Le Québec Vote — lequebecvote.ca

ENQUÊTE

SAAQclic and work performed in India: what the documents prove — and what they do not

Gallant Commission records show that LGS/IBM relied heavily on resources in India, that the SAAQ paid at least $2.6 million to bring some sensitive work back to Quebec, and that an exemption involving client data was considered in 2022. They do not establish that a breach or improper access occurred.

Published September 8, 2026 · Équipe Le Québec Vote

Were Quebecers’ personal records accessible from India during the development of SAAQclic? The most rigorous answer is uncomfortable. Public records show that a concrete risk was identified several times, that teams in India had technical access to the SAAQ network, and that a 2022 exemption request involved production systems containing client data. The records also show that anonymization tools and contractual authorizations were not always aligned with the way LGS/IBM intended to deliver the project. Those same records do not establish that a consultant in India actually viewed, copied or disclosed anyone’s personal file without authorization. In its final report, published on February 16, 2026, the Gallant Commission expressly says it could not determine whether data-conversion operations performed abroad truly created a risk that personal information would be communicated. What is established remains significant: foreign outsourcing was part of the bid’s economic model; the contract imposed limits; the SAAQ paid at least $2.6 million to bring certain sensitive work back to Quebec; and, five years later, its lawyers again had to oppose an exemption that would have exposed production systems to administrators located in India and Morocco, among other places. ## India was not a marginal solution According to the [Gallant Commission report](https://cesis.gouv.qc.ca/fileadmin/documents/Rapport/CESIS_rapport_recommandations.pdf), LGS/IBM estimated that more than 40% of its total resources would be located abroad. For the technology-integration team — responsible in part for the design and development of the enterprise software — planning documents showed that more than 60% of resources would work off-site. The Commission found that a substantial portion of technology integration was outsourced to a centre in India throughout the program. Most of the people involved worked primarily in English. Witnesses described communication, collaboration and translation difficulties that conflicted with the ambition to work in an agile model, on site and in French. The strategy directly affected the price. Resources in the “technology integration” profile were billed at a much lower rate because a significant share of the work was to be done overseas. The use of India did not emerge after the contract was signed as an improvised workaround: it was part of how LGS/IBM planned to deliver the project at the submitted price. ## A “grey area” identified before the contract Even before the contract was awarded, the SAAQ knew that its call for tenders was unclear about work performed abroad. In a [September 23, 2015 email](https://www.cesis.gouv.qc.ca/fileadmin/documents/Malenfant/74_P-1507_courriel_DubeA_KM_travaux_offshore_20150923_bif.pdf), Alain Dubé, then with the major programs directorate, relayed a supplier’s question. The SAAQ asked bidders to present their global pool of resources, yet Quebec public bodies were generally reluctant to permit services from outside Quebec. What proportion would be allowed? Dubé wrote that the tender contained a “grey area” and that the SAAQ needed a clear position. An addendum later allowed certain work outside Quebec, including specific or custom development. The contract signed on June 14, 2017 nevertheless imposed other conditions. The team was generally expected to work in the SAAQ’s Quebec City offices and in French. Specific work could be performed elsewhere where specialized expertise justified it, but it had to be authorized in the lot agreements. The personal-information schedule also required written authorization before any data — even for technical purposes — could be communicated or transferred outside Quebec. The contradiction therefore existed from the outset: LGS/IBM’s delivery strategy depended heavily on foreign resources, while the contract framed off-site work as a case-by-case exception. ## Converting billions of records, including identifying information CASA required information from legacy systems to be converted into the new platform. The Gallant report describes a “mega-conversion” involving billions of pieces of information. These were not merely technical settings. The data included names, addresses, dates of birth and driver’s licence numbers, as well as information about SAAQ suppliers and operations. A [SAAQ note dated September 27, 2019](https://www.cesis.gouv.qc.ca/fileadmin/documents/Malenfant/74_P-1502_DAP_rapatriement_travaux_conversion.pdf) says concerns had been raised during Delivery 1 about conversion and security work assigned to resources in India. According to the note, that work involved manipulating confidential identifying information or creating security roles capable of granting access to it. The SAAQ had assessed as “very high” the risk associated with the manipulation of, or access to, information concerning several million Quebecers from outside Quebec, together with the effect an incident could have on public confidence. The CASA project manager therefore required the relevant work to be brought back to the SAAQ’s head office and IBM’s client innovation centre in Montreal. ## Bringing the work back cost $2.6 million The hourly rate for the technology-integration profile had been reduced to $82 during the bidding process, in part because overseas work cost less. When the SAAQ required the work to be repatriated, the rate increased to $195 from January 1 to March 31, 2018, then to $197. The September 2019 note puts the funding required to cover this rate difference at $2.6 million. The SAAQ’s management committee approved it on February 27, 2018. A [May 20, 2020 legal opinion](https://www.cesis.gouv.qc.ca/fileadmin/documents/Malenfant/74_P-1500_travaux_Inde_PRP_20200520_bif.pdf), for its part, says Project Adjustment Request 35 provided for a budget increase of slightly more than $4 million. The figures do not necessarily measure the same thing: $2.6 million is the documented rate differential, while the overall adjustment may have covered a broader scope. The public records do not support adding the figures as though they were separate expenditures. For Delivery 2, LGS/IBM wanted the same pricing arrangement renewed. The Alliance estimated that keeping conversion and security resources in Quebec would cost an additional $15 million to $16 million. The SAAQ ultimately refused. An internal note stated that the Alliance had not requested written authorization for work outside Quebec that involved handling identifying information or creating privileged security roles. ## Remote access is still a communication The May 2020 legal opinion addresses an important technical argument: keeping the data physically in Quebec does not resolve the issue. SAAQ lawyers examined a scenario in which a resource in India used a virtual private network, or VPN, to view data stored in Quebec. They concluded that this access was subject to section 70.1 of the Act respecting Access to documents held by public bodies and the Protection of personal information. The SAAQ therefore had to ensure that the information would receive protection equivalent to Quebec law. At the time, the lawyers could not confirm that Indian law provided such protection. They said that analysis still had to be completed before the arrangement could be authorized. This distinction matters. Data need not be downloaded onto a foreign server to be communicated abroad: allowing someone in another country to view it remotely can be enough. Commission records also show that, as early as June 16, 2017, [five virtual workstations had been prepared for overseas resources in India](https://www.cesis.gouv.qc.ca/fileadmin/documents/Malenfant/74_P-1518__essais_VPN_Inde_autorises_20170616_bif.pdf). The record establishes that VPN access to the network existed. By itself, it does not prove that those five workstations could view non-anonymized personal information. ## Anonymization: a real safeguard, but an incomplete one The witnesses disagreed about how effective anonymization was. According to former program director Karl Malenfant, the risk resulted from the initial unavailability of an anonymization tool that had been expected for Delivery 1. Guy Beaupré, who led conversion work for LGS/IBM, told the Commission that the tool did not eliminate the risk of access to personal information. Former IBM manager Martine Gagné disputed that the risk existed in the manner described. The Gallant Commission did not resolve this factual conflict. It described the evidence as highly contradictory and said it could not determine whether conversion operations performed abroad actually created a risk of communicating personal information. It nevertheless framed a stark dilemma. If the risk existed, the planned foreign work disregarded the legal framework and it was surprising that the SAAQ paid to correct the situation. If no risk existed, the paid repatriation had no basis. ## A 2022 exemption request involving production systems The issue did not end with Delivery 1. On October 17, 2022, the legal and litigation directorate learned of an exemption request to make CASA production systems, including client data, available to external consultants located in India and Morocco, among other places. In the [emails filed with the Commission](https://www.cesis.gouv.qc.ca/fileadmin/documents/76_P-1688_courriel_dem_derogation_CASA_20221017-27.pdf), an SAAQ lawyer wrote that the supplier had never demonstrated equivalent legal protection for each contemplated foreign location. She warned that an exemption could not displace a statutory duty and should not proceed without that demonstration. The exemption was ultimately rejected. Ten days later, the participants agreed that the need to deliver CASA could not justify failing to meet privacy and information-security requirements. The alternative they selected reveals the nature of the concern. Consultants in India or Morocco held “Basis” system-administrator roles. By default, they were not supposed to have access to production data. But according to the legal email, they could “relatively easily” change their permissions to view client data, and several production environments were not anonymized. The SAAQ therefore chose to program alerts to detect access changes. If access to client data became necessary, the consultant had to be located in Canada. This control is not proof that prohibited access had already occurred. The public records do not say whether an alert was ever triggered, whether access logs were audited retroactively, or whether a consultant abroad actually viewed a client file. ## What can be said — and what cannot The records establish that: - outsourcing to India was a major, planned part of LGS/IBM’s strategy; - the pricing model depended in part on lower foreign labour rates; - the contract required authorization for off-site work and written authorization before any data was communicated or transferred outside Quebec; - VPN access to the SAAQ network was granted to workstations intended for resources in India; - SAAQ officials associated some conversion and security work with a high risk involving identifying information; - the SAAQ paid $2.6 million for the rate difference associated with bringing work back during Delivery 1; - in 2022, an exemption involving production systems and client data was considered, then rejected; and - administrators in India or Morocco had the technical ability to change their own access rights, leading the SAAQ to implement alerts. The records reviewed do not prove that: - personal information was exfiltrated to India; - a foreign consultant unlawfully viewed an identifying record; - a privacy incident linked to these permissions was detected; or - a minister personally authorized the VPN access, repatriation or exemption request. The documented decisions were made primarily within the SAAQ and its relationship with the Alliance. They also span two governments: the contract and first repatriation took place under Philippe Couillard’s Liberal government, while Delivery 2 and the 2022 exemption request occurred under François Legault’s Coalition Avenir Québec government. Without further evidence, attributing the operational decision to a party or minister would go beyond the public record. ## The real accountability question The documented problem is not, in itself, that a Quebec public body used specialists abroad. International outsourcing can provide scarce expertise and lower some costs. The problem is that a program handling some of the most sensitive data held by the state was built around incompatible requirements: a delivery strategy dependent on foreign resources, an objective of on-site work in French, case-by-case authorization, and a legal framework requiring equivalent privacy protection. When that contradiction came to a head, the SAAQ paid more to bring certain work back. It later had to oppose an exemption and monitor administrators who retained the technical ability to grant themselves broader access. Since September 2023, Quebec’s Law 25 has required, among other things, a privacy impact assessment before personal information is communicated outside Quebec and adequate protection for the information. The reform strengthens the process, but it does not answer the historical questions left open by CASA. Closing the file convincingly would still require publication of an audit of access logs, confirmation of whether the 2022 alerts were ever triggered, identification of the environments that were not anonymized, and a complete record of every authorization for work outside the country. Until then, the conclusion must remain precise: **the public record proves a serious organizational and contractual exposure, together with a technical access capability that concerned the SAAQ’s own lawyers. It does not prove that Quebecers’ personal information was actually leaked or improperly viewed in India.**

Sources