and their interests, safe and secure; and assist Canadians in emergency situations/incidents. The RCMP also offers expertise at the international level by providing specialized training for police officers; conducting international policing activities, including peacekeeping; and sharing intelligence with trusted partners to support investigations, as well as disrupt and dismantle criminal operations.

The Civilian Review and Complaints Commission (CRCC) for the Royal Canadian Mounted Police investigates complaints from the public about the conduct of members of the RCMP in an open, independent and objective manner. The Commission also holds public hearings and conducts research and policy development to improve the public complaints process.

The Office of the Correctional Investigator (OCI) conducts independent, thorough and timely investigations about issues related to the Correctional Service of Canada. The OCI may initiate an investigation based on a complaint from (or on behalf of) an offender, as the result of a ministerial request, or on its own initiative.

The RCMP External Review Committee (ERC) is an independent agency that promotes fair and equitable labour relations within the RCMP. The Committee conducts an independent review of appeals in disciplinary, discharge and demotion matters, as well as certain kinds of grievances.

The Access to Information and Privacy (ATIP) Office

The department's Access to Information and Privacy (ATIP) Office is responsible for the coordination and implementation of policies, guidelines, and procedures to ensure departmental compliance with the Access to Information Act as well as the Privacy Act. In keeping with the department's role to support the Minister in the coordination of entities within the Public Safety Portfolio, it also plays a leadership role with respect to ensuring alignment of approach with the ATIP Offices of other Public Safety Portfolio organizations, where appropriate.

The ATIP Office is housed within the department's Portfolio Affairs and Communications Branch and includes the ATIP Operations Unit and the Privacy Management Unit (PMU). In 2025-2026, 3.4 full time equivalents (FTEs) were involved in the administration of responsibilities pursuant to the Privacy Act. The ATIP Office did not employ any regional ATIP staff or consultants during the reporting period.

Public Safety did not have any wholly owned subsidiaries at any time during the reporting period, and was not a party to any service agreements to provide services to other organizations under section 73.1 of the Privacy Act during the fiscal year.

Delegation Order

The following Delegation Order was in effect at the end of the reporting period.

Privacy Act Delegation Order
Position Authorities Under the Privacy Act and Privacy Act Regulations
  • Deputy Minister
  • Associate Deputy Ministers
  • Assistant Deputy Minister, Portfolio Affairs and Communications
  • Director General, Strategic Direction and Integration
  • Director, ATIP and Executive Services
  • ATIP Manager
Full authority
  • Team Leaders, ATIP Operations
  • ATIP Analysts
Section 15 of the Privacy Act

Dated, at the City of Ottawa, this 11 day of June, 2025.

The Honourable Gary Anandasangaree, P.C., M.P.
Minister of Public Safety

Performance 2025-2026

The following sections provide an overview of key data points on Public Safety's processing of Privacy Act requests during the reporting period, as required by the Treasury Board Secretariat.

Volume of Requests

In recent years, the department has seen an increase in the number of requests received under both the Access to Information Act and the Privacy Act in comparison with previous years. While the number of Privacy Act requests decreased slightly compared with the previous year, the overall increase in request volume has placed pressure on the ATIP Office and the department.

During the 2025-2026 fiscal year, the ATIP Office received 91 formal requests under the Privacy Act (a 10% decrease over the previous year), completed 90 requests (a 7% increase), and processed 6,965 pages (a 14% decrease).

Reporting period Requests received Requests closed Pages processed
2025 to 2026 91 90 6,965
2024 to 2025 101 84 8,139
2023 to 2024 48 50 4,805
2022 to 2023 37 40 7,599
2021 to 2022 40 40 18,767

Response within Legislated Timelines

The percentage of formal requests that were closed within the legislated timelines was 74%, a slight decrease (2%) compared to the previous year. This number was linked to the high overall volume of requests under both Acts and the resulting increase in overall workload being handled by the ATIP Office, and is comparable to compliance rates for other similar size organizations.

Reporting period Compliance
2025 to 2026 74%
2024 to 2025 76%
2023 to 2024 78%
2022 to 2023 88%
2021 to 2022 93%

Active Requests as of March 31, 2026

At the end of the fiscal year, Public Safety had a total of 22 active requests that were carried over to the next reporting period. Of these, 8 were within the legislated timelines, while 14 were beyond the legislated timelines. These numbers were comparable to those reported by other similar size organizations.

Reporting Period Received Requests Carried over within Legislated Timelines as of March 31, 2025 Requests Carried Over that are Beyond Legislated Timelines as of March 31, 2025 Total
2025-26 8 8 16
2024-25 0 5 5
2023-24 0 0 0
2022-23 0 0 0
2021-22 0 0 0
2020-21 0 0 0
2019-20 0 1 1
2018 or earlier 0 0 0

Completion Times

The following table provides a breakdown of completion times for the 90 formal requests that were completed during the fiscal year. The distribution of completion times was comparable to previous years.

Completion time Number of requests Overall representation (%)
1 to 15 days 23 26%
16 to 30 days 29 32%
31 to 60 days 22 24%
61 to 120 days 8 9%
121 to 180 days 2 2%
181 to 365 days 3 3%
Over 365 days 3 4%

Reasons for Extensions

For the requests completed in 2025-26, a total of 22 extensions were taken during the fiscal year. All extensions were taken due to interference with operations.

Reason for Extension (with corresponding section of the Act) Number of Files
Interference with Operations – s. 15(a)(i) 22
Consultations – s. 15(a)(ii) 0

Response Disposition

The following table shows the disposition of requests completed in 2024-25. This breakdown was consistent with previous years.

Disposition of Requests Total Overall Representation (%)
All disclosed 3 3%
Disclosed in part 11 12%
All exempted 1 1%
All excluded 0 0%
No records exist 53 59%
Request abandoned 22 24%
Neither confirmed nor denied 0 0%

Consultations

During the year, the department received four consultations from other organizations and completed five, including one that was outstanding from the previous year. Of these, two were completed within 0 to 15 days, two within 16 to 30 days, and one within 61 to 120 days.

Active Complaints as of March 31, 2026

At the end of the fiscal year, Public Safety had three active complaints with the Office of the Privacy Commissioner (OPC). During the year, the ATIP Office worked closely with the OPC to establish timelines for the resolution of complaints and to ensure all complaints were addressed within the timelines established by the OPC. No concerns were identified by the OPC during the fiscal year with respect to the timely processing of complaint files by the department.

Training and Awareness

Public Safety remains committed to promoting awareness and providing ongoing training opportunities to all employees. During the year, the ATIP Office continued its outreach to the department to reinforce knowledge and understanding of the legislation and ATIP processes among policy and program areas. The ATIP Office provided 8 training and information sessions on the Access to Information Act and Privacy Act. A variety of subjects were presented, including strategies for retrieving records and applying exemptions, as well as requirements for proactive publication. A total of 371 people attended these sessions.

The PMU also provides outreach and awareness concerning the department's privacy obligations, through department-wide communication modes such as InfoBulletin and by participating on various internal working groups and other fora. The PMU frequently meets with employees to provide guidance on privacy and reviews new and existing programs and activities to support compliance with the provisions of the Privacy Act.

Policies, Guidelines, and Procedures

During the year, Public Safety's ATIP Office worked closely with external and internal partners to ensure continuous alignment with policies, guidelines, and procedures issued by Treasury Board Secretariat (TBS) and the Privy Council Office and to support security of information in both the remote and hybrid work environment. The ATIP Office also worked closely with areas of the department facing high volumes of requests and implemented special procedures on a case by case basis to mitigating workload pressures and to support compliance with legislated timelines to the extent possible.

In 2025-2026, the PMU continued to work with TBS on an ongoing basis to ensure the department's suite of internal privacy policies and procedures were aligned with new privacy templates and tools issued by TBS. New and existing programs, surveys, and other activities that involve the collection of personal information are required to complete a Privacy Checklist in order to document any personal information that may be collected, used, or disclosed, along with the level of risk and any mitigation measures in place related to that information. The PMU works with program areas to ensure that standard or department-specific Personal Information Banks (PIBs) are in place for all personal information and that Privacy Protocols or Privacy Impact Assessments (PIAs) are completed in situations where a new collection, use, or disclosure of personal information will occur, or where significant changes are made to an existing collection, use, or disclosure. The PMU also provides privacy review and analysis for Treasury Board Submissions.

During the year, Public Safety also provided input to support TBS's review of the Privacy Act,which solicited feedback from federal organizations and civil society on ways the legislation can be modernized to improve services to Canadians, strengthen privacy protections for the digital age, and update the foundation and oversight of the federal privacy regime.

Initiatives and Projects to Improve Privacy

During the year, the ATIP Office continued to provide dedicated support on high visibility files within Public Safety and the Portfolio that required a coordinated approach to the handling of ATIP requests, including the implementation of the Assault-Style Firearms Compensation Program, as well as files related to foreign interference, national security operations, border security, policing, and international affairs. The ATIP Office also continued to provide support in reviewing documents in response to Parliamentary Committee motions for document production. The ATIP Office also continued efforts towards modernizing the current request processing software, working closely with partners including Treasury Board Secretariat, Public Services and Procurement Canada, and Shared Services Canada to set up contracts for software licensing and server hosting. These efforts are scheduled to continue through 2026-2027 and are intended to streamline the ATIP process and support alignment with other government departments going forward.

During the year, the PMU team continued to connect with a range of new internal clients, in order to increase opportunities to provide independent advice to Public Safety programs to support the safeguarding of personal information. The PMU is also a member of the department's 3rd Party Solutions Approval Team (3PSAT), which reviews applications for new software and digital tools proposed for use by the department, and provides advice and guidance to ensure that privacy by design principles are taken into account during the approval of new digital solutions. During the reporting period, the PMU also established a new internal SharePoint platform to improve access to privacy management tools within the department and to streamline the intake and case management process.

Summary of Key Issues and Actions Taken on Complaints

As in previous years, Public Safety received a comparatively low volume of complaints on requests made under the Privacy Act. During the year, the OPC received six new complaints against the department and concluded three investigations on Public Safety files. Of these, no complaints were deemed to be well-founded. The ATIP Office continued to maintain a constructive relationship with the OPC, meeting periodically with the OPC both at the Manager and the Director level to ensure ongoing alignment of approach, identify priority files for attention, and address any areas of concern as they arose. No specific issues were noted by the OPC during the year.

Material Privacy Breaches

Public Safety experienced no material privacy breaches in 2025-2026.

Privacy Impact Assessments

One PIA was completed during the reporting period, to support the establishment of the Office of the Foreign Influence Commissioner of Canada. Updates were also made to the PIAs for the Assault-Style Firearms Compensation Program for individuals and businesses. Summaries for these PIAs have been made publicly accessible on Public Safety's website. Several other PIAs pertaining to departmental programs and initiatives were in progress during the year.

Public Interest Disclosures Pursuant to Paragraph 8(2)(m) of the Privacy Act

Paragraph 8(2)(m) of the Privacy Act provides the head of the institution with the authority to disclose personal information where the public interest in disclosure clearly outweighs any invasion of privacy that could result from the disclosure, or where the disclosure would clearly benefit the individual to whom the information relates. No disclosures pursuant to paragraph 8(2)(m) of the Privacy Act were made by Public Safety during the fiscal year.

Monitoring Compliance

Public Safety maintains four recurring ATIP reports to inform senior management of the program during the fiscal year. These reports track a range of information including the list of new formal Privacy Act requests received by the department each week, deadlines assigned for retrieval, and the list of upcoming requests scheduled for release, as well as quarterly reporting on retrieval response times for Public Safety branches. Reports are shared weekly with Assistant Deputy Ministers (ADMs) and other senior officials and are discussed with senior management as required. In addition, ATIP performance is monitored at the ADM level through performance agreements and evaluations to ensure ATIP remains a priority within the department.

Compliance with the provisions of the Access to Information Act and the Privacy Act is also an explicit requirement enshrined within all contracts, information sharing agreements, and information sharing arrangements issued by the department. The ATIP Office also reviews contracts and information sharing agreements as required and provides advice and guidance with respect to privacy protections.

Date modified: