Could not agree more that misuse of information when you get gcms can lead to fraud
Identity theft, or the theft of personal information, can be the starting point to a range of crimes — from financial fraud and forgery to abuse of government programs. The thief only needs a small amount of information, as little as your name and birth date, to start building their new identity and committing fraud. Once they access your personal information, identity thieves can also:
- spend money from your accounts
- open new bank accounts
- change your passwords and contact information for your online accounts
- apply for loans, credit cards and benefits in your name
- rent an apartment or car
- commit other crimes using your credentials
That is why combating identity theft requires safeguarding your information even before you arrive in Canada. Be careful in disclosing your information to third parties when you get GCMS.
There are some poorly designed/configured 3rd party GCMS websites out there that have been known to leak client information in various ways. Applicants often focus on the cost of the GCMS service in making a decision but they often end up "paying" for it in other ways.
Let's start with IRCC which with its vast resources still manages to have
material privacy breaches,
nine of them in the latest reporting period which only continues to grow (below is from IRCC ATIP report)
A privacy breach refers to the improper or unauthorized creation, collection, use, disclosure, retention or disposition of personal information. A material privacy breach is a privacy breach that involves sensitive personal information and could reasonably be expected to cause injury or harm to the individual.
The ATIP Division provided advice and guidance to departmental staff on containment and mitigation strategies to improve the protection of personal
information. In addition, senior officials were notified of all material breaches to facilitate communication within the Department and raise awareness of issues that could hinder the public’s right to privacy. The ATIP Division monitors all privacy breaches reported at IRCC. The Division also reviews how and
where they are occurring within the Department. ATIP addresses trends and provides tailored privacy breach training sessions to raise awareness and
increase privacy breach prevention.
In 2019-2020, IRCC notified the OPC and TBS of
nine material privacy breaches. IRCC monitors all privacy breaches closely and has established notifications and remedial measures to address each situation. The majority of material breaches were of small scale and affected a limited number of
individuals.
•
Five material breaches involved client files that were lost, or went missing during shipment from a Case Processing Centre to one of the regional offices or to the intended recipient. The affected individuals were notified.
•
Three material breaches involved inadvertent disclosures of information to the wrong individual. The affected individuals were notified.
•
One material privacy breach involved a planned disclosure of information, which inadvertently included personal information of other individuals. Affected individuals have been notified.
3rd party GCMS providers can't match the resources of IRCC in terms of security and technology (yet IRCC has privacy breaches) and that is why your concerns are very valid.
Other things to consider:
HTTPS - it's the minimum expected to have a presence on the web. 3rd party GCMS providers need to take this further with what is called
HSTS, it does not cost anything to make use of this
enhanced security feature. You can do a simple check if the third party website uses HSTS or not, check here
https://hstspreload.org/ This list is managed by
Google and used by all major web browsers. For those interested, a
full list of domains added to the HSTS preload list is available, you can search and find your 3rd party GCMS provider on this list
cloudflare.com is another great service that
enhances security and all 3rd party GCMS providers should use this or something similar.
Information provided by the likes of IRCC and CBSA is NOT password protected
. That is why it's the responsibility of the 3rd party GCMS provider to not only provide the information in a secure manner but ensure that the
PDF file is password protected. Many simply forward the email they receive from IRCC and that just doesn't cut it. CBSA is attempting to change how it does things, see this note from CBSA;
"As requested, attached to this email is a copy of your release package. To open the file, please use the agreed upon password provided during your telephone conversation"
Immigration lawyers, registered consultants and the likes — back in the day some of these folks did not like to publicize the availability of Gcms notes; because it “
✔ Lets you know if your representative is doing his/her job ”. Times have changed and these days
some of these folks are heavily promoting this service. You ask why? For some folks it’s an opportunity to
up-sell and
cross-sell other services they offer like legal opinion, interpretation service, health insurance and a myriad of other services. Such services are often unnecessary to the larger audience and definitely expensive.
Here is another example of what can happen when you order your Gcms file from folks “affiliated” with a licensed immigration lawyer or “affiliated” with a registered immigration consultant. Look closely to what the image below has to say. Such “affiliations” are sometimes not in your best interest. Working with an independently operated firm has better outcomes.
Data collection — is a huge endeavour among some of these firms as well. We are not talking about anonymised data; it’s very much personal and identifiable data points that are being collected. Such data is collected from forms you complete to order your Gcms file or at times from the Gcms file itself. Ever wonder why some firms are asking for your mailing address or phone number? Gcms notes are NOT going to be mailed to you and neither is anyone going to call you to deliver the information over the phone. It’s not needed for processing your payment either. With
advances in payment technology such information is increasingly becoming optional as it creates friction in the checkout process. Furthermore, why are some firms asking for a copy of your passport and visa refusal letter? It’s not required to obtain your Gcms file. Sometimes, IRCC may request such documents for validation purposes but it’s not common and absolutely not required during the initial phase when you order your file. Why provide confidential information upfront when it’s not required? It does NOT speed up your Gcms order; that is a myth because IRCC has laws about
processing standards. Another interesting trend that is becoming prevalent is collecting your information and reselling it in the name of providing visa progress tracking services which are of little to no value.
It is your decision to make where you request your Gcms Notes from. Make an informed decision because it matters where you request your file from. There is a lot at stake.