AI-Assisted Remote Reporting for Immigration Enforcement Conditions
Border & Immigration · Safety & Security
What it collects that can identify you
- Five facial photo views (straight ahead, up, down, left, right) submitted by the individual at each reporting event via the ReportIn app, plus an enrollment reference photo taken during the initial in-person or virtual CBSA onboarding session.
- GPS and sensor-derived location of the individual's smartphone at the moment of each report submission, used to verify compliance with any location-specific reporting conditions. The EnStream location service may also be used during non-compliance investigations.
- Given and family name, Unique Client Identifier (UCI), personal email address, phone number, employment information, device ID, device model, and operating system version — collected directly from the individual via the ReportIn app and used by CBSA officers to manage and contact individuals.
- Run by
- Canada Border Services Agency (CBSA)
- Where
- No fixed location
- Kept
- Retained As per CBSA PPU1801 (specific period not stated in AIA)
- Shared with
- Accountable organization, Vendor
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
ReportIn is a voluntary smartphone app that lets people subject to Canadian immigration reporting conditions check in remotely using facial comparison and GPS location, instead of visiting a CBSA office in person. Amazon Rekognition compares submitted photos against an enrollment reference photo and produces a similarity score; a trained CBSA officer reviews every single report before any compliance determination is made. The most important thing to know is that no automated decision is final — 100% of reports receive human review through a three-tier escalation process.
What it collects and what happens to it
Data taken in
- Five facial photo views (straight ahead, up, down, left, right) submitted by the individual at each reporting event via the ReportIn app, plus an enrollment reference photo taken during the initial in-person or virtual CBSA onboarding session.
- GPS and sensor-derived location of the individual's smartphone at the moment of each report submission, used to verify compliance with any location-specific reporting conditions. The EnStream location service may also be used during non-compliance investigations.
- Given and family name, Unique Client Identifier (UCI), personal email address, phone number, employment information, device ID, device model, and operating system version — collected directly from the individual via the ReportIn app and used by CBSA officers to manage and contact individuals.
Processing
- Amazon Rekognition performs one-to-one facial comparison between the submitted report photos and the stored enrollment reference photo, analyzing facial attributes (landmarks, beard, eyeglasses, eye openness) to produce a percentage similarity score. This is not a one-to-many database search against publicly collected images.
What it does
- Amazon Rekognition processes five facial photo views submitted through the ReportIn app, comparing them against a stored reference photo to produce a percentage similarity score. This score is advisory — a trained CBSA officer makes the final match or no-match determination.
- The system scores the likelihood that the reporting individual matches their enrollment photo (pass at ≥99% similarity, fail below 99%) and also validates GPS location data. These scores and flags are presented to CBSA officers who make the final compliance assessment.
Outputs
- A percentage facial similarity score (pass if ≥99%, fail if <99%) displayed to CBSA ATD Monitoring Centre Officers in the CRES backend system, along with location match status, to inform but not replace the officer's match or no-match determination.
- CBSA officer compliance records (match or no-match status, reporting frequency, compliance history) stored in CRES and linked to identified individuals, used by enforcement officers to assess ongoing compliance with immigration conditions.
Run by
- The CBSA deploys and operates CRES/ReportIn under its Intelligence and Enforcement Branch to monitor individuals subject to immigration reporting conditions as an alternative to detention.
Built by
- Amazon developed and supplies the facial comparison software (Amazon Rekognition) and the cloud infrastructure (AWS) on which CRES runs. AWS operates under a contract that prohibits use or disclosure of personal information beyond contracted service delivery.
Kept for
- Facial photos (enrollment, reference, and report photos), location data, compliance records, device information, and personal identifiers are retained in CRES on CBSA cloud servers in accordance with Personal Information Bank CBSA PPU1801.
- Duration: As per CBSA PPU1801 (specific period not stated in AIA)
Shared with
- CBSA immigration enforcement personnel access CRES to review facial comparison scores, location data, reporting frequency, compliance history, and to use the one-way direct messaging feature. Access is gated — all CBSA staff using CRES must first complete the CBSA Facial Comparison Course.
- AWS may access personal information only to the extent necessary to provide contracted cloud services or to notify CBSA of personal data breaches. The contract includes a non-disclosure agreement. AWS does not use individual data for training or other purposes.
- Individuals subject to reporting conditions do not have direct access to their compliance records, similarity scores, or CRES data through the ReportIn app. They are contacted by CBSA officers only when a follow-up investigation is triggered.
Stored
- All CRES data is stored on Amazon Web Services (AWS) cloud infrastructure under a contract that prohibits AWS from accessing, using, or disclosing personal information except as needed to provide services or notify of data breaches.
- Duration: As per CBSA PPU1801 and AWS contract terms
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerCanada AI Register — Client Reporting and Engagement System (CRES)/ReportInAI Register ID: 2526-CBSA-ASFC-003. Canada Border Services Agency.
- Policy documentAlgorithmic Impact Assessment — CRES/ReportIn (AIA Package ID: eaeb269c-6ac5-4429-a5aa-1fcc07c77933)AIA Version 0.10.0. Director General Bradley Belanger, Intelligence and Enforcement Branch, CBSA.
- AI registerCanada AI Register — CRES/ReportIn
- Policy documentAIA — CRES/ReportIn
- Register entryPublished by the Helpful Places. Reference e6bc8748. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseIndividuals are informed of AI use before enrollment. The CBSA discloses that ReportIn uses automated facial recognition software. AI use is disclosed to users as confirmed in the register. Plain-language notice is posted through all service delivery channels (Internet, in person, mail, or telephone) as required by the AIA Impact Level 2 requirements.
- Right to a Human ReviewEvery report is reviewed by a trained CBSA ATD Monitoring Centre Officer (ATD MCO). If a facial comparison fails, the case escalates to an ATD Monitoring Centre Supervisor (ATD MCS), and then to a Regional Inland Enforcement Officer (IEO) who may interview the individual in person before any detention decision is made. The ATD MCO — not the system — makes the final match determination.
- Right to an Explanation of a DecisionWhere a decision results in denial of a benefit or regulatory action, individuals are entitled to a meaningful explanation in plain language covering: the role of the system in the decision; the training and client data used; the criteria applied to evaluate the data; the system output and how to interpret it; the principal factors leading to the decision; and available recourse options. This is required under AIA Impact Level 2 and the Directive on Automated Decision-Making.
- Right to ContestIndividuals who fail a facial comparison or location match may challenge the determination through a three-tier recourse process: first with the ATD Monitoring Centre Officer, then with the ATD Monitoring Centre Supervisor, and finally with the Regional Inland Enforcement Office. At each level, the individual has an opportunity to provide additional information or evidence, including in-person participation in an investigation.
Risks and safeguards
- Civil liberties harmFacial recognition applied to a vulnerable population (immigration detainees and those on enforcement conditions) could produce false negatives leading to unnecessary detention, or create surveillance chilling effects on movement. The algorithm is a trade secret and difficult to interpret. Mitigations: 100% human review of every submission through a three-tier escalation (ATD MCO → ATD MCS → Regional IEO); the app is voluntary; Privacy Impact Assessment completed; Privacy Commissioner consulted; AWS contract prohibits secondary use of personal data; third-party bias evaluation by Credo AI showed 99.9% match rate across six demographic groups; plain-language notice provided through all service delivery channels.
- Reputational harmA false facial comparison failure could stigmatize an individual as non-compliant, potentially triggering investigation and detention. The algorithm may misfire due to image angle, blur, or demographic factors. Mitigations: ATD MCO makes the final match/no-match decision (not the algorithm); if one of five photo views fails but others pass, the officer can still record an overall match; the individual is given the opportunity to provide information or evidence during any investigation (e.g., if they have had facial surgery); the reference photo can be updated to reflect legitimate facial changes.