There was an interesting piece about document security lapses within the federal government, which is something that speaks to me as someone who spent time doing records management within a federal department back during my early days in Ottawa as I was building up my freelance career (before I started on the Hill). The report cited 3075 lapses in the past year at Public Services and Procurement, with six employees being cited as chronic offenders.
During my time doing this kind of document work, there were a rash of news stories about secret documents being left unattended, or being thrown out and found on street corners, and much of it boils down to a culture within the public service of not caring about document security – in part because people aren’t trained to care about it. It was also because, in my department’s experience, every time they would train an admin assistant in document management, she would go on mat leave, then her replacement wouldn’t be trained to the same level, and she would go on mat leave or another assignment, and her replacement not trained, and on it went. So records went unattended, and people in the department stopped properly dealing with their records, including those who were supposed to be kept secret. And you’d see people in the Tim Horton’s downstairs from the office with Protected of Secret file folders on them, despite the fact that they weren’t supposed to leave the office area. And nobody seemed to care about that fact – all of which reinforced the notion that there isn’t a culture of responsibility around these kinds of things.
Which brings me back to the article. With those chronic offenders, they are being treated leniently, despite the fact that they are supposed to be subjected to tough sanctions, including demotion or termination. But as with so many things in the public service, where there are so few instances where there are consequences for transgressions, it seems to reinforce the notion that document security doesn’t need to be taken seriously, and then we get more security and privacy breaches. If there were actual consequences, that might start making an effort at reducing the number of breaches.