The WCB is inviting your firm to submit a Proposal for the following: A Data Masking Solution for use at the WCB.
Description of Services
To support the successful achievement of the project objectives, the WCB requires Vendors to provide and implement a best-in-class masking solution (the "Solution"). The solution must deliver robust data masking capabilities and meets the high- level functional and nonfunctional requirements listed outline below::
a. Functional requirements:
i. The Solution must automatically discover and identify sensitive data elements across the WCB-supported data sources, including personal, health, financial, and claim-related data, using a combination of metadata inspection, pattern recognition, and configurable detection logic.
ii. The Solution must allow the WCB to configure, manage, and maintain data classification and masking rules that align with the WCB’s data classification standards and privacy obligations. This includes the ability to refine and tune detection rules to reduce false positives and false negatives.
iii. The Solution must support static data masking of production data prior to its use in non-production environments, ensuring that sensitive data is permanently de-identified and cannot be re-identified unless WCB explicitly approves a reversible masking method for a specific use case.
iv. The Solution must support multiple masking techniques, such as substitution, tokenization, shuffling, nulling, and encryption-based masking, and must allow the WCB to apply different techniques based on data type, sensitivity level, and business usage requirements.
v. The Solution must preserve referential integrity, data relationships, and key dependencies across tables, schemas, and databases to ensure that applications, integrations, reports, and analytics continue to function correctly after masking is applied.
vi. The Solution must support consistent and repeatable masking results across recurring data refreshes and across multiple non-production environments, including development, testing, training, and business intelligence environments.
vii. The Solution must support automated execution of masking workflows, including orchestration, scheduling, dependency handling, and integration with the WCB’s existing data refresh, replication, and environment provisioning processes.
viii. The Solution must provide comprehensive monitoring, logging, error handling, and audit capabilities for all discovery, classification, and masking activities, including the ability to demonstrate what data was masked, when, how, and under which rules.
ix. The Solution must support role-based access controls and segregation of duties, ensuring that only authorized users can configure rules, execute masking jobs, view sensitive metadata, or approve masking exceptions.
x. The Solution must be capable of masking large data volumes and high-frequency refreshes, including recurring masking of changing data in the WCB’s BI sub-live environments, without compromising data integrity, usability, or operational timelines.
b. Non-functional Requirements:
i. The Solution must comply with all applicable Manitoba and Canadian privacy and access to information legislation, including FIPPA and PHIA, as well as the WCB internal privacy, security, and data governance policies.
ii. The Solution must ensure that all data processed, stored, or generated, including masked data, metadata, logs, and backups, remains within Canada and within the WCB controlled environments, unless the WCB expressly approves exception in writing.
iii. The Solution must be designed and implemented using secure-by-design principles, including protection of credentials and secrets, encryption of data in transit, and safeguards against unauthorized access to sensitive data and metadata.
iv. The Solution must be capable of performing masking operations at the WCB scale, including large data volumes and recurring refresh cycles, without materially impacting upstream systems, downstream systems, or required operational timelines.
v. The Solution must be reliable and resilient, with mechanisms to detect failures, prevent partial or inconsistent masking outcomes, and enable restart and recovery of masking processes that are interrupted or fail.
vi. The Solution must be deployed within the WCB’s on-premises and cloud environments and must align with the WCB enterprise architecture, infrastructure, networking, and security standards.
vii. The Solution must be operable and supportable by the WCB staff, including enabling configuration management, monitoring, upgrades, patching, and controlled change processes, without dependence on vendor-owned or vendor-managed infrastructure.
viii. The Solution must provide robust administrative, operational, and audit interfaces to support day-to-day operations, troubleshooting, compliance verification, and internal or external audit requirements.
ix. The Solution must be extensible and adaptable to accommodate future growth or changes in data sources, data volumes, masking scope, and regulatory requirements, without requiring fundamental redesign or replacement.
x. The Proponent must provide comprehensive documentation, training, and knowledge transfer sufficient to enable the WCB to independently operate, administer, and govern the Solution throughout its lifecycle.
The WCB is also seeking professional services- including consulting, implementation and support services for the establishment and maintenance of the data masking solution/services as part of this RFP. The vendor shall provide a detailed description of their proposed approach and methodology for the designing, solutioning, sizing, implementing, testing, rolling out, managing, and supporting the masking solution at the WCB. The description must include (but may not be limited to):
a. A detailed explanation of the Vendor's to data discovery, solution design/architecture and overall solutioning of the implementation and service.
b. A clear outline of the implementation scope, methodology, anticipated timeline, and defined milestones.
c. A comprehensive testing and validation cycle, including User Acceptance Testing (UAT), leading to successful roll out.
d. A plan for supporting the WCB with all change management and communication activities required for the rollout and establishment of the masking solution/service. This includes the planning, participation, and provision of all necessary materials.
e. A training plan and program enabling the Vendor to train the WCB personnel for all roles (including administrative and management) associated with the masking solution.
f. A detailed implementation and go-live plan, including warranty provisions and post-go-live support.
g. A description of the proposed work methodology, project management approach, milestones and a milestone-based payment plan.
h. A tiered milestone-linked payment plan that includes payment tied to all milestones including successful completion of the warranty period, and proposed payment plans for annual support services.
i. A detailed annual support plan commencing after post-go-live support and warranty period. The WCB intends to procure two (2) years of support plan through this RFP, with annual options renewal thereafter. The WCB will retain the right to cancel or terminate the support contract with 30 days' notice.
The solution shall be owned by the WCB and shall be hosted within the WCB infrastructure (on premises and/or within the WCB Cloud tenant). The solution must integrate with the WCB's source and target data systems to deliver the required data masking related services.
The WCB may at its sole discretion, contact some or all the Shortlisted Vendors for virtual or in-person demonstration of the proposed solution(s), to obtain additional details or clarifications, and/or conduct interactions or interviews prior to awarding the Contract.
The vendor will not be required to have and maintain worker compensation coverage for its workers who will be providing services, unless required pursuant to The Workers Compensation Act.
The Services shall normally be performed during Business Hours. However, the WCB may request some of the Services to be performed outside Business Hours from time to time, as deemed necessary, in the unfettered discretion of the WCB. The Contractor shall not be entitled to charge overtime rates.
The proponents shall ensure the availability of all relevant resources for as long as required to successful deliver of the Services. The WCB requires the proponents to deploy quality and seasoned resources to provide the Services. The WCB shall reserve the right to terminate the Agreement if the respective vendor proposes or fields inadequately qualified resources in providing Services, or such other reasons in the opinion of the WCB, acting reasonably. The Proposal must include an overview of the proposed resource(s), including profiles of work which highlight their experience performing similar projects in past 5 years.
The Services shall be provided onsite at the WCB's facilities and from the Contractor's facilities located in Canada, as applicable, unless otherwise agreed in writing. Proponents must ensure that relevant team members are available to be physically present at the WCB premises during key phases, important discussions, and critical cutover activities where in-person participation is required for effective service delivery. The WCB expects all travel related costs to be included in the fixed price proposal for the Services. No additional travel or related expenses will be permitted.
The commencement of the Warranty and Support Services is contingent upon the successful completion of the implementation phase, which is expected to take no more than four (4) months. Upon acceptance of the implementation by the WCB, the Vendor shall provide a warranty period of ninety (90) days (the “Warranty Period”). The Warranty Period shall run concurrently with the Post-Implementation Support Services, which will have an initial term of two (2) years.
The preferred start date for the Services is March 27, 2026; however, the WCB reserves the right, at its sole discretion, to amend or modify this proposed start date. The WCB shall have an irrevocable option to extend the Support Services for one (1) additional year under the same terms, conditions, and fees.