blog

What Documents Does a Fingerprinting Service Need to Keep — And Why?

Documents Does a Fingerprinting Service Need to Keep

Table of Contents

Running an RCMP-accredited fingerprinting service in Canada is not just about taking clean prints and submitting them correctly. It is about operating a compliant, trustworthy, professionally managed business that handles some of the most sensitive personal information a person can share — their biometric identity.

Every accredited fingerprinting agency is subject to document retention requirements that span four distinct categories: client and applicant records, RCMP accreditation and compliance documents, privacy and data protection records, and operational business records. Getting these right is not optional. They are central to maintaining RCMP accreditation, complying with federal privacy law, resolving applicant disputes, and demonstrating professional integrity to every client who walks through the door.

At Lotey Fingerprinting Services in Brampton, compliance is not a box we tick — it is how we operate. This guide explains exactly what documents an RCMP-accredited fingerprinting service must maintain, how long each should be kept, and what applicants should retain for their own protection.

Why Document Retention Matters for a Fingerprinting Service

Document Retention Matters for a Fingerprinting Service

 Why Is Record Keeping So Important for Fingerprinting Agencies?

The answer is straightforward: fingerprinting services handle biometric data. Fingerprints are permanently, uniquely tied to an individual. Unlike a password or a PIN, they cannot be changed. This makes them among the most sensitive categories of personal information under Canadian privacy law — and it makes the organisations that collect, process, and transmit them subject to a high standard of accountability.

Beyond privacy, document retention matters for five practical reasons:

  • RCMP accreditation maintenance — CCRTIS may conduct inspections or audits of accredited agencies at any time. Agencies that cannot produce required documentation risk suspension or revocation of their accreditation.
  • Submission dispute resolution — If an applicant’s result is delayed, missing, or disputed, the Transaction Control Number (TCN) and submission records are the only way to trace what happened.
  • Rejection resubmission — When a fingerprint submission is rejected, the rejection notice and original session records are needed to correct and resubmit accurately.
  • PIPEDA compliance — The Personal Information Protection and Electronic Documents Act requires organisations to document how personal information is collected, used, stored, and destroyed.

Legal and liability protection — In the event of a complaint, dispute, or investigation, comprehensive records protect the agency and its clients.

Category 1: Client & Applicant Records

Client & Applicant Records

What Client Documents Must a Fingerprinting Service Keep?

These records are created at every single fingerprinting session and form the core of a fingerprinting agency’s operational record:

Consent Form — Signed by the Applicant

The consent form is the legal foundation of every fingerprinting transaction. It documents the applicant’s informed agreement to have their biometric information collected and submitted for a specific purpose. Without a signed consent form, the fingerprinting agency has no legal basis to collect or transmit the applicant’s biometric data.

The consent form must capture

  • Applicant’s full legal name and date of birth
  • Purpose of the fingerprint submission (criminal record check, PCC, immigration, VSC, etc.)
  • Applicant’s signature and the date of signing
  • Acknowledgement that the data will be submitted to the RCMP CCRTIS

The RCMP’s own Consent for Certified Criminal Record Checks form establishes the standard for what consent documentation must contain for civil fingerprinting purposes.

Government-Issued Photo ID Verification Record

Every fingerprinting session requires identity verification — the person being fingerprinted must be confirmed as the person named in the application. Agencies must record:

  • Which form of government-issued photo ID was presented (passport, driver’s licence, PR card, etc.)
  • The ID document number or reference
  • Date of verification

This record protects the agency from fraud claims and confirms that the biometric data submitted belongs to the identified individual.

Application Form and Purpose of Submission

The application form documenting the submission purpose — criminal record check, Police Clearance Certificate, immigration, Vulnerable Sector Check, FBI, or other — must be retained. This establishes the legal purpose for which data was collected and transmitted, which is a core PIPEDA requirement.

Transaction Control Number (TCN)

The TCN is the unique reference number generated by the RCMP RTID system for each electronic fingerprint submission. It is the single most important operational record an agency retains after a submission:

Category Role Requirement
Submission Tracking Uniquely identifies every submission in the RCMP RTID system The only way to trace a submission if results are delayed or missing
Transmission Proof Confirms the submission was received by the RCMP Evidence of successful electronic transmission
Dispute Resolution Required for dispute resolution with RCMP CCRTIS Without the TCN, the RCMP cannot locate the submission in their system
Applicant Record Provides applicant’s proof of submission Agencies should issue the TCN to applicants as a receipt

The TCN is non-negotiable. Every fingerprinting agency must record and retain the TCN for every session — and every applicant should be given their TCN at the time of service.

Payment Receipt

Every session produces a payment record covering both the agency’s service fee and the $25 federal RCMP processing fee collected on the RCMP’s behalf. This must be:

  • Issued to the applicant as a receipt
  • Retained by the agency for financial records

Rejection Notices (Where Applicable)

When the RCMP returns a rejection notice for a submission, the agency must retain this document. It identifies the reason for rejection, which is needed for accurate resubmission, and it forms part of the audit trail for that applicant’s file.

Category 2: RCMP Accreditation & Compliance Documents

RCMP Accreditation & Compliance Documents

 What Accreditation Documents Must a Fingerprinting Agency Maintain?

These documents sit at the business level — they are not created per session but must be kept current and accessible throughout the agency’s accredited operation

Document Purpose Compliance Importance
RCMP CCRTIS Accreditation Certificate Formal confirmation of accreditation by the RCMP Proof of authority to submit civil fingerprints electronically
CSO Security Screening Certificate Personnel security clearance for the Company Security Officer Mandatory RCMP requirement that must remain valid and renewed when required
ACSO Security Screening Certificate Security clearance for the Alternate Company Security Officer Required to maintain accreditation continuity and operational compliance
Physical Site Security Inspection Report Assessment conducted by an RCMP-qualified private security firm Confirms the premises meet CCRTIS physical security standards
IT Security Inspection Report Independent review of systems and network security controls Demonstrates compliance of data systems and submission infrastructure
EFCD Device Certification Documentation Certification records for the Electronic Fingerprint Capture Device Verifies the device is RCMP-certified and NIST-compliant
Certified Vendor Documentation Manufacturer compliance records from an RCMP-approved vendor Establishes the device’s compliance and certification at source
RTID Connectivity & Configuration Records Technical documentation of integration with the RCMP RTID system Required during inspections, audits, troubleshooting, and dispute resolution

Important: Security inspections are now conducted by private-sector inspection firms qualified under CCRTIS criteria — agencies are responsible for arranging and paying for these inspections. Retaining the inspection reports from these firms is critical, as these reports will be the primary evidence of compliance if CCRTIS ever audits the agency.

Category 3: Privacy & Data Protection Records

Privacy & Data Protection Records

What Privacy Records Must a Fingerprinting Service Keep Under PIPEDA?

Fingerprinting agencies are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada’s federal private sector privacy law — because they collect, use, and disclose personal and biometric information in the course of commercial activity.

PIPEDA requires organisations to document their privacy practices and be accountable for how personal information is handled. Specific records that must be maintained include:

Privacy Policy

A documented privacy policy explaining:

  • What personal and biometric information is collected
  • Why it is collected and for what purposes
  • How it is stored and protected
  • How long it is retained
  • How it is destroyed
  • Who it is disclosed to (RCMP CCRTIS, and no one else without consent)
  • How applicants can access their own records or request correction

This policy must be made available to applicants at the point of collection.

Data Retention and Destruction Log

RCMP CCRTIS retains fingerprint submission data for 90 days before destruction. Fingerprinting agencies must have their own documented retention and destruction policy for client records — and a log recording when client files were destroyed and by what method.

Biometric data cannot simply be deleted carelessly. Secure destruction must be documented.

Client Consent and Withdrawal Records

Where an applicant withdraws consent after the fact, that withdrawal must be documented — including the date, the applicant’s request, and the action taken by the agency in response.

Data Breach Response Log

In the event of a data breach — whether a physical breach (lost records), a digital breach (system compromise), or an accidental disclosure — PIPEDA requires prompt notification to affected individuals and, in serious cases, to the Office of the Privacy Commissioner. The agency must maintain:

  • A log of all data incidents, however minor
  • The response actions taken
  • Notification records if applicable

Category 4: Operational & Business Records

Operational & Business Records

What Operational Records Should a Fingerprinting Service Maintain?

Beyond the regulatory minimums, professional fingerprinting operations maintain operational records that protect both the business and its clients:

  • Appointment and session log — date, time, applicant name, submission type, TCN for every session. This is the agency’s master record of all transactions.
  • Staff training records — documentation that all fingerprint technicians have received training in RCMP standards, technique requirements, form compliance, and privacy obligations.
  • EFCD device maintenance and calibration records — scheduled and unscheduled maintenance logs for fingerprint capture devices, confirming ongoing certification compliance.
  • Error and resubmission log — tracking of any rejected submissions: what was rejected, the stated reason, and the corrective action taken.
  • Mobile fingerprinting session records — where the agency provides mobile services, additional records of site, date, and session conduct should be kept for each off-premises appointment.

How Long Should Each Record Type Be Kept?

Long Should Each Record Type Be Kept

What Are the Record Retention Timelines for Fingerprinting Services?

Record Type Retention Period Reason for Retention
Client Consent Forms & ID Verification Minimum 2 Years PIPEDA accountability and dispute resolution support
Transaction Control Numbers (TCNs) Minimum 2 Years Required for RCMP dispute resolution and applicant follow-up inquiries
Rejection Notices Minimum 2 Years Supports resubmissions and maintains a complete audit trail
RCMP Accreditation Certificate Accreditation Period + 2 Years Proof of authority to operate during and after accreditation
Security Inspection Reports Until Next Inspection Cycle (Minimum 3 Years) Essential evidence for CCRTIS audits and compliance reviews
Personnel Security Screening Certificates CSO/ACSO Role Duration + 2 Years Required to demonstrate ongoing RCMP security compliance
EFCD Certification Documents Device Life Cycle + 2 Years Maintains proof of equipment certification and compliance
Payment Receipts & Financial Records Minimum 7 Years Required under CRA business record retention standards
Privacy Policy Version Records Indefinitely (or Superseded Version + 5 Years) Supports long-term PIPEDA accountability and governance
Data Breach Logs Minimum 2 Years from Incident Required for privacy incident tracking and regulatory compliance
Staff Training Records Employment Duration + 2 Years Protects against liability and demonstrates training compliance

What Should Applicants Keep for Their Own Records?

Applicants Keep for Their Own Records

What Documents Should a Fingerprinting Applicant Keep After Their Session?

It is best practice for fingerprinting services to advise every applicant to retain:

  • A copy of their completed fingerprint consent and application form — confirms the purpose and details of the submission
  • Their Transaction Control Number (TCN) or session receipt — the only way to trace a submission if results are delayed, missing, or disputed. Every applicant should receive this before leaving.
  • The rejection notice (if applicable) — needed for the resubmission appointment; bring it with you so the new technician understands what went wrong the first time
  • Any RCMP correspondence about their criminal record check — including result letters, extension notices, or queries
  • The original request from the employer or agency that triggered the fingerprinting — establishes the purpose context if questions arise later

If an applicant cannot locate their TCN and needs to trace a submission, they should contact the fingerprinting agency first — the agency’s session log and TCN records are the starting point for resolution.

What Happens If an Agency Cannot Produce Required Documents?

Agency Cannot Produce Required Documents

 What Are the Consequences of Poor Record Keeping for Accredited Agencies?

Document failure at an RCMP-accredited fingerprinting agency carries serious consequences:

  • RCMP CCRTIS audit failure — leading to suspension or revocation of accreditation
  • PIPEDA complaints — if applicants cannot access their own records, or if poor data handling leads to a complaint to the Office of the Privacy Commissioner of Canada
  • Inability to resolve disputes — without TCNs and session records, the agency cannot assist an applicant whose results are delayed or missing
  • Liability exposure — if a client suffers harm as a result of lost, misdirected, or improperly handled biometric data, documented records are the agency’s primary defence

Professional fingerprinting agencies treat their records with the same seriousness that legal or medical offices treat client files — because the data is equally sensitive and the regulatory obligations are equally real.

Why Lotey Fingerprinting Takes Compliance Seriously

At Lotey Fingerprinting Services in Brampton, every client session generates a complete, compliant record set — consent documentation, ID verification, TCN, and payment receipt — issued to the applicant at the time of service. Our accreditation files, security inspection reports, and EFCD certification documentation are maintained to CCRTIS standards. Our privacy practices comply with PIPEDA.

When you book with Lotey, you are booking with an agency that has gone through the full RCMP accreditation process and maintains the standards that accreditation demands — not just to stay on the list, but because you are trusting us with your biometric identity.

FAQ: Your Questions Answered

What is the most important document a fingerprinting agency must keep for each client?

 The two most critical documents per session are the signed consent form and the Transaction Control Number (TCN). The consent form is the legal basis for collecting and submitting biometric data — without it, the agency has no documented authority to act. The TCN is the RCMP RTID-generated reference that proves the submission was transmitted and allows it to be traced if results are delayed, disputed, or missing. Every applicant should also receive their TCN as a personal record at the time of service.

 Yes. Fingerprinting agencies collect, use, and disclose personal information — including biometric data — in the course of commercial activity, which brings them under the Personal Information Protection and Electronic Documents Act (PIPEDA). PIPEDA requires agencies to have a documented privacy policy, obtain informed consent before collecting biometric information, protect personal data appropriately, retain it only as long as necessary, destroy it securely, and allow individuals to access their own records on request.

For civil fingerprint submissions, RCMP CCRTIS retains fingerprint data for 90 days before destruction. This means that after your criminal record check is processed and the result issued, the fingerprint data itself is not held indefinitely — it is purged within 90 days. The criminal record result and associated identifiers are retained separately within the National Repository if a criminal record exists.

Under PIPEDA, individuals have the right to access their own personal information held by an organisation. Best practice — and the standard Lotey Fingerprinting follows — is to provide every applicant with a copy of their completed consent form and their TCN at the time of service. This creates a complete record for the applicant and avoids disputes about what was agreed and submitted.

 Contact the fingerprinting agency where your session was conducted and provide your full name, date of birth, and approximate date of the session. The agency’s appointment log and TCN records should allow them to locate your submission. With your TCN, both you and the agency can make enquiries with RCMP CCRTIS about the status of your criminal record check.

No — employers should not receive or retain copies of an employee’s fingerprint data or the biometric submission itself. The employer receives only the result of the criminal record check — a confirmation of whether a record exists — not the fingerprint data or the submission documentation. The fingerprint records remain with the fingerprinting agency and the RCMP. Biometric data is the most sensitive category of personal information and its distribution is tightly restricted.

 Secure destruction depends on the format of the record. Physical documents (consent forms, ID copies) should be cross-cut shredded or destroyed by a certified document destruction service. Digital records should be securely deleted using methods that prevent recovery — simple deletion to the recycle bin is not sufficient. Agencies should maintain a destruction log recording what was destroyed, the date, and the method used.

RCMP CCRTIS has outsourced physical site and IT security inspections to private-sector security firms that meet CCRTIS qualification criteria. Fingerprinting agencies must arrange and pay for their own inspections through these approved firms. The inspection results in a written report confirming whether the agency’s premises and systems meet RCMP standards. This report is a critical compliance document — agencies must retain it as evidence of passing inspection and produce it if audited by CCRTIS.

If an agency closes or has its accreditation revoked, it retains obligations under PIPEDA to protect and appropriately dispose of client personal information. Records should not simply be abandoned or discarded — they must be securely destroyed or transferred only in ways that comply with PIPEDA consent requirements. Any applicants with pending submissions would need to resubmit through a currently accredited agency.

The content of records is the same regardless of where the fingerprinting takes place — consent form, ID verification, TCN, payment receipt. For mobile sessions, agencies should additionally document the off-premises location, the date and time, and confirm that all required equipment was present and functioning correctly. This is particularly relevant because RCMP CCRTIS accreditation requirements cover the security of the premises and equipment — mobile operations require careful management to ensure the same standards are met off-site as in the primary accredited location.

Picture of Navneet Lotey

Navneet Lotey

Navneet Lotey has over 5 years of experience in fingerprinting. He aims to deliver accurate, easy-to-understand fingerprinting solutions for individuals and businesses alike.

Leave a Reply

Your email address will not be published. Required fields are marked *