
Canada Border Services Agency (Re), 2024 OIC 43
The complainant alleged that the Canada Border Services Agency (CBSA) improperly withheld the complete source code for the ArriveCAN application under subsection 16(2) of the Access to Information Act. CBSA argued that disclosing the source code could reasonably be expected to facilitate the commission of an offence by allowing malicious actors to hack the application, impersonate it, or expose security vulnerabilities, thereby risking personal information. The OIC found that at the time of the request in September 2022, when ArriveCAN was mandatory and collected sensitive personal data, the disclosure of the source code could indeed facilitate an offence. The Commissioner also concluded that CBSA reasonably exercised its discretion by weighing the public interest in disclosure against the risks. Furthermore, the OIC accepted CBSA's argument that severance of the source code was not reasonable due to the unknown locations of potential vulnerabilities. Consequently, the complaint was deemed not well founded.
Ontario
British Columbia
Alberta
Saskatchewan
Manitoba
Quebec
Nova Scotia
New Brunswick
Prince Edward Island
Newfoundland and Labrador
Yukon
Northwest Territories
Nunavut