Professional Institute of the Public Service of Canada v. Canada (Attorney General)
Source text
Professional Institute of the Public Service of Canada v. Canada (Attorney General) Court (s) Database Federal Court Decisions Date 2015-09-22 Neutral citation 2015 FC 1101 File numbers T-551-15 Decision Content Date: 20150922 Docket: T-551-15 Citation: 2015 FC 1101 Ottawa, Ontario, September 22, 2015 PRESENT: The Honourable Madam Justice Kane BETWEEN: THE PROFESSIONAL INSTITUTE OF THE PUBLIC SERVICE OF CANADA AND STÉPHANE AUBRY Applicants and ATTORNEY GENERAL OF CANADA Respondent ORDER AND REASONS Overview [1] The applicants, the Professional Institute of the Public Service of Canada [PIPSC], the bargaining agent which represents 35,000 scientists and professionals employed by the Government of Canada, and Stéphane Aubry, an employee, member of PIPSC and its part-time Vice-President, seek an interlocutory injunction to prevent the Treasury Board of Canada, on behalf of the Government of Canada, from implementing the 2014 Standard on Security Screening [2014 Standard or Standard] pending the final determination of the applicants’ application for judicial review of the government’s decision to implement the Standard. [2] The applicants’ motion for the interlocutory injunction targets particular aspects of the Standard, including but not limited to credit checks, criminal record checks (requiring fingerprinting), open source inquiries, and requirements to update the employer on changes in an employee’s status and ongoing monitoring, referred to as “after-care”. [3] To succeed o…
Full judgment (source text)
Mirrored from decisions.fct-cf.gc.ca — the linked original is authoritative.
Professional Institute of the Public Service of Canada v. Canada (Attorney General) Court (s) Database Federal Court Decisions Date 2015-09-22 Neutral citation 2015 FC 1101 File numbers T-551-15 Decision Content Date: 20150922 Docket: T-551-15 Citation: 2015 FC 1101 Ottawa, Ontario, September 22, 2015 PRESENT: The Honourable Madam Justice Kane BETWEEN: THE PROFESSIONAL INSTITUTE OF THE PUBLIC SERVICE OF CANADA AND STÉPHANE AUBRY Applicants and ATTORNEY GENERAL OF CANADA Respondent ORDER AND REASONS Overview [1] The applicants, the Professional Institute of the Public Service of Canada [PIPSC], the bargaining agent which represents 35,000 scientists and professionals employed by the Government of Canada, and Stéphane Aubry, an employee, member of PIPSC and its part-time Vice-President, seek an interlocutory injunction to prevent the Treasury Board of Canada, on behalf of the Government of Canada, from implementing the 2014 Standard on Security Screening [2014 Standard or Standard] pending the final determination of the applicants’ application for judicial review of the government’s decision to implement the Standard. [2] The applicants’ motion for the interlocutory injunction targets particular aspects of the Standard, including but not limited to credit checks, criminal record checks (requiring fingerprinting), open source inquiries, and requirements to update the employer on changes in an employee’s status and ongoing monitoring, referred to as “after-care”. [3] To succeed on the motion for an interlocutory injunction, the applicants must establish that a serious issue has been raised, that the applicants will suffer irreparable harm if the injunction is not granted and the implementation of the Standard continues, and that the balance of convenience, which assesses the harm to the applicants, the harm to respondent and includes an assessment of the public interest, favours the applicants. [4] For the reasons elaborated on below, I find that the applicants have raised one or more serious issues that will be determined on judicial review, but have not provided any concrete evidence that irreparable harm will be suffered by any of the union’s members between now and the time that the judicial review is finally disposed of. [5] The jurisprudence has clearly established that all three elements of the test for an injunction must be established and that independent and concrete evidence, rather than general and speculative assertions of irreparable harm, must be provided. The applicants’ assertion that the requirement to provide information for a security clearance, by its very nature, amounts to a loss of privacy overlooks, among other things, the many safeguards in place to protect the information, including ensuring that it is not disclosed to anyone other than designated Security Officers within government departments, and overlooks that many of the measures at issue are not unprecedented and could have been required under the 1994 Personnel Security Standard [1994 Standard] and as updated in 2002. [6] It should have been a simple matter to provide an affidavit from Mr Aubry or other members of the union indicating their position, existing security level and the date of its expiry to establish that some particular employee(s) would be subjected to the new measures in the period pending the judicial review and describing the harm that employee would suffer by submitting themself to the measures at issue. Had such evidence been provided, the respondent and the Court would have had an opportunity to test and assess the evidence to determine whether irreparable harm had been established. Rather, the applicants simply assert that it is a foregone conclusion or a matter of common sense for the Court to conclude that it is obvious that some or many of the 35,000 members of its union will be subjected to the new measures in the near future and will suffer harm. [7] The applicants must do more than make assertions and ask the Court to make assumptions and rely on common sense, rather than on the law. [8] With respect to the balance of convenience, the relative harm to the applicants and respondent has been assessed and the harm to the public good has been considered in this context. [9] The respondent has established to the satisfaction of the Court that the 2014 Standard was developed and implemented in the public interest. The Court need not determine if that is so at this stage; it is presumed to be so. As a result, enjoining the implementation of the Standard is assumed to result in harm to the public good. [10] The applicants have not offered any evidence to overcome this assumption and to show that the public interest would be harmed by continuing to implement the Standard pending the determination of the judicial review. Nor have they provided concrete evidence of other harm to them. Information required to be provided by applicants in accordance with the Standard pending the determination of the judicial review will be safeguarded and will not be disclosed, redress mechanisms exist, and an employee’s ongoing employment will not be at risk to any greater extent than under the previous Standard. The applicants have not established that the harm to them, if the injunction is not granted, is greater than the harm to the respondents, if the injunction is granted. [11] The government has launched the new Standard and is in the process of fully implementing it over a 36 month period. Although the implementation is at an early stage, it is underway. An injunction would halt the implementation and leave a gap in the modernisation of security screening. The options proposed by the applicants, including to rely on the former Standard for those requiring only Reliability status and the 2014 Standard for those requiring other security clearances, are not feasible given that the 1994 Standard has been rescinded and the screening for Reliability status is applicable to all, as it is the starting point or base for all other security levels. The balance of convenience favours maintaining this status quo. Background [12] On October 20, 2014, the Government of Canada rescinded the 1994 Standard and launched the 2014 Standard, with a new security screening model and measures. The 2014 Standard applies to all federal departments defined in section 2 and all federal agencies included in Schedules IV and V of the Financial Administration Act, RSC, 1985, c F-11. Departments and agencies have until October 20, 2017 to fully implement the Standard. [13] The Standard describes its objectives as: to ensure that government security screening practices are effective, efficient, rigorous, consistent and fair, and to enable greater transferability of security screening results between agencies and departments. [14] The respondent provided the affidavit of Rita Whittle, Executive Director of the Security and Identity Management Division [SIDM], Chief Information Officer Branch of the Treasury Board of Canada Secretariat, with responsibility for directing the policy activities of SIDM, including all Treasury Board government security policy instruments, which includes the 2014 Standard. Ms Whittle describes the development of the Standard, the key provisions, the differences from the 1994 Standard and the screening measures which will now be used. Ms Whittle states that she is principally responsible for the development and implementation of the 2014 Standard. She explains that the implementation process will proceed in stages and that the readiness of departments and agencies will vary to some extent. [15] The 1994 Standard provided for two levels of Reliability status screening (Basic Reliability and Enhanced Reliability) and three levels of security clearance screening (Confidential, Secret and Top Secret). The Basic Reliability status was eliminated following the events of September 2001. Since 2002, all employees and others subject to the 1994 Standard have been required to undergo Enhanced Reliability screening (involving a name-based criminal records check and fingerprint-based check if the name-based check is inconclusive) as the first stage of screening, although their position and duties may require a higher level of screening. The minimum level of security screening from 2002 until October 2014 was Enhanced Reliability status. [16] Under the 2014 Standard, there are three levels of Standard screening (Reliability status, Secret clearance and Top Secret clearance). Secret and Top Secret screening are for security clearances, as opposed to a status, and are required for positions with access to government classified information, assets, facilities or information technology systems. There are also two levels of Enhanced screening (Enhanced Reliability status and Enhanced Top Secret clearance). [17] Reliability status is now the minimum level of security screening for all individuals who are employed in the federal public service and is a prerequisite for all security clearances. Enhanced Reliability status or Enhanced Top Secret clearance is required for those whose duties involve or support security or intelligence functions, or when an individual has access to sensitive information that creates a risk of influence by criminal or ideologically-motivated persons or organizations. [18] Obtaining and maintaining a valid security status or clearance is a condition of employment, contract, appointment or assignment. Government employees must give their informed consent to the security screening. [19] The differences between the 1994 Standard and the 2014 Standard are summarized below. The information is derived primarily from the affidavit of Ms Whittle. The applicants portray some of the measures differently in their submissions in support of the injunction. • Credit Checks o Credit checks are now mandatory for all positions and are, therefore, part of the assessment for Reliability status. o Credit checks were previously optional for Basic and Enhanced Reliability status and for Confidential and Secret clearance and could be conducted when duties or tasks to be performed required it or in the event of a criminal record, based on the type of offence. o Credit checks were previously mandatory for Top Secret clearance. • Law Enforcement Inquiry o The law enforcement inquiry includes a criminal records check and a Law Enforcement Records Check [LERC]. o A criminal records check was optional before 2002 and has been mandatory for all positions since 2002. o The Royal Canadian Mounted Police [RCMP] is responsible for conducting criminal records checks and now relies on fingerprints to do so. o A LERC is a new component of the 2014 Standard to be conducted for Enhanced screening. o Previously, some departments, such as the Canada Border Services Agency, RCMP, and Financial Transactions and Reports Analysis Centre of Canada, conducted LERCs as part of their screening. o A LERC searches law enforcement databases to determine if individuals are known or suspected of being associated with organized crime, criminality or threats to national security. o The disclosure of outstanding charges (i.e., where there is no conviction) could be done on a case-by-case basis under the 1994 Standard, depending on the type of charge and the employee’s position. o The affidavit of Brendan Heffernan, Chief Superintendent, RCMP, Canadian Criminal Real Time Identification Services indicates that disclosed criminal history information may include criminal convictions, absolute and conditional discharges with findings of guilt, and criminal charges that may be before the courts. Criminal history information about non-conviction dispositions (e.g., acquittals or withdrawals) may only be disclosed in exceptional circumstances depending on the criminal history information and its applicability to the position being screened. • Open Source Inquiries o An open source inquiry involves accessing publicly available information, such as various internet sources, including social media. o Open source inquiries were not specifically addressed in the 1994 Standard. o Open source inquiries are now mandatory for screening for Enhanced Reliability status and Enhanced Top Secret clearance and optional in specific circumstances (i.e., on a case-by-case basis) for other screening, including Reliability status, when negative information is found in the security screening process. o Ms Whittle explains that open source information is only one of several factors considered during the screening process and the significance and relevance of the information would be considered. • After-care o After-care reporting refers to the duty to report changes in circumstances and behaviour. o Most of these requirements were previously required under the 1994 Standard, including the requirement to attend security briefings and the requirement for those with security clearances to report changes in cohabitation or marital status. o The 2014 Standard requires all employees and others subject to the Standard to report changes in their criminal record status, association with criminals and significant changes in their financial situation (such as bankruptcy or unexpected wealth). Those who work in security and intelligence organizations may also be required to report changes in personal status, including marital status. [20] The applicants seek this injunction to prohibit the implementation of particular screening measures in the Standard as they apply to employees and others requiring Reliability status until the final disposition of the application for judicial review. The screening measures the applicants take issue with are credit checks, criminal records checks to the extent that they involve fingerprinting, law enforcement inquires that involve information about outstanding charges under the Criminal Code, RSC, 1985, c C-46, open source inquiries and after-care reporting requirements. [21] The applicants do not challenge the screening measures for employees who require a security clearance or Enhanced screening to perform their duties and suggest that it should be possible to carve out or exempt employees requiring only Reliability status from the new measures. [22] The respondent highlights that Reliability status is required for all employees and is the starting point or foundation for employees who require a security clearance or Enhanced screening: i.e., Secret clearance, Top Secret and Enhanced Top Secret clearance, and Enhanced Reliability status. The respondent submits it is not possible to carve out those requiring only Reliability status from the new screening measures and that the applicants’ recent amendment to narrow the scope of its motion for this injunction does not have the desired result. The Issues Should parts of the Applicants’ Affidavit be Struck? [23] The respondent notes that the affidavit of Martin Ranger, submitted by the applicants, contains several paragraphs that include legal opinion and argument and other paragraphs that extend beyond the personal knowledge of Mr Ranger. The respondent submits that these paragraphs should be struck. However, the respondent acknowledges that the applicants did not rely on the impugned paragraphs of the affidavit in their oral arguments. [24] The applicants submit that the paragraphs at issue were not intended to provide legal opinion, but to provide context for the applicants’ position. The applicants also note that the information included in other paragraphs, which the respondent argues is not within the affiant’s personal knowledge or is hearsay or irrelevant, including the exhibits attached, has now been provided to the Court, for the most part, through other means, including as exhibits to the written cross-examination of Ms Whittle. [25] The jurisprudence has established that striking affidavits at the preliminary stage is exceptional. However, an affidavit or parts thereof may be struck where it is vexatious or abusive, or contains conjecture, speculation or legal opinion (Global Enterprises International Inc v Aquarius (The), 2001 FCT 1311, 214 FTR 269 (FCTD) [Global Enterprises]). [26] In Global Enterprises the Court noted at para 6: Generally, affidavits ought not to be struck out at a preliminary stage. For the sake of efficiency, impugned affidavits should be left for the trial judge, who may be in a better position to assess and weigh that evidence. However, there are exceptions to this general observation, exceptions which involve special circumstance, including where an affidavit is abusive, or is clearly irrelevant, or where the Court is convinced that admissibility should be resolved at an early stage, so that the ultimate hearing might proceed in an orderly manner, or where there is conjecture, speculation or legal opinion in the affidavit. […]. [27] In the present case, the affidavit is not abusive, but it does include paragraphs which should be struck in whole or part. The context, which the applicants note as the reason for statements in the affidavit at paragraphs 12, 16 and 17, has been provided to the Court through the exhibits attached to the affidavit of Ms Whittle and through the Memoranda of Fact and Law. These paragraphs include legal opinion on the issues the Court must determine in the application for judicial review. [28] Paragraphs 16 and 17 (describing the measures in the 2014 Standard) are struck in their entirety. Paragraph 12 is struck in part; the phrase, “much of which is unreasonable and unnecessary to achieve the objectives of its new Standard on Security Screening” is struck. [29] Paragraphs 19, 20 and 21 are struck because this information is outside the personal knowledge of the affiant. Paragraphs 22 and 23 are also struck because this information is outside the personal knowledge of the affiant and because it relates to a different policy, not that which is the subject of this judicial review. Should the Interlocutory Injunction be Granted? [30] The parties agree that the test to be applied is that established by the Supreme Court of Canada in RJR-MacDonald v Canada (Attorney General), [1994] 1 SCR 311, 111 DLR (4th) 385 [RJR-MacDonald]. This is a three-part test of which each element must be satisfied: the applicant for interlocutory relief must demonstrate that there is a serious question to be tried, meaning a question that is not frivolous or vexatious; the applicant must convince the Court that it will suffer irreparable harm if the relief is not granted; and, the balance of convenience must be found to favour the applicant. [31] Although the test for establishing a serious issue is low, the applicants’ and respondent’s positions on the serious issues raised are described in some detail to provide the context for the other two elements of the three-part test. Have the Applicants Established one or more Serious Issues? The Applicants’ Position [32] The applicants submit that the 2014 Standard provides for the collection of personal information that was not collected under the 1994 Standard that is not necessary and that will result in an unjustified loss of privacy. The screening measures are not reasonable or proportionate despite the measures to safeguard the sensitive information. [33] The applicants dispute the rationale advanced by Treasury Board for the 2014 Standard and submit that the goal of consistency in security screening does not make the measures reasonable. Nor does the need to satisfy the international community, including the Five Eyes alliance (the group of countries that share intelligence in national security matters), justify the screening measures for employees at the Reliability status level. The applicants also dispute that Canadians may lose trust in public servants without new security screening measures. [34] The applicants note that interconnected systems and networks are not new. While the internet was not firmly established in 1994, it was in 2002, yet no changes to the 1994 Standard had been made since the elimination of Basic Reliability status in 2002. The applicants argue that if there were serious concerns arising from the increased use of technology, changes would have been made before 2014. [35] The applicants point to specific screening measures which raise serious concerns and argue that these measures violate the Privacy Act, RSC, 1985, c P-21, sections 7 and 8 of the Canadian Charter of Rights and Freedoms, Part I of the Constitution Act, 1982, being Schedule B to the Canada Act 1982 (UK), 1982, c 11 [Charter] and are an abuse of discretion by the respondent. [36] The applicants argue that a credit check is neither necessary nor effective and is not a proportionate or reasonable measure. A credit check is not relevant to assessing the loyalty and reliability of government employees who do not have access to secret or top secret information and do not have jobs relating to intelligence or security. The information obtained from a credit check is extensive, private and sensitive information, and includes a person’s history of loans and mortgages, bankruptcy proposals, bankruptcy and credit report inquiries. The applicants note that financial information is part of an individual’s biographical core of information protected by the right to privacy (R v Cole, 2012 SCC 53 at paras 47-48, [2012] 3 SCR 34 [Cole]). [37] The applicants also assert that if an employee refuses to consent to a credit check, they will not meet a condition of employment, which is to obtain Reliability status, and this would result in an administrative termination of employment. [38] With respect to the disclosure of outstanding charges under the Criminal Code, the applicants submit that the 2014 Standard does not use a case-by-case approach, unlike the 1994 Standard, but seeks this information from all employees regardless of their position. [39] In addition, fingerprints are now required through the criminal records check for Reliability status. The applicants submit that most employees will be required to use an authorized police service or private fingerprinting company to provide their fingerprints and argue that this exacerbates the aura of criminality arising from the act of fingerprinting. The applicants distinguish this from the situation of volunteers who are required to submit to a criminal records check with fingerprinting because prospective volunteers give informed consent and the measure is proportionate. The applicants’ view is that name-based record checks are sufficient and the RCMP should be directed by the respondent to continue this method. [40] The applicants also dispute the respondent’s reliance on the Auditor General’s recommendations regarding the RCMP’s criminal record services and the use of fingerprints. The applicants submit that the Auditor General’s concerns were about fingerprints for criminal justice purposes. The applicants also dispute that the name-based records checks resulted in false positives and add that, in such cases, it is preferable to rely on fingerprints only to resolve such results, rather than as the norm. [41] With respect to open source inquiries, the applicants submit that the search will reveal more than is reasonable or necessary for an employer. The applicants dispute the respondent’s position that any breach of privacy is mitigated because only information that is relevant, reliable and attributable to the individual under review will be retained in the employee’s security file. [42] The applicants also challenge the after-care and reporting requirements that apply in the five or ten year period between security screenings. The applicants note this will have a “chilling” effect despite that only information that raises a concern about loyalty or reliability would be noted. The applicants add that the scope of reporting is too broad; only those requiring higher levels of security should be required to report a change in their criminal record or their association with criminals, and there is no reason for anyone to report changes in their wealth or marital status. [43] The applicants submit that even if the information is only provided to or shared with qualified personnel, this does not respond to the breach of privacy because the information should not be accessed in the first place. [44] The applicants argue that these measures raise several serious legal issues that should be addressed in the application for judicial review. Breach of the Privacy Act [45] The applicants submit that the Standard does not comply with the Privacy Act, particularly section 4, which provides that personal information shall not be collected unless it relates directly to an operating program or activity of the institution. [46] The jurisprudence establishes that providing an individual with control over his or her personal information is connected to individual autonomy, dignity and privacy, and that privacy legislation is quasi-constitutional, as privacy plays a fundamental role in the preservation of a free and democratic society (Alberta (Information and Privacy Commissioner) v United Food and Commercial Workers, Local 401, 2013 SCC 62 at paras 19, 21-22, 24, [2013] 3 SCR 733). The applicants submit that the unreasonable screening measures deprive employees of this control. [47] The applicants argue that the Privacy Act can be an independent source of legal rights (and note, for example, Bernard v Canada (Attorney General), 2014 SCC 13 at paras 30-33, [2014] 1 SCR 227 [Bernard]; Zarzour v Canada, [2000] FCJ No 2070 (QL) at paras 23-29, 196 FTR 320 (FCA) [Zarzour]). [48] Although section 5.2.3 of the Standard expressly requires compliance with the Privacy Act, this does not mean that the Standard does comply. The applicants submit that they have a right to seek a declaration that Treasury Board has breached or failed to comply with the Privacy Act. Breach of Section 8 of the Charter [49] The applicants submit that the exercise of discretion in adopting the Standard must be carried out in a manner that conforms to the Charter (Canada (Attorney General) v PHS Community Services Society, 2011 SCC 44 at para 117, [2011] 3 SCR 134). [50] The applicants argue that the screening measures in the Standard violate the reasonable expectation of privacy of employees. Employees should not have to trade off their privacy rights to become employees. [51] Section 8 prohibits unreasonable search and seizure and applies in the administrative law context (R v McKinlay Transport Ltd, [1990] 1 SCR 627 at 647, 72 OR (2d) 798 [McKinlay]; Gillies (Litigation Guardian of) v Toronto School Board, 2015 ONSC 1038, 125 OR (3d) 17). The applicants argue that Treasury Board, acting as an employer, is carrying out a search under section 8 by requiring and collecting personal information. [52] The applicants submit that the reasonableness of the search must take into account the privacy interests at stake. Section 8 “seek[s] to protect a biographical core of personal information which individuals in a free and democratic society would wish to maintain control from dissemination to the state. This would include information which tends to reveal intimate details of the lifestyle and personal choices of an individual” (R v Tessling, 2004 SCC 67 at para 25, [2004] 3 SCR 432 [Tessling], citing R v Plant, [1993] 3 SCR 281 at 293, [1993] 8 WWR 287). Informational privacy is included in the definition of privacy (Tessling at para 23). [53] The applicants emphasize that the Supreme Court of Canada has clearly established that privacy is a matter of reasonable expectations (Cole at para 35) and that even a diminished expectation of privacy can be a reasonable expectation of privacy (Cole at para 9). [54] The applicants submit that the screening measures in the Standard would require employees to reveal details of their lifestyle and personal choices, including contacts with police, financial information, ideology, conduct and associations, and that this amounts to an unreasonable search. [55] The applicants did not pursue the argument that the Standard violates the privacy protections under section 7 of the Charter and that this raises a serious issue. Abuse of Discretion and Authority [56] Abuse of discretion is a basis for Courts to review the exercise of administrative discretion on the grounds of legality, reasonableness and fairness (Canada (Attorney General) v TeleZone Inc, 2010 SCC 62 at para 24, [2010] 3 SCR 585; Dunsmuir v New Brunswick, 2008 SCC 9 at para 28, [2008] 1 SCR 190). [57] The applicants submit that the Standard and its screening measures violate the common law of the workplace and amount to an abuse of discretion and authority by Treasury Board. Treasury Board must justify the infringement of an employee’s legitimate right to privacy with clear and compelling evidence and has not done so. [58] The applicants rely on several arbitration decisions to support their argument that the common law of the workplace requires that the employer not exercise its discretion in a manner that is overly privacy invasive, including Vancouver (City) v Canadian Union of Public Employees Local 15, [2007] BCCAAA No 216, 91 CLAS 298; Winnipeg (City) v Canadian Union of Public Employees Local 500, [2002] MGAD No 21; Canada Post Corp v Canadian Union of Postal Workers (CUPW 730-85-00037), [1988] CLAD No 12, 34 LAC (3d) 392; and, Ottawa (City) v Ottawa Professional Firefighters Assn, [2007] OLAA No 731, 169 LAC (4th) 84. [59] The applicants also note that the Supreme Court of Canada has confirmed, in the context of alcohol and drug testing in the workplace, that employers can only impose rules where “the need for the rule outweighs the harmful impact on employees’ privacy rights” (Communications, Energy and Paperworkers Union of Canada, Local 30 v Irving Pulp & Paper, Ltd, 2013 SCC 34 at para 4, [2013] 2 SCR 458). The Respondent’s Submissions [60] The respondent notes that the determination whether a serious issue has been raised and the other aspects of the three-part test must be considered in the appropriate context. Context [61] The respondent notes that security screening began in the 1940s. Cabinet Directives established in the 1950s and 60s provided guidance until the issuance of the Treasury Board Policy on Government Security in 1986 (1986 Policy) and the 1994 Standard. The 1994 Standard was rescinded in 2014. The 2014 Standard reflects modernisation; some of the same screening measures remain, while others have been modified or are new. [62] The 2014 Standard is essential to maintain trust between the government and citizens and between the government and other stakeholders, including foreign governments. [63] The level of security screening under the Standard will depend on the sensitivity of the information an employee will have access to; however, all employees must be screened for Reliability status. Reliability status underpins all other security levels. [64] The respondent notes that those with Reliability status have access to a wide range of information, information technology systems and unescorted access to facilities. Those with Reliability status perform duties and activities which could give them access to a great deal of information that is provided and retained for a range of government programs. It is essential to ensure that employees responsible for programs and services can be trusted with the information they have access to. [65] The affidavit of Ms Whittle describes the need for the new Standard, including the evolving nature of threats to the security of Canada, particularly since 2001, and the need to provide assurances to the Five Eyes intelligence-sharing community that Canada’s security policy is analogous to the policies of other members of the community. [66] The Standard also reflects the evolution in the workplace, including open work spaces, significant reliance on technology, the interconnected networks that employees have access to and the increased use of social media. In addition, the establishment of Shared Services Canada, which merges many services for government departments, results in data being accessed by more employees. [67] Ms Whittle also provided exhibits indicating that the development of the Standard dates back to a 2003 survey regarding screening of personnel conducted by the Privy Council Office and includes the results of a subsequent task force, which made recommendations to modify the security screening regime. [68] The respondent notes that there was no oral cross-examination of Ms Whittle; however, written answers and exhibits were provided. Her evidence of the development of the Standard and the need it meets is, therefore, uncontradicted. No Serious Issue [69] The respondent argues that the applicants have not raised any serious issue. [70] The respondent highlights that the information provided by an employee is not accessible to anyone other than the qualified, trained personnel responsible for security in a department, for example, the Departmental Security Officer, who is tasked with conducting the assessment. These professionals do not disclose the information gathered to the manager or anyone else. [71] The respondent notes that the applicants have misconstrued some of the screening measures and their applicability. [72] Credit checks are not new measures, as these were included in the 1994 Standard, but are now mandatory. The credit check is done by a credit reporting agency, but the agency will “mask” the inquiry so it will not be apparent that the inquiry was made. [73] The respondent contests the applicants’ assertion that refusal to consent to a credit check would result in an administrative termination of employment. The policy simply provides that the cancellation of a person’s security status or clearance could result in termination of employment; however, there would be opportunities for explanation and several factors would be considered to determine whether the security status or clearance could be granted. In addition, there are redress mechanisms. [74] The respondent notes that the 2014 Standard requires a criminal records check, but the Standard does not specify a method and does not require that criminal records checks be conducted by fingerprinting. The RCMP is responsible for performing criminal records checks under the Standard and has adopted, effective July 2015, a fully electronic, fingerprint based, criminal records check model to identify the person and the record. The affidavit of Chief Superintendent Heffernan explains the reasons for doing so, including the recommendations of the Auditor General that fingerprints are an international best practice, their accuracy and their expediency. The respondent notes that the RCMP’s decision to require fingerprinting for criminal records checks is not at issue in the judicial review. [75] In addition, the requirement for fingerprinting by a third party is not new; both the 1986 Policy and the 1994 Standard provided for fingerprinting in some circumstances as part of the criminal records check and, when required, fingerprints could be taken at an RCMP office or local police station. [76] The respondent adds that the Auditor General’s 2000 and 2004 reports do in fact refer to fingerprinting in the employment security screening context. [77] With respect to the disclosure of outstanding criminal charges, the respondent submits that the applicants have misconstrued the requirements; the 2014 Standard does not require disclosure. The RCMP would only disclose non-conviction information as part of a criminal records check in exceptional circumstances, as explained in the affidavit of Chief Superintendent Heffernan. The respondent notes that this evidence is uncontradicted. [78] The release of criminal records information under the Standard is governed by the Criminal Records Act, RSC, 1985, c C-47, the Youth Criminal Justice Act, SC 2002, c 1), the Privacy Act, the Criminal Code and directives from the Minister of Public Safety. The respondent also notes that a LERC is only required for Enhanced screening. [79] With respect to open source inquiries, the respondent submits that such inquiries could have been undertaken previously as there was no prohibition and the information is publicly available. Now open source inquiries are specifically addressed, but are mandatory only for Enhanced screening and are optional for screening for Reliability status, as part of after-care or for cause. The respondent adds that if there is a risk of behaviour or association with others that may pose a security risk or make a person vulnerable, it would be risky not to check the publicly available information. [80] After-care reporting is intended to ensure that in the ten year period between screenings there is no change in the employee’s ability to do their job and perform their duties in a reliable and trustworthy manner. After-care was part of the 1994 Standard. The 2014 Standard seeks to standardize the measure. [81] The respondent submits that the applicants have not raised a serious issue; the Standard and the screening measures at issue do not violate the Privacy Act or Charter and do not reflect an abuse of discretion. Breach of the Privacy Act [82] The respondent notes that the Standard specifically requires compliance with the Privacy Act and there is no evidence that it violates the Privacy Act. [83] Recourse for a breach of the Privacy Act can be sought by filing a complaint to the Privacy Commissioner with respect to the collection, retention, disposal, use or disclosure of personal information held by a government institution (Privacy Act at para 29(1)(h)). The only recourse to the Federal Court provided under the Privacy Act is for individuals who are refused access to their information and who have made a complaint with the Privacy Commissioner (section 41). [84] The respondent submits that the jurisprudence relied on by the applicants to support their argument that the Privacy Act can be an independent source of legal rights and that declaratory relief against alleged violations of privacy rights can be granted arose from different circumstances and focussed on how government institutions handled the information in their possession. [85] The respondent agrees that section 4 of the Privacy Act provides that personal information should not be collected unless it relates to an operating program and submits that the Standard is such a program. The Standard sets out how personal information will be handled and includes safeguards. [86] The respondent refers to Appendix C of the Standard which describes the collection, use, disclosure, retention and disposal of personal information for the purpose of security screening. These activities must be carried out in compliance with the Privacy Act and with other applicable legislation, policies, directives, standards and guidelines. [87] The respondent disputes the applicants’ argument that simply collecting the information constitutes a violation of an employee’s privacy. Section 8 of the Charter [88] The respondent submits that although the screening measures may be more rigorous than they were previously, this does not make them unreasonable (Reference re Marine Transportation Security Regulations, 2009 FCA 234 at para 66, 395 NR 1 [Marine Transportation Reference]). [89] The Federal Court of Appeal determined that screening measures analogous to those at issue were not overly intrusive and were not unreasonable in Marine Transportation Reference. Given that similar considerations exist in the present case, the respondent submits that there is no serious issue raised with respect to section 8, as it has already been decided. [90] The Standard demonstrates a balance between the privacy protections of the Charter and the legitimate objective of the government to maintain the integrity of its information, assets and facilities, which enable
Source: decisions.fct-cf.gc.ca
R v Brown
[2022] 1 SCR 506