ArriveCAN Slack Deletion Shows Ottawa’s Digital Secrecy Problem Is Still Unfixed
ArriveCAN was not only a procurement scandal. The Information Commissioner’s Slack findings show why Ottawa needs a digital-records ledger.
ArriveCAN was never just a procurement scandal. It was also a records scandal. The Information Commissioner’s 2025–2026 Annual Report and related final report on the Canada Border Services Agency make that plain: a major federal digital project used a collaboration platform for years, then the workspace disappeared before the watchdog could inspect what was inside.
The Commissioner’s investigation began after allegations that records connected to ArriveCAN had been destroyed while access-to-information requests were in play. On the alleged destruction of records from a corrupted Outlook PST file, the Commissioner found no evidence of an offence under subsection 67.1(1) of the Access to Information Act. That point matters. Accountability should be factual, not speculative.
But the Slack findings are still damning. The report says CBSA used Slack between April 2020 and May 2023 for ArriveCAN development, testing and maintenance communications involving staff, vendors and contractors. CBSA said roughly 180 registered users were on the workspace over the three years it was used, including some people not involved in ArriveCAN. Some external individuals used it. Some CBSA employees accessed it with non-government email addresses.
Then came the core failure: the Slack workspace was deleted in May 2023. The Commissioner found it was deleted without consultation with CBSA’s Access to Information and Privacy unit and without a documented review of its contents. The OIC could not review the workspace because there were no backups or archival copies. CBSA’s ATIP unit, according to the report, was unaware Slack existed and therefore could not test whether ArriveCAN responses were complete or ensure deletion was paused while relevant records were identified and retrieved.
That is not a technical footnote. It is the transparency system colliding with modern government. If officials can move policy, procurement, vendor and project communications into chat tools that ATIP offices do not know exist, the legal right of access becomes a paper right. If workspaces can be decommissioned before access officers confirm whether they contain responsive records, the public record depends on luck.
Conservatives should draw the line here: every federal department needs a live digital-records ledger. It should list every collaboration tool in use, every program area using it, every outside participant category, every non-government-account exception, every retention setting, every backup rule, every ATIP search protocol and every decommissioning approval. No workspace tied to active public business should be deleted until ATIP signs off that access requests, litigation holds, audits and parliamentary requests have been checked.
The Commissioner did not need to prove a criminal records-destruction offence to expose a serious governance failure. Ottawa’s answer cannot be another training memo. The answer is enforceable disclosure architecture: searchable systems, retention defaults, deletion freezes, audit logs and monthly compliance reporting.
ArriveCAN cost taxpayers money. The Slack episode cost them confidence. If the Carney government wants to claim it has turned the page on Liberal-era procurement chaos, it can start by proving federal digital records cannot vanish before Canadians get to ask for them.
- Information Commissioner of Canada: 2025–2026 Annual Report
- Information Commissioner of Canada: Canada Border Services Agency (Re), 2026 OIC 46
- Information Commissioner of Canada: Access to information struggles to keep pace with an evolving public service workplace
This article argues for proactive disclosure and records-governance controls. It does not allege an Access to Information Act offence; the Commissioner reported no evidence of an offence under subsection 67.1(1) in relation to the alleged PST-file destruction.