With respect to the acquisition and retention of data, including associated data, metadata, bulk data, or any other kind of data by the Canadian Security Intelligence Service (CSIS): (a) how many internal data repositories does CSIS have access to; (b) what are the different kinds of internal data repository to which CSIS has access; (c) are there any data repositories that have been accessed by CSIS, whether internal or external, that are housed within servers that do not belong to CSIS; (d) what is the difference, according to CSIS, between the terms “associated data” and “metadata”; (e) what is the exhaustive list of organizations with which CSIS shares information, including bulk data, metadata, associated data and any other data to which CSIS has access; (f) what is the exhaustive list of organizations, including telecommunications companies, financial institutions, government departments, and other organizations, with which CSIS communicates for purposes other than the sharing of information; (g) when were Cabinet Ministers informed of CSIS’s collection of bulk data, and with relation to their notification, (i) who were those Ministers, (ii) what were the forms of communication through which they were informed, (iii) what were the dates on which each Minister was informed, starting from January 1, 2006, until December 31, 2016, inclusively; (h) when were Cabinet Ministers informed of the methodologies employed by CSIS for the purpose of the collection of bulk data, (i) who were those Ministers, (ii) what were the forms of communication through which they were informed, (iii) what were the dates on which each Minister was informed, starting from November 4, 2015, until the present time; (i) with respect to the bulk data that CSIS has collected or otherwise has or has had access to, does it include (i) communications metadata, (ii) travel information, (iii) passport data, (iv) law enforcement wiretaps, (v) arrest records, (vi) financial transactions, (vii) information collected from social media, (viii) medical data, (ix) other kinds of bulk data that CSIS have access to; (j) what are the descriptions of all the different methods through which this bulk data is collected; (k) what is the exhaustive list of sources of bulk data that CSIS has access to, and how many times were bulk data collected starting from January 1, 2006, until December 31, 2016, inclusively; (l) how many judicial warrants were given to CSIS for the purpose of acquisition of bulk data starting from January 1, 2006, until December 31, 2016, inclusively, and when were these warrants received by CSIS; (m) how many (i) telecommunications companies, (ii) financial institutions, (iii) medical institutions, (iv) airports, (v) other companies, were compelled or requested to provide access to bulk data, associated data, metadata or any other kind of data to CSIS; (n) what are the kinds of leverage that CSIS employs in order to request or compel the acquisition of data from external data suppliers, (i) how many judicial warrants were obtained by CSIS for the collection of such data from private entities, (ii) has CSIS ever collected or had access to any such data without obtaining judicial warrants beforehand; (o) how many government departments or agencies were compelled or requested to (i) transfer bulk data, associated data, metadata or any other kind of data to CSIS, (ii) grant access to such data to CSIS, starting from January 1, 2006, until December 31, 2016, inclusively; (p) how many judicial warrants were obtained by CSIS for the collection of such data from government departments or entities, and has CSIS ever collected or had access to any such data without obtaining judicial warrants beforehand; (q) how many investigations has the use of bulk data helped in during the period starting from January 1, 2006, until December 31, 2016, inclusively, and how many individuals were the subjects of these investigations; (r) how many datasets or data repositories are housed within the Operational Data Analysis Centre, and how many of these data sets or data repositories include bulk data; (s) how many datasets or data repositories are housed in internal CSIS servers; (t) what are the approximate percentages of (i) bulk data, (ii) associated data, (iii) metadata, (iv) any other data that are housed within the servers mentioned in (s); (u) what is the description of the SMART data collection methodology employed by CSIS, and what kinds of data does this methodology collect; (v) what are all the steps involved in obtaining validation of authority to collect any kind of data; (w) has all information collected by CSIS since November 3, 2016, passed the “strictly necessary” test, as stipulated in Section 12(1) of the CSIS Act; (x) has all information retained by CSIS since November 3, 2016, passed the “strictly necessary” test, as stipulated in Section 12(1) of the CSIS Act; and (y) in light of the ruling by the Federal Court of Canada on the illegality of the retention of associated data by CSIS, delivered on November 3, 2016, what are the changes that CSIS has undertaken in order to ensure that the policies and practices of CSIS comply with the Court’s ruling?
In the House of Commons on May 8th, 2017. See this statement in context.

