AI-Assisted Data Classification for Compliance and Security
Enforcement · Safety & Security
What it collects
- Government documents, records, and data files subject to security classification and regulatory retention policies at the Department of National Defence.
- Run by
- National Defence (DND)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
This AI system automatically classifies government data according to security and regulatory retention policies at the Department of National Defence. It is used by Government of Canada employees to reduce the risk of non-compliance with data-handling rules. The system makes classification decisions about information, which may affect how long data is kept and who can access it.
What it collects and what happens to it
Data taken in
- Government documents, records, and data files subject to security classification and regulatory retention policies at the Department of National Defence.
Processing
- The AI applies classification and prediction techniques to assign security and retention policy labels to data records, based on learned patterns from existing policy frameworks.
What it does
- The AI classifies data into security and retention categories. The system's outputs inform compliance decisions; GC employees are the primary users and are expected to review or act on classifications.
Outputs
- The system produces classification decisions — assigning security labels and retention categories to government data. These outputs determine how data is handled, stored, and disposed of.
Run by
- The Department of National Defence (DND) is the federal department accountable for deploying this AI system to classify data per security and retention policies for Government of Canada employees.
Built by
Not stated by the Helpful Places.
Kept for
Not stated by the Helpful Places.
Shared with
- Classification outputs are available to the Department of National Defence and GC employees who use the system as part of their compliance workflows.
- Members of the general public do not have direct access to the classification outputs or data processed by this internal government system.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Directive on Automated Decision-Making — AI and Algorithmic Impact Assessment RegisterRegister entry ID: 2526-DND-MDN-006. Department of National Defence.
- AI registerGovernment of Canada AI Register — 2526-DND-MDN-006
- Register entryPublished by the Helpful Places. Reference 597a41d7. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Algorithmic TransparencyAs a Government of Canada employee affected by automated classification decisions, you have the right to be informed that AI is used in this process and to understand the general logic of how data is classified. Contact the Department of National Defence for information about this system.
- Right to Be Informed of AI UseGC employees using this system should be informed that AI is classifying data on their behalf or about their work. The Government of Canada's Directive on Automated Decision-Making requires disclosure of automated systems in use.
Risks and safeguards
- Reputational harmMisclassification of data could result in sensitive government information being improperly retained or disclosed, or non-sensitive data being over-restricted, both of which could harm operational effectiveness or public trust.Safeguard: The system is intended to reduce compliance risk; human employees review outputs, and the use of established security and retention policy frameworks constrains the classification space.
- Civil liberties harmAutomated security classification decisions at a defence department could restrict access to information or affect individuals' rights in ways that are not transparent. Over-classification may impede access-to-information rights.Safeguard: GC employees are the primary users and interact with outputs; explicit mitigation strategies are not described in the register entry.