A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Review of the Communications Security Establishment’s Signals Intelligence Data Retention was recently released under the Access to Information Act.
NSIRA reviewed how the Communications Security Establishment (CSE) retains signals intelligence (SIGINT) collected in support of its foreign intelligence mandate.
The review covered October 2020 to April 2024. NSIRA examined CSE’s policies and technical systems and conducted four inspections of information held in those systems.
CSE collects large amounts of information to support Canada’s foreign intelligence interests. The law requires CSE to retain information collected under its authorities only for as long as reasonably necessary.
This means that CSE must have effective safeguards not only for collecting information, but also for deciding how long to keep that information and for deleting it when necessary.
The review looked at whether those requirements were reflected in CSE’s policies, systems, and day-to-day practices.
Key Findings
NSIRA found that CSE has safeguards to protect information relating to Canadians and persons in Canada. Many of its systems automatically delete information that should not be retained once identified.
NSIRA’s main concern was the treatment of non-Canadian information that CSE determines has no foreign intelligence value.
CSE’s retention schedule does not distinguish non-Canadian information from information that may have foreign intelligence value. CSE also lacks mechanisms to delete certain information of no foreign intelligence value before the end of its retention period.
In two of the four inspections, NSIRA found that CSE retained non-Canadian information after determining that it had no foreign intelligence value. NSIRA found that this may not comply with the conditions of the applicable ministerial authorization and could result in information being kept longer than reasonably necessary.
NSIRA also identified issues with:
- continuing to target selectors that are no longer of foreign intelligence interest;
- SIGINT stored outside CSE’s main systems, where deletion may require manual action; and
- ensuring retention requirements are respected when SIGINT is shared with other agencies, including Five Eyes partners
Non-Compliance Report
One of the findings in this review also led NSIRA to issue a non-compliance report.
NSIRA issues a non-compliance report when it believes that an activity related to national security or intelligence may not comply with the law. In this case, the report relates to CSE’s retention of information that it had determined had no foreign intelligence value.
Recommendations and Next Steps
NSIRA made six recommendations to address these issues. Among other things, NSIRA recommended that CSE create clear rules for deleting non-Canadian information that has no foreign intelligence value, improve controls over information stored outside its main systems, and ensure its authorization requests accurately reflect its retention practices.
NSIRA also recommended that CSE delete the information identified in two inspections that it had already determined had no foreign intelligence value.
Overall, NSIRA recognized the safeguards CSE has established to protect Canadians and persons in Canada. At the same time, the review identified gaps in how CSE manages information that no longer has foreign intelligence value.
The recommendations are intended to strengthen CSE’s retention practices and ensure that information is kept only for as long as reasonably necessary.
