Table of Contents
Running an RCMP-accredited fingerprinting service in Canada is not just about taking clean prints and submitting them correctly. It is about operating a compliant, trustworthy, professionally managed business that handles some of the most sensitive personal information a person can share — their biometric identity.
Every accredited fingerprinting agency is subject to document retention requirements that span four distinct categories: client and applicant records, RCMP accreditation and compliance documents, privacy and data protection records, and operational business records. Getting these right is not optional. They are central to maintaining RCMP accreditation, complying with federal privacy law, resolving applicant disputes, and demonstrating professional integrity to every client who walks through the door.
At Lotey Fingerprinting Services in Brampton, compliance is not a box we tick — it is how we operate. This guide explains exactly what documents an RCMP-accredited fingerprinting service must maintain, how long each should be kept, and what applicants should retain for their own protection.
Why Document Retention Matters for a Fingerprinting Service
Why Is Record Keeping So Important for Fingerprinting Agencies?
The answer is straightforward: fingerprinting services handle biometric data. Fingerprints are permanently, uniquely tied to an individual. Unlike a password or a PIN, they cannot be changed. This makes them among the most sensitive categories of personal information under Canadian privacy law — and it makes the organisations that collect, process, and transmit them subject to a high standard of accountability.
Beyond privacy, document retention matters for five practical reasons:
- RCMP accreditation maintenance — CCRTIS may conduct inspections or audits of accredited agencies at any time. Agencies that cannot produce required documentation risk suspension or revocation of their accreditation.
- Submission dispute resolution — If an applicant’s result is delayed, missing, or disputed, the Transaction Control Number (TCN) and submission records are the only way to trace what happened.
- Rejection resubmission — When a fingerprint submission is rejected, the rejection notice and original session records are needed to correct and resubmit accurately.
- PIPEDA compliance — The Personal Information Protection and Electronic Documents Act requires organisations to document how personal information is collected, used, stored, and destroyed.
Legal and liability protection — In the event of a complaint, dispute, or investigation, comprehensive records protect the agency and its clients.
Category 1: Client & Applicant Records
What Client Documents Must a Fingerprinting Service Keep?
These records are created at every single fingerprinting session and form the core of a fingerprinting agency’s operational record:
Consent Form — Signed by the Applicant
The consent form is the legal foundation of every fingerprinting transaction. It documents the applicant’s informed agreement to have their biometric information collected and submitted for a specific purpose. Without a signed consent form, the fingerprinting agency has no legal basis to collect or transmit the applicant’s biometric data.
The consent form must capture
- Applicant’s full legal name and date of birth
- Purpose of the fingerprint submission (criminal record check, PCC, immigration, VSC, etc.)
- Applicant’s signature and the date of signing
- Acknowledgement that the data will be submitted to the RCMP CCRTIS
The RCMP’s own Consent for Certified Criminal Record Checks form establishes the standard for what consent documentation must contain for civil fingerprinting purposes.
Government-Issued Photo ID Verification Record
Every fingerprinting session requires identity verification — the person being fingerprinted must be confirmed as the person named in the application. Agencies must record:
- Which form of government-issued photo ID was presented (passport, driver’s licence, PR card, etc.)
- The ID document number or reference
- Date of verification
This record protects the agency from fraud claims and confirms that the biometric data submitted belongs to the identified individual.
Application Form and Purpose of Submission
The application form documenting the submission purpose — criminal record check, Police Clearance Certificate, immigration, Vulnerable Sector Check, FBI, or other — must be retained. This establishes the legal purpose for which data was collected and transmitted, which is a core PIPEDA requirement.
Transaction Control Number (TCN)
The TCN is the unique reference number generated by the RCMP RTID system for each electronic fingerprint submission. It is the single most important operational record an agency retains after a submission:
| Category | Role | Requirement |
|---|---|---|
| Submission Tracking | Uniquely identifies every submission in the RCMP RTID system | The only way to trace a submission if results are delayed or missing |
| Transmission Proof | Confirms the submission was received by the RCMP | Evidence of successful electronic transmission |
| Dispute Resolution | Required for dispute resolution with RCMP CCRTIS | Without the TCN, the RCMP cannot locate the submission in their system |
| Applicant Record | Provides applicant’s proof of submission | Agencies should issue the TCN to applicants as a receipt |
Payment Receipt
Every session produces a payment record covering both the agency’s service fee and the $25 federal RCMP processing fee collected on the RCMP’s behalf. This must be:
- Issued to the applicant as a receipt
- Retained by the agency for financial records
Rejection Notices (Where Applicable)
When the RCMP returns a rejection notice for a submission, the agency must retain this document. It identifies the reason for rejection, which is needed for accurate resubmission, and it forms part of the audit trail for that applicant’s file.
Category 2: RCMP Accreditation & Compliance Documents
What Accreditation Documents Must a Fingerprinting Agency Maintain?
These documents sit at the business level — they are not created per session but must be kept current and accessible throughout the agency’s accredited operation
| Document | Purpose | Compliance Importance |
|---|---|---|
| RCMP CCRTIS Accreditation Certificate | Formal confirmation of accreditation by the RCMP | Proof of authority to submit civil fingerprints electronically |
| CSO Security Screening Certificate | Personnel security clearance for the Company Security Officer | Mandatory RCMP requirement that must remain valid and renewed when required |
| ACSO Security Screening Certificate | Security clearance for the Alternate Company Security Officer | Required to maintain accreditation continuity and operational compliance |
| Physical Site Security Inspection Report | Assessment conducted by an RCMP-qualified private security firm | Confirms the premises meet CCRTIS physical security standards |
| IT Security Inspection Report | Independent review of systems and network security controls | Demonstrates compliance of data systems and submission infrastructure |
| EFCD Device Certification Documentation | Certification records for the Electronic Fingerprint Capture Device | Verifies the device is RCMP-certified and NIST-compliant |
| Certified Vendor Documentation | Manufacturer compliance records from an RCMP-approved vendor | Establishes the device’s compliance and certification at source |
| RTID Connectivity & Configuration Records | Technical documentation of integration with the RCMP RTID system | Required during inspections, audits, troubleshooting, and dispute resolution |
Important: Security inspections are now conducted by private-sector inspection firms qualified under CCRTIS criteria — agencies are responsible for arranging and paying for these inspections. Retaining the inspection reports from these firms is critical, as these reports will be the primary evidence of compliance if CCRTIS ever audits the agency.
Category 3: Privacy & Data Protection Records
What Privacy Records Must a Fingerprinting Service Keep Under PIPEDA?
Fingerprinting agencies are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada’s federal private sector privacy law — because they collect, use, and disclose personal and biometric information in the course of commercial activity.
PIPEDA requires organisations to document their privacy practices and be accountable for how personal information is handled. Specific records that must be maintained include:
Privacy Policy
A documented privacy policy explaining:
- What personal and biometric information is collected
- Why it is collected and for what purposes
- How it is stored and protected
- How long it is retained
- How it is destroyed
- Who it is disclosed to (RCMP CCRTIS, and no one else without consent)
- How applicants can access their own records or request correction
This policy must be made available to applicants at the point of collection.
Data Retention and Destruction Log
RCMP CCRTIS retains fingerprint submission data for 90 days before destruction. Fingerprinting agencies must have their own documented retention and destruction policy for client records — and a log recording when client files were destroyed and by what method.
Biometric data cannot simply be deleted carelessly. Secure destruction must be documented.
Client Consent and Withdrawal Records
Where an applicant withdraws consent after the fact, that withdrawal must be documented — including the date, the applicant’s request, and the action taken by the agency in response.
Data Breach Response Log
In the event of a data breach — whether a physical breach (lost records), a digital breach (system compromise), or an accidental disclosure — PIPEDA requires prompt notification to affected individuals and, in serious cases, to the Office of the Privacy Commissioner. The agency must maintain:
- A log of all data incidents, however minor
- The response actions taken
- Notification records if applicable
Category 4: Operational & Business Records
What Operational Records Should a Fingerprinting Service Maintain?
Beyond the regulatory minimums, professional fingerprinting operations maintain operational records that protect both the business and its clients:
- Appointment and session log — date, time, applicant name, submission type, TCN for every session. This is the agency’s master record of all transactions.
- Staff training records — documentation that all fingerprint technicians have received training in RCMP standards, technique requirements, form compliance, and privacy obligations.
- EFCD device maintenance and calibration records — scheduled and unscheduled maintenance logs for fingerprint capture devices, confirming ongoing certification compliance.
- Error and resubmission log — tracking of any rejected submissions: what was rejected, the stated reason, and the corrective action taken.
- Mobile fingerprinting session records — where the agency provides mobile services, additional records of site, date, and session conduct should be kept for each off-premises appointment.
How Long Should Each Record Type Be Kept?
What Are the Record Retention Timelines for Fingerprinting Services?
| Record Type | Retention Period | Reason for Retention |
|---|---|---|
| Client Consent Forms & ID Verification | Minimum 2 Years | PIPEDA accountability and dispute resolution support |
| Transaction Control Numbers (TCNs) | Minimum 2 Years | Required for RCMP dispute resolution and applicant follow-up inquiries |
| Rejection Notices | Minimum 2 Years | Supports resubmissions and maintains a complete audit trail |
| RCMP Accreditation Certificate | Accreditation Period + 2 Years | Proof of authority to operate during and after accreditation |
| Security Inspection Reports | Until Next Inspection Cycle (Minimum 3 Years) | Essential evidence for CCRTIS audits and compliance reviews |
| Personnel Security Screening Certificates | CSO/ACSO Role Duration + 2 Years | Required to demonstrate ongoing RCMP security compliance |
| EFCD Certification Documents | Device Life Cycle + 2 Years | Maintains proof of equipment certification and compliance |
| Payment Receipts & Financial Records | Minimum 7 Years | Required under CRA business record retention standards |
| Privacy Policy Version Records | Indefinitely (or Superseded Version + 5 Years) | Supports long-term PIPEDA accountability and governance |
| Data Breach Logs | Minimum 2 Years from Incident | Required for privacy incident tracking and regulatory compliance |
| Staff Training Records | Employment Duration + 2 Years | Protects against liability and demonstrates training compliance |
What Should Applicants Keep for Their Own Records?
What Documents Should a Fingerprinting Applicant Keep After Their Session?
It is best practice for fingerprinting services to advise every applicant to retain:
- A copy of their completed fingerprint consent and application form — confirms the purpose and details of the submission
- Their Transaction Control Number (TCN) or session receipt — the only way to trace a submission if results are delayed, missing, or disputed. Every applicant should receive this before leaving.
- The rejection notice (if applicable) — needed for the resubmission appointment; bring it with you so the new technician understands what went wrong the first time
- Any RCMP correspondence about their criminal record check — including result letters, extension notices, or queries
- The original request from the employer or agency that triggered the fingerprinting — establishes the purpose context if questions arise later
If an applicant cannot locate their TCN and needs to trace a submission, they should contact the fingerprinting agency first — the agency’s session log and TCN records are the starting point for resolution.
What Happens If an Agency Cannot Produce Required Documents?
What Are the Consequences of Poor Record Keeping for Accredited Agencies?
Document failure at an RCMP-accredited fingerprinting agency carries serious consequences:
- RCMP CCRTIS audit failure — leading to suspension or revocation of accreditation
- PIPEDA complaints — if applicants cannot access their own records, or if poor data handling leads to a complaint to the Office of the Privacy Commissioner of Canada
- Inability to resolve disputes — without TCNs and session records, the agency cannot assist an applicant whose results are delayed or missing
- Liability exposure — if a client suffers harm as a result of lost, misdirected, or improperly handled biometric data, documented records are the agency’s primary defence
Professional fingerprinting agencies treat their records with the same seriousness that legal or medical offices treat client files — because the data is equally sensitive and the regulatory obligations are equally real.
Why Lotey Fingerprinting Takes Compliance Seriously
At Lotey Fingerprinting Services in Brampton, every client session generates a complete, compliant record set — consent documentation, ID verification, TCN, and payment receipt — issued to the applicant at the time of service. Our accreditation files, security inspection reports, and EFCD certification documentation are maintained to CCRTIS standards. Our privacy practices comply with PIPEDA.
When you book with Lotey, you are booking with an agency that has gone through the full RCMP accreditation process and maintains the standards that accreditation demands — not just to stay on the list, but because you are trusting us with your biometric identity.
FAQ: Your Questions Answered
What is the most important document a fingerprinting agency must keep for each client?
The two most critical documents per session are the signed consent form and the Transaction Control Number (TCN). The consent form is the legal basis for collecting and submitting biometric data — without it, the agency has no documented authority to act. The TCN is the RCMP RTID-generated reference that proves the submission was transmitted and allows it to be traced if results are delayed, disputed, or missing. Every applicant should also receive their TCN as a personal record at the time of service.
Are fingerprinting agencies required to comply with PIPEDA in Canada?
Yes. Fingerprinting agencies collect, use, and disclose personal information — including biometric data — in the course of commercial activity, which brings them under the Personal Information Protection and Electronic Documents Act (PIPEDA). PIPEDA requires agencies to have a documented privacy policy, obtain informed consent before collecting biometric information, protect personal data appropriately, retain it only as long as necessary, destroy it securely, and allow individuals to access their own records on request.
How long does the RCMP keep fingerprint data after submission?
For civil fingerprint submissions, RCMP CCRTIS retains fingerprint data for 90 days before destruction. This means that after your criminal record check is processed and the result issued, the fingerprint data itself is not held indefinitely — it is purged within 90 days. The criminal record result and associated identifiers are retained separately within the National Repository if a criminal record exists.
Does a fingerprinting agency need to give applicants a copy of their consent form?
Under PIPEDA, individuals have the right to access their own personal information held by an organisation. Best practice — and the standard Lotey Fingerprinting follows — is to provide every applicant with a copy of their completed consent form and their TCN at the time of service. This creates a complete record for the applicant and avoids disputes about what was agreed and submitted.
What should I do if I lost my fingerprinting receipt and need to trace my results?
Contact the fingerprinting agency where your session was conducted and provide your full name, date of birth, and approximate date of the session. The agency’s appointment log and TCN records should allow them to locate your submission. With your TCN, both you and the agency can make enquiries with RCMP CCRTIS about the status of your criminal record check.
Can an employer or HR department keep copies of an employee's fingerprint records?
No — employers should not receive or retain copies of an employee’s fingerprint data or the biometric submission itself. The employer receives only the result of the criminal record check — a confirmation of whether a record exists — not the fingerprint data or the submission documentation. The fingerprint records remain with the fingerprinting agency and the RCMP. Biometric data is the most sensitive category of personal information and its distribution is tightly restricted.
How should a fingerprinting agency securely destroy client records?
Secure destruction depends on the format of the record. Physical documents (consent forms, ID copies) should be cross-cut shredded or destroyed by a certified document destruction service. Digital records should be securely deleted using methods that prevent recovery — simple deletion to the recycle bin is not sufficient. Agencies should maintain a destruction log recording what was destroyed, the date, and the method used.
What is the RCMP security inspection now, and how is it documented?
RCMP CCRTIS has outsourced physical site and IT security inspections to private-sector security firms that meet CCRTIS qualification criteria. Fingerprinting agencies must arrange and pay for their own inspections through these approved firms. The inspection results in a written report confirming whether the agency’s premises and systems meet RCMP standards. This report is a critical compliance document — agencies must retain it as evidence of passing inspection and produce it if audited by CCRTIS.
What happens to client records if a fingerprinting agency closes or loses RCMP accreditation?
If an agency closes or has its accreditation revoked, it retains obligations under PIPEDA to protect and appropriately dispose of client personal information. Records should not simply be abandoned or discarded — they must be securely destroyed or transferred only in ways that comply with PIPEDA consent requirements. Any applicants with pending submissions would need to resubmit through a currently accredited agency.
Should fingerprinting agencies keep records differently for mobile vs. in-office sessions?
The content of records is the same regardless of where the fingerprinting takes place — consent form, ID verification, TCN, payment receipt. For mobile sessions, agencies should additionally document the off-premises location, the date and time, and confirm that all required equipment was present and functioning correctly. This is particularly relevant because RCMP CCRTIS accreditation requirements cover the security of the premises and equipment — mobile operations require careful management to ensure the same standards are met off-site as in the primary accredited location.
Navneet Lotey
Navneet Lotey has over 5 years of experience in fingerprinting. He aims to deliver accurate, easy-to-understand fingerprinting solutions for individuals and businesses alike.