2016 FC 1105, 2016 FC 1105
Opinion
[2017] 2 F.C.R. 396 [***] 2016 FC 1105 IN THE MATTER OF an Application by [***] for Warrants Pursuant to Sections 12 and 21 of the Canadian Security Intelligence Act , R.S.C., 1985, c. C-23 and in the Presence of the Attorney General of Canada and Amici ; AND IN THE MATTER OF [***] Threat-Related Activities Indexed as: X ( Re ) Federal Court, Noël J.—Ottawa, February 25, 26, March 1, 31, April 1 and May 9; October 4, 2016. Editor’s Note: Portions deleted by the Court are indicated by [***].
Security Intelligence — Warrants — Application for warrants, amendments to conditions of draft warrant templates presented by Canadian Security Intelligence Service (CSIS) pursuant to Canadian Security Intelligence Service Act (Act), ss. 12(1) , 21 — Act, s. 12(1) allowing CSIS to collect (to extent strictly necessary), analyse, retain information, intelligence relating to activities reasonably suspected of constituting threats to security of Canada — Act, s. 21 instructing CSIS as to how to apply for warrants if conventional means of investigation not sufficient — CSIS creating Operational Data Analysis Centre (ODAC) to exploit data collected from investigations, warrants — Retaining third party information, including associated data, through operation of warrants — Associated data consisting of data collected through operation of warrants and assessed as unrelated to threats, of no use to investigation — Evidence CSIS retaining associated data indefinitely since 2006, inserting it into ODAC program for future investigative purposes — Expression “to the extent that it is strictly necessary” in Act, s. 12(1), implications for CSIS functions of collection, retention, analysis of information needing to be ascertained herein — Applicant asserting, inter alia, s. 12(1) not applying to Act, s. 21 — Arguing collection of information controlled exclusively by s. 21 — Main issues: whether CSIS breaching its duty of candour towards Court by omitting to disclose, explain ODAC program; whether “strictly necessary” limit applying to retention function in regard to information collected through operation of warrants issued pursuant to Act, ss. 2 , 12(1), 21; whether associated data can be retained for future inquiries as part of ODAC program pursuant to Act, ss. 2, 12(1), 21 — CSIS breaching its duty of candour — Court cannot properly assess warrants when not informed of retention policies, practices related to information Court allowing CSIS to collect — CSIS having elevated duty to ensure designated judges can fully assume their role — Court not informed “clearly and transparently” of data retention program — Argument that s. 21 not conferring general supervisory authority to Federal Court judges unacceptable — CSIS having to inform Court fully, substantially, clearly, transparently of its use of information collected through warrants — Qualifier “to the extent that it is strictly necessary” restricting CSIS’s mandate — Essential question whether different parts of Act operating independently from each other or not — CSIS mandate limited in respect of collection, retention of information — CSIS may not keep associated data — S. 21 not creating separate scheme distinct from primary function of CSIS as described in s. 12(1) — Rather complementing primary function of “investigating threats” by establishing procedural requirements when application for warrants sought — Establishing system of judicial control over warrant application process — Parameters set by s. 12(1) not permitting CSIS to retain non-target, non-threat information on long-term basis — If collected information not meeting strict necessity criteria, all three functions (collection, retention, analysis of information) operating outside CSIS’s limited statutory mandate — Adopting such understanding of ss. 2, 12(1) giving full recognition to limited mandate of CSIS — As to changes sought to warrant templates, entrusting decision-making responsibilities to any “service employees” in warrant conditions negatively affecting accountability of CSIS — Transferring decision-making responsibilities from Regional Director General or his Designate to unidentified “service employees” as category inappropriate — Essential that senior executives of CSIS take such decisions — Warrant conditions must recognize operational reality, adapt to it — Operational work dealing with assessment of information should be performed by most relevant resource as long as such task given to specific individuals, not class of employees — Regional Director General must remain fully accountable — Court allowing certain warrant amendments herein, proposing two different assessment periods to process, assess warrant-collected information — Application allowed but only conditions as they read prior to proposed amendments accepted.
This was an application for warrants, and amendments to some of the conditions of the draft warrant templates, presented by the Canadian Security Intelligence Service (CSIS) pursuant to subsection 12(1) and
section 21 of the Canadian Security Intelligence Service Act (Act or CSIS Act). Subsection 12(1) allows CSIS to collect (to the extent that it is strictly necessary), analyse and retain information and intelligence respecting activities that may on reasonable grounds be suspected of constituting threats to the security of Canada.
Section 21 is the procedural
section that instructs the CSIS as to how to apply for warrants to the Federal Court if conventional means of investigation are not sufficient to advance the investigation. Amendments are periodically brought to the warrant conditions templates in order to reflect the powers intended to be granted and their limits. The templates must be adapted to, inter alia , the evolution of technology and of investigative methods.
In 2006, CSIS created the Operational Data Analysis Centre (ODAC) in order to exploit all data collected from investigations and warrants in ongoing and future investigations through a technological program. It was only in 2011 that CSIS indirectly alluded to the ODAC program before the Court. In January 2016, the Security Intelligence Review Committee made public CSIS’s retention of collected information through the operation of warrants. This was the first time the Court understood that CSIS was indefinitely retaining third party information, including associated data.
Associated data consists of data collected through the operation of the warrants from which the content was assessed as unrelated to threats and of no use to an investigation, prosecution, national defence, or international affairs. There was evidence that CSIS has been retaining associated data indefinitely since 2006 and inserting it into the ODAC program for future investigative purposes.
The meaning of the expression “to the extent that it is strictly necessary” in subsection 12(1) of the Act and its implications for the functions of CSIS, i.e. the collection, retention and analysis of information, needed to be ascertained. The historical record demonstrates that the legislator intended to substantially limit the mandate and functions of CSIS in regard to subsection 12(1). The applicant asserted, inter alia , that subsection 12(1) does not apply to
section 21 of the Act . The applicant suggested that CSIS is
permitted by subsection 12(1) to obtain basic information and that following the granting of a warrant, subsection 12(1) no longer applies and the collection of information is instead controlled exclusively by the parameters set in
section 21. The applicant argued that applying the “strictly necessary” qualifier to both collection and retention is an
interpretation of the wording that runs contrary to the structure of subsection 12(1) and to the Supreme Court’s decision in Charkaoui v. Canada (Citizenship and Immigration) ( Charkaoui II). Contrary to the applicant’s position, the amici submitted that subsection 12(1) of the CSIS Act provides exclusive authority for the Service to collect and retain information in the course of its investigations of threats to the security of Canada.
Incidental collection with a minimum period of analysis to determine whether the collected data is threat related or not is the only collection of non-threat-related information that falls within the meaning of “strictly necessary” as per subsection 12(1) of the CSIS Act.
The main issues were: whether CSIS breached its duty of candour towards the Court by omitting to disclose and explain the existence of the ODAC program since its launch in 2006; whether the “strictly necessary” limit applies to the retention function in regard to information collected through the operation of warrants issued pursuant to subsection 12(1) and sections 2 and 21 of the Act ; and whether the associated data can be retained for future inquiries as part of the ODAC program pursuant to subsection 12(1) and sections 2 and 21 of the Act.
Held , the application should be allowed but only the conditions as they read prior to the proposed amendments are accepted. CSIS breached its duty of candour by not informing the Court of its associated data retention program. The Court cannot properly assume its duties to assess very intrusive warrants when the party appearing in front of it ex parte and in camera does not inform the Court of retention policies and practices directly related to the information the Court allows CSIS to collect through the warrants it issues.
Designated judges serve as the gatekeepers of intrusive powers, ensuring a balance between private interest and the state’s need to intrude upon that privacy for the collective good. They must also ensure that the intrusive means sought are proportionate with the gravity of the threat. The warrants issued by the designated judges have direct impacts on the activities of CSIS and on the information that can or cannot be collected and retained. Given its unique position as applicant and sole source of evidence to the Court, CSIS has an elevated duty to ensure the designated judges can fully assume their role.
If CSIS unduly limits the flow of information the Court needs to make proper determinations, then CSIS can be seen as manipulating the judicial decision-making process. The Court was not informed “clearly and transparently” of the establishment of a data retention program. CSIS knew that it had to inform the Court of the substantial changes it brought to its policy of retention of information. Unfortunately, the evidence is inconclusive as to whether or not CSIS intentionally did not inform the Court in a clear and transparent manner.
At the very least, CSIS was aware that it should have informed the Court in 2006, yet did not do so. The position of CSIS that
section 21 of the Act does not confer any general supervisory authority to Federal Court judges is unacceptable. CSIS cannot solely decide what the Court should and should not know. Through its elevated duty of candour, CSIS must inform the Court fully, substantially, clearly and transparently of the use it makes of the information it collects through the operation of Court issued warrants. Failing to do so, the Court is in no position to properly assume its judicial obligation to render justice in accordance with the rule of law.
The qualifier “to the extent that it is strictly necessary” found in subsection 12(1) establishes that CSIS’s mandate is restricted. The essential question was whether the different parts of the CSIS Act operate independently from each other or not. The mandate of CSIS is limited in respect of the collection and retention of information obtained by the operation of warrants. CSIS may retain information that is threat-related, but may not keep associated data collected from the operation of warrants.
Associated data is, in effect, metadata collected through the operation of a warrant of which the analogous content was assessed as non-threat-related and destroyed.
Section 21 supports advancing an investigation when conventional means are not sufficient and intrusive methods are necessary.
Section 21 does not create a separate scheme wholly distinct from the primary function of CSIS as described in subsection 12(1) ; rather,
section 21 complements the primary function of “investigating threats” by establishing procedural requirements when an application for warrants is sought.
Section 21 was enacted to establish an efficient system of judicial control over the warrant application process. Both subsection 12(1) and
section 2 include clear restrictions. In the case of the primary functions delineated in subsection 12(1), the expression “to the extent that it is strictly necessary” establishes an important mandatory restriction to the functions of CSIS. The terminology used shows that the purpose of the
section was intended to be clear and without ambiguity. In regard to
section 2, the wording at the end of the
definitions of threats to the security of Canada “but does not include lawful advocacy, protest or dissent, unless carried out in conjunction with any of the activities referred to in paragraphs (
a) to (d)” shows that legitimate activities (lawful advocacy, protest or dissent) are specifically excluded from the ambit of CSIS. The mandate and functions of CSIS are thus not open-ended; rather, they are clearly limited by the vocabulary used to describe them. Subsection 12(1) must be read logically. The retention function may only logically retain what has been collected in a “strictly necessary” manner.
If CSIS collects information more widely than legally permitted, i.e. outside the scope of the warrant or unrelated to threats, then the information cannot be retained long-term nor can it be analysed, because it should not have been collected in the first place. Given the wording of subsection 12(1), CSIS may only collect and retain information if it is obtained through investigations or otherwise and if the information falls within the boundaries set by subsection 12(1) and
section 2. The parameters set by subsection 12(1) do not permit CSIS to retain non-target and non-threat information on a long-term basis. Simply coming into contact with a targeted individual, a targeted group, or the individual’s or group’s means of communication does not automatically transform a third-party into a legal target. Non-threat and non-target information collected due to a coincidence of time and events should not be retained for more than a short assessment period to determine whether it is threat-related.
The decision of the Supreme Court in Charkaoui II supports the Court’s conclusions that the function of retention is also moderated by the “strictly necessary” limit, and that
section 21 is not an independent scheme operating in isolation from the restrictions of subsection 12(1). The “strictly necessary” concept cannot logically apply to the analysis function other than by relying only on properly collected and retained information. The argument that the “strictly necessary” concept only applies to the function of collection misses the point. All three functions (the collection, retention and analysis of information) are premised on the idea that only legally collected information is retained and analysed by CSIS.
It flows directly from this initial strict limit to collection that the other two functions can operate unimpeded; the filter has already been applied. If the collected information does not meet the strict necessity criteria, all three functions are operating outside CSIS’s limited statutory mandate. This is the only way to interpret subsection 12(1) of the CSIS Act. Failing to give full effect to subsection 12(1) contradicts the purpose intended by the legislator. Adopting such an understanding of subsection 12(1) and of
section 2 gives full recognition to the limited mandate of CSIS. The rule of law is entirely recognized through such an
interpretation. As to the changes sought to the warrant templates, there was concern that CSIS’s proposal to entrust decision-making responsibilities to any “service employees” in the warrant conditions would negatively affect the accountability of CSIS. Warrants are exceptional and
intrusive means of investigation. Asking the Court to authorize the transfer of these important decision-making responsibilities from theRegional Director General or his Designate to unidentified “service employees” as a category is inappropriate. The concept ofaccountability in such a situation is most important. It is essential to ensure that a senior executive of CSIS takes such an importantdecision. Allowing a senior executive to do so is appropriate because the delegation falls within the mandate of the identified executivepursuant to the CSIS Act; it does not violate the designated judges’ mandate.
But for such a delegation to remain valid and legal, theinformation collected must remain related to the threat identified and the target of the warrant. The warrant conditions must recognizeoperational reality and adapt to it. As long as accountability remains strong, with the ultimate responsibility resting on the shoulders of aRegional Director General, operational work dealing with the assessment of information collected through the operation of a warrantshould be performed by the most relevant resource as long as such task is given to specific individuals and not a class of employees.
Itcould thus refer to individuals as long as the Regional Director General remains fully accountable. Finally, the Court allowed certain warrant amendments and proposed two different assessment periods to process and assess warrant-collected information. Following the respective performance of these assessments, information (both content and associated data) foundto be of no assistance to an investigation of a threat, useless for prosecution, or unrelated to international affairs or the defence of Canada,must be destroyed. STATUTES AND REGULATIONS CITED
An Act to amend the Canadian Security Intelligence Service Act and other Acts, S.C. 2015, c. 9. Bill C-9,
An Act to establish the Canadian Security Intelligence Service, to enact
An Act respecting enforcement in relation to certainsecurity and related offences and to amend certain Acts in consequence thereof or in relation thereto, 2nd Sess., 32nd Parl., 1984. Bill C-22,
An Act to establish the National Security and Intelligence Committee of Parliamentarians and to make consequentialamendments to certain Acts, 1st Sess., 42nd Parl., 2015. Bill C-44,
An Act to amend the Canadian Security Intelligence Service Act and other Acts, 2nd Sess., 41st Parl., 2015. Bill C-157,
An Act to establish the Canadian Security Intelligence Service, 1st Sess., 32nd Parl., 1983. Canadian Charter of Rights and Freedoms, being
Part I of the Constitution Act, 1982,
Schedule B, Canada Act 1982, 1982, c. 11 (U.K.)[R.S.C., 1985, Appendix II, No. 44], ss. 7, 8. Canadian Security Intelligence Service Act, R.S.C., 1985, c. C-23, ss. 2 “threats to the security of Canada”, 12, 12.1(1), 13, 14, 15, 16,19, 21, 21.1, 40(1), 41, 42, 53, 54. Canadian Security Intelligence Service Act, S.C. 1984, c. 21. Security of Canada Information Sharing Act, S.C. 2015, c. 20, s. 2. CASES CITED APPLIED: X (Re), 2014 FCA 249, [2015] 1 F.C.R. 684, affg 2013 FC 1275, [2015] 1 F.C.R. 635; Charkaoui v. Canada (Citizenship andImmigration), 2008 SCC 38, [2008] 2 S.C.R. 326.
CONSIDERED: Canada (Citizenship and Immigration) v. Harkat, 2014 SCC 37, [2014] 2 S.C.R. 33; Canadian Security Intelligence Service Act (Re),2012 FC 1437, [2014] 2 F.C.R. 514. REFERRED TO: Charkaoui v. Canada (Citizenship and Immigration), 2007 SCC 9, [2007] 1 S.C.R. 350; R. v. Vu, 2013 SCC 60, [2013] 3 S.C.R. 657;Ruby v. Canada (Solicitor General), 2002 SCC 75, [2002] 4 S.C.R. 3; Almrei (Re), 2009 FC 1263, [2011] 1 F.C.R. 163; Rizzo & RizzoShoes Ltd. (Re), (SCC), [1998] 1 S.C.R. 27, (1998) 36 O.R. (3d) 418; R. v.
Thompson, (SCC), [1990] 2S.C.R. 1111, (1990), 73 D.L.R. (4th) 596; Canadian Security Intelligence Act (Re), (FC), [1998] 1 F.C. 420, (1997), (FC), 10 C.R. (5th) 273 (T.D.). AUTHORS CITED Canada. Commission of Inquiry Concerning Certain Activities of the Royal Canadian Mounted Police. First Report: Security andInformation, Ottawa: Supply and Services Canada, 1980. Canada. Commission of Inquiry Concerning Certain Activities of the Royal Canadian Mounted Police. Second Report: Freedom andSecurity Under the Law, Vols. 1-2,
Part V, Ottawa: Supply and Services Canada, 1981. Canada. Commission of Inquiry Concerning Certain Activities of the Royal Canadian Mounted Police. Third Report: Certain R.C.M.P.Activities and the Question of Governmental Knowledge, Ottawa: Supply and Services Canada, 1981. Canada. Law and Government Division Research Branch. A Comparison of Bills C-157 and C-9, the Proposed Canadian SecurityIntelligence Service Act, Ottawa: Library of Parliament, 1984. Canada. Parliament. House of Commons. Minutes of Proceedings and Evidence of the Standing Committee on Justice and Legal Affairs,
32nd Parl., 2nd Sess., Issue No. 28 (April 3 and 10, May 24, June 7, 1984). Canada. Parliament. House of Commons. Special Committee on the Review of the Canadian Security Intelligence Service Act and the Security Offences Act . In Flux But Not In Crisis: A Report of the Special Committee on the Review of the CSIS Act and the Security Offences Act , September 1990. Canada. Parliament. House of Commons Debates , 32nd Parl., 2nd Sess. (February 10, 1984). Canada. Parliament. Senate. Report of the Special Committee of the Senate on the Canadian Security Intelligence Service.
Delicate Balance: A Security Intelligence Service in a Democratic Society . Ottawa: Minister of Supply and Services Canada, November 1983. Canada. Privy Council. The report of the Royal Commission appointed under Order in Council P.C. 411 of February 5, 1946 to investigate the facts relating to and the circumstances surrounding the communication, by public officials and other persons in positions of trust of secret and confidential information to agents of a foreign power: June 27, 1946 , Ottawa: King’s Printer, 1946. Canada. Royal Commission on Security.
Report of the Royal Commission on Security , Ottawa: Queen’s Printer, 1969. Canada. Security Intelligence Review Committee. Annual Report 2014-2015 . “Broader Horizons: Preparing the Groundwork for Change in Security Intelligence Review”, Ottawa: Public Works and Government Services Canada, 2015. Côté, Pierre-André, The
Interpretation of Legislation in Canada , 4th ed. Toronto: Carswell, 2011. Solicitor General of Canada. On Course: National Security for the 1990s: The Government’s Response to the Report of the House of Commons Special Committee on the Review of the Canadian Security Intelligence Service Act and the Security Offences Act , February 1991. Sullivan, Ruth. Sullivan on the Construction of Statutes , 6th ed. Markham, Ont.: Lexis Nexis, 2014. APPLICATION for warrants, and amendments to some of the conditions of the draft warrant templates, presented by the Canadian Security Intelligence Service pursuant to subsection 12(1) and
section 21 of the Canadian Security Intelligence Service Act . Application allowed but only conditions as they read prior to proposed amendments accepted. APPEARANCES Robert Frater , Katia Bustros , Karla Unger and Anna Walsh , for applicant. François Dadour and Gordon Cameron as amici curiae . SOLICITORS OF RECORD Deputy Attorney General of Canada , for applicant. Table of Contents Paragraph I. Introduction 1 A. Overview 1 B. Factual Context 9 C. Terminology and Useful Concepts 26
(1) Phases of an Intelligence Investigation 27
(2) What is Associated Data? 31
(3) Operational Capacities of the CSIS in Relation to Data Exploitation 37 D. Relevant Legislation 46 E. Historical Overview 50 II. Arguments 56 A. Arguments of the Attorney General and Counsel for the CSIS 56 (1) Subsection 12(1) does not Apply to
Section 21 of the CSIS Act 58
(2) Arguments on Privacy Interests 64
(3) Suggested Amendments to the Conditions 67 B. Arguments of the Amici Curiae 69 (1) Subsection 12(1) Applies to
Section 21 73
(2) Arguments on Privacy Interests 78
(3) Suggestions Regarding Amendments to the Warrant Conditions 81 III. Issues Raised 85 IV. Analysis 86 A. The Duty of Candour 86 B. Limited Mandate of the CSIS 109
(1) Principles of
Interpretation 110
(2) Contextual Approach 117 (
a) McDonald Commission 120 (
b) Bill C-157 and the Pitfield Report 133 (
c) Bill C-9 137 (
d) Standing Committee on Justice and Legal Affairs 139 (
e) Five-Year Review and the Government’s Response 146
(3) The Scheme of the CSIS Act: Purposive and Textual Analysis 150 (
a) Ascertaining the Primary and Secondary Functions of the Service 159 (
b) Details on the Secondary Functions 164 (
c) Distinguishing the Effects of
Section 21 on Subsection 12(1) and
Section 16 167 (
d) Judicial Control Emanating from
Section 21 170 (
e) Distinction Between “Reasonable Grounds to Believe” and “Reasonable Grounds be Suspect[ed]” 173 (
f) Comments on
Part III – Review Processes (SIRC and Bill C-22) 176 (g) Subsection 12(1) Details 181
(4) Additional Considerations 189 (
a) Differences and Similarities with Charkaoui II 189
(5) Key Findings of this
Chapter 196 C. Practical Effects 201
(1) Changes Sought to the Warrant Templates 201 (
a) A New Condition for [***] for the [***] Warrant, and [***] Warrant 204 (
b) A New Condition Authorizing the Retention of [***] for the [***] Warrant, [***] Warrant, and [***] Warrant 208 (
c) A New Condition that Would Govern [***] for the [***] Warrant, and [***] Warrant 212 (
d) Destruction of Information 217 (
e) Proposition Concerning Delegation and Accountability (“Regional Director or his Designate” to be Replaced by “Service Employees”) 220 (
i) General Comments 221 (ii) [***] 224 (iii) [***] 228 (iv) Further Changes from “Regional Director General or his Designate” to “Designated Service Employees” for the Task of Assessing Warrant-collected Non-target Information 231 (f) [***] Warrant Amendment to Remove Condition 2 236 (
g) Amendments to the [***] Warrant and [***] Warrant Concerning Condition 3 238 (h) [***] Warrant—New Condition 3 240 (
i) Solicitor-Client Clarifications and Other Changes, of Which Some Have Already Been Agreed Upon 241 (
j) Further Changes Sought Following the En Banc Hearings (New Definition for “Associated Data”, Communication and Retention Period of [***] Rather than Indefinitely) 247
(2) Further Comments—A Two Stage Process to Assess Warrant-Collected Information 252 V. Conclusion 254 A. Conclusions Reached Regarding the Specific Issues Identified 254 B. Closing Comments 260 VI. Appendices A. Relevant Legislation B. Bibliography The following are the reasons for judgment and judgment rendered in English by Noël j.: I. Introduction A. Overview [ 1 ] In this application for warrants presented by the Canadian Security Intelligence Service (the CSIS, also referred to as the Service) before a designated Judge of the Federal Court pursuant to subsection 12(1) and
section 21 of the Canadian Security Intelligence Service Act , R.S.C., 1985, c. C-23 (the CSIS Act [or the Act]), the CSIS, aside from seeking specific warrants, also asks this Court to amend some of the conditions of the draft warrant templates (further referred to as “warrant templates”). This request stems from three developments: the Federal Court of Appeal’s decision in X (Re) , 2014 FCA 249 , [2015] 1 F.C.R. 684, the coming into force of
An Act to amend the Canadian Security Intelligence Service Act and other Acts [ S.C. 2015, c. 9 ], and an ongoing discussion between the CSIS and the Court regarding the need to protect third party information collected through the operation of warrants notably in file [***]. Following the publication of the Security Intelligence Review Committee’s 2014-2015 Annual Report (the SIRC Report) in late January 2016, new evidence was filed concerning a CSIS program of collection and retention of information. The Court had never before been fully informed of the existence of the program.
The Court, during the hearings, learned that the program had been in existence since 2006 yet it had never heard nor seen any evidence on the matter prior to the recent hearings. As I will detail later, suffice to note for now that for the CSIS, “associated data” is a specific type of metadata obtained from service providers. Although these reasons are based on the
CSIS’s definition of “associated data”, I feel it necessary to further adapt the term to the specific legal and judicial context at play here (see paragraph 31 and following). (Canada. Security Intelligence Review Committee. Annual Report 2014-2015 : “Broader Horizons: Preparing the Groundwork for Change in Security Intelligence Review” (Ottawa: Public Works and Government Services Canada, 2015).) (Bill C-44,
An Act to amend the Canadian Security Intelligence Service Act and other Acts , 2nd Sess., 41st Parl., 2015.) [ 2 ] Following the SIRC’s Report, this Court convened an en banc hearing where proposed amendments to the warrant conditions templates and the collection and retention program were discussed. An en banc hearing is one where all available designated judges attend, may participate, and hear the evidence tendered. This format is helpful as it allows the presentation of evidence pertinent to future warrants applications and helps avoid repetition.
Designated judges can also benefit from each other’s perspectives. In this en banc hearing, the Court heard evidence relevant to warrant applications over a four-day period. [ 3 ] I have been mandated by the Chief Justice to deal with all matters related to the issues raised in this application, meaning that, although all designated judges attended the hearings, I am the sole decision maker in this application; I write these reasons with full judicial independence.
I have attached, at “Appendix B” of these reasons, not only a bibliography of the documents submitted by the sets counsel involved, but also source documents that I consider essential readings for this file. The volume of the works consulted is substantial, but necessary to obtain a proper and broad understanding of the issues before the Court today. Sets of counsel referred to the McDonald Commission’s reports and to excerpts from Hansard and from a committee of the House of Commons; I will discuss, cite, and contextualize these documents later.
After having carefully read the submissions and the books of authorities submitted, in order to properly fulfil my judicial role, I thought it necessary to consult the details of the primary sources referred to by counsel in order to ascertain the legislator’s intent (see, for example, paragraph 62 of these reasons).
In addition, given that the CSIS Act contained a review clause, I took notice of the report on the statutory review and of the corresponding response. [ 4 ] Due to the important issues raised by the proposed amendments to the warrant conditions and by the collection and retention program, I appointed two amici curiae (Mr. Gordon Cameron and Mr. François Dadour) (the amici ) who participated at the en banc hearings, received all documentation, cross-examined witnesses, and filed submissions. I have benefited from written submissions from the Attorney General, counsel for the CSIS, and from the appointed amici .
I ultimately issued the warrants but only accepted the conditions as they read prior to the proposed amendments. By doing so, I relied on conditions developed and reviewed over several years and took under reserve the proposed amendments to the warrant templates. Among other concerns, I also reserved accepting the amendments related to the issue of information collected and retained through the operation of a warrant along with the other proposed amendments. [ 5 ] The text, context and purpose of the CSIS Act surrounding the enactment of subsection 12(1) of the CSIS Act, formerly
section 12 prior to 2015, establishes that strictly limiting the CSIS’s mandate was inherent to the legislator’s intent. As such, the functions of both collection and retention of information must be performed only to the extent that is strictly necessary. On the other hand, the Court finds that strictly limiting the analysis function of the CSIS is unwarranted and runs counter to the legislative intent identified and to common sense. As long as the information analysed is collected and retained because it is threat-related pursuant to
section 2 of the Act, no limit must be imposed on the extent of the analysis that may be performed by the CSIS. [ 6 ] The information collected and retained pursuant to subsection 12(1) and
section 21 of the CSIS Act must be information related to a threat to the security of Canada, which focuses on information that relates to the target of the warrant.
Section 21 is not a scheme operating independently from the primary mandate and functions established at subsection 12(1). Threats to the security of Canada are circumscribed at
section 2 as activities involving the target as determined through investigation. Presently, in order to retain the information collected pursuant to the warrant conditions, the CSIS must assess this information within the one-year time period stipulated in paragraph 21(5)(
b) to determine whether it is indeed linked to the identified threat or may be of some use to a prosecution, national defence, or international affairs. Specifically, due to the illegality identified, information unrelated to the threat and linked to third parties must not be retained as it does not fall within the ambit of the warrants issued by the Court. [ 7 ] In addition, the CSIS has breached its duty of candour towards the Court by failing to inform it clearly and transparently of its retention program, more specifically in regard to associated data collected and retained through the operation of warrants.
Each of these conclusions will be detailed over the course of these reasons, which also include findings as to the proposed amendments to the warrants templates. [ 8 ] To approach this complex decision, I will now describe the general structure of the following reasons. First, I will provide an overview of the relevant facts, terminology, legislation, and legislative history. Second, I will expose the submissions presented by the Attorney General, counsel for the CSIS, and the amici . Third, I will identify the legal issues raised. Fourth, I will perform an analysis containing several chapters. The first
chapter will discuss the duty of candour. The second chapter, the longest, will elaborate as to why the primary function of the CSIS to investigate threats is limited “to the extent that it is strictly necessary” ( subsection 12(1) , sections 2 and 21 ). Having done so, the third
chapter will explore the practical effects of my findings on the Service, notably in regard to the amendments sought to the warrants templates. Finally, I will conclude briefly and add closing comments. It will be suggested that the legislation of 1984 calls for a review in order to answer to the needs of the present and or unforeseen times ahead with an adaptation to new technologies at play. There is a need to rediscuss the benefits of insuring a better national security but with the least intrusion on privacy. A proper balance of these new technologies must be performed. B.
Factual Context [ 9 ] Designated judges have always kept a close eye on the wording of warrants.
They continuously try to ensure that the powers granted by the warrants are clearly defined, that the information collected and the means taken are proportionate to the threat, and that such information relates only to the target of the warrant and not to innocent third parties unassociated to the threat factually described in each warrant application. [ 10 ] Warrants are live documents that require continual review by designated judges with input from counsel for the CSIS and appointed amici (where thought to be necessary).
Amendments are periodically brought to the warrant conditions templates in order to faithfully reflect the powers intended to be granted and their limits. The templates must be adapted to the evolution of technology, of
investigative methods, of programs and means of communications, of case law, and of new laws or amendments to the CSIS Act . The present reasons are an example of such a periodic examination of the warrant conditions templates. [ 11 ] In 2005, a CSIS task force recommended the Service retain all data collected from investigations and warrants in order to exploit that information in ongoing and future investigations through a technological program.
As a result, the Operational Data Analysis Centre (the ODAC) was created and became operational in April 2006. [ 12 ] The CSIS originally intended to present the ODAC program to the Court and to seek its comments, along with its new position on retention of data unrelated to identify threats collected through the operation of warrants (see paragraph 31). It presented the program to the responsible Minister but not to the Court. It was only in December 2011, at an en banc hearing called to deal with the proposed amendments to the warrants templates in response to Charkaoui v.
Canada (Citizenship and Immigration) , 2008 SCC 38 , [2008] 2 S.C.R. 326 (further referred to as “ Charkaoui II” given that Charkaoui v. Canada (Citizenship and Immigration) , 2007 SCC 9 , [2007] 1 S.C.R. 350 “ Charkaoui I” was rendered prior) that an indirect allusion was made to the program. Counsel for the CSIS alluded to the program but did not mention its name or what it consisted of. The allusion came about as a result of my invitation to counsel for the CSIS to add anything as a final comment.
Counsel for CSIS said: “these are other minor changes to the conditions that we think go to clarity … we also looked at trying to better the language … not change to better the language”. More on this exchange later. (See transcript of file [***] dated [***] at pages 83–85.) [ 13 ] These “minor changes” in fact distinguished “associated data” from “content”. Information deemed “content”, according to relevant warrant conditions, is to be destroyed. By inserting the word “content” into the condition, the CSIS effectively rendered it silent on “associated data”.
This change was not performed in response to Charkaoui II, but rather for operational reasons, as the historical record of the ODAC and use of associated data shows. [ 14 ] Following this seemingly innocuous “minor change”, the CSIS later adopted the position that it had explained “clearly and transparently” the retention of associated data to the Court.
However, the SIRC, which studied CSIS’s use of metadata, concluded in its 2014-2015 annual report that the CSIS should have been more explicit with the Court. [ 15 ] Following two days of en banc hearings in March 2016, in a letter dated April 29, 2016 the Attorney General and the counsel for the CSIS acknowledged that the Court was not: “fully advised of the Service’s practices with respect to retention of associated data” and that “[i]t was deeply regrettable that this was only done recently”. [ 16 ] In mid-2015, in the application for warrants indexed as [***] which I was assigned to, the CSIS proposed a series of amendments to the warrant conditions templates.
The changes proposed in that application were presented as consequential to the decision X ( Re ) , 2014 FCA 249 , [2015] 1 F.C.R. 684 [cited above], in turn giving effect to the decision X (Re) , 2013 FC 1275 , [2015] 1 F.C.R. 635, and as a result of the coming into force of Bill C-44, also known as
An Act to amend the Canadian Security Intelligence Service Act and other Acts . Due to the importance of the changes sought, an amicus curiae , Mr. Gordon Cameron, was appointed. [ 17 ] In application [***], the Court considered amendments proposed by the CSIS which aimed to ensure compliance with new legislation, mainly regarding the sharing of information with other international intelligence agencies.
This issue was resolved with input from both counsel for the CSIS and the amicus : amendments to the warrants templates were accepted to impose on the CSIS an obligation to consider potential harm to the person concerned as a result of the shared information. I raised other issues in that same application, notably the CSIS’s undertaking [***] and the issue of collecting and retaining non-threat and third party-related information. The overarching purpose of these discussions was to debate the possibility of an assessment period for retention shorter than [***].
On six occasions, a hearing was held to discuss all of these issues; I will comment further on this topic later. The application for warrants in file [***] was granted with some amendments concerning the sharing of information. [ 18 ] As for the other matters, counsel for the CSIS requested time to review them in light of the Service’s relevant operational needs. At the request of counsel for the CSIS, the period granted to answer the Court’s concerns was extended twice from the initial deadline of September 2015: first to October, and ultimately to December 2015.
It was only on December 8, 2015 that a letter from counsel for the CSIS to the Court broached the topic of the definition of the term “destroyed” and the topic of the assessment period required by the CSIS to decide what information may be retained in conformity with the warrant conditions. It contained numerous amendments to the warrant templates.
At no time during the many hearings, or in any correspondence thereafter, was it mentioned that the CSIS was retaining data concerning third parties unrelated to threats as defined in the conditions required for a warrant to be issued although such retention was the crux of the Court’s concern about non-threat, third party information.
All of the further amendments sought in [***] were to be dealt with in a later application for warrants. [ 19 ] Some of those amendments were assessed with relative ease: in a direction issued January 11, 2016, the Court accepted the amendment concerning the word “obtention” and a second amendment suggesting a shorter retention period for certain types of warrants [***] rather than [***] for [***] warrants). That same direction scheduled another en banc hearing in order to address the other substantial changes sought which required viva voce evidence.
This en banc hearing, which became file [***], the present proceeding, was scheduled to be held from February 25 to February 26, 2016. Two further days of hearings were held on March 31 and April 1, 2016. [ 20 ] In this application, the CSIS seeks amendments to the warrants templates as follows:
a) A provision allowing the Service to retain [***];
b) A new condition allowing the Service to retain [***];
c) A new condition specifically and explicitly governing any [***];
d) A new condition explicitly stating that information destroyed pursuant to a warrant condition [***];
e) New wording describing the persons responsible to determine whether information, communication, or oral communications collected
should be retained, i.e. replacing all references to a “Regional Director General or his designate”; and
f) A series of stylistic or minor changes. (See written submissions to the applicant, at paragraph 12.) In regard to condition (e), as a result of the en banc hearing, the CSIS now proposes that the wording should read “Regional Director” for some decisions and “Service employees” for others. [ 21 ] The public 2014-2015 SIRC Annual Report was tabled on January 28, 2016 in the House of Commons and made public the CSIS’s retention of collected information through the operation of warrants.
This was the first time I understood that the Service was indefinitely retaining third-party information as a result of the operation of warrants. [ 22 ] The day following my reading of the SIRC Report, as part of the [***] application (this file), I issued a direction to the CSIS communicating that the upcoming en banc of late February 2016 would need to address this new matter and that an affidavit should be filed that would “explain in chronological order the various
interpretations adopted by CSIS with respect to metadata use and retention practices by referring to the applicable warrant language, the date of proposed language changes with the exact reference to the application for warrants where counsel brought to the attention to the Court the nature of the use of metadata, such use and retention being in the Service’s view in compliance with the exception to the warrant conditions”. I directed that the affiant be available for examination on the two days already scheduled and that amici would be appointed to assist the Court; Mr. Gordon Cameron and Mr.
François Dadour were appointed. [ 23 ] On that same day, the Federal Court’s designated proceedings registry received a letter from the Assistant Deputy Attorney General (Litigation) addressed to the Chief Justice of the Federal Court. The letter stated that, at the en banc hearing of December 16, 2011 the CSIS had “clearly communicated … the retention program of associated data”.
The letter further indicated that “to ensure that there can be no confusion on this issue going forward” counsel had already made changes in the affidavits in support of two warrant applications [***], at paragraph 91 and [***], at paragraph 71) by adding the following information and bringing it to the attention of the presiding judge: “When a communication is intercepted, the Service obtains the content of the communication but also its associated data. Data associated to any communication collected by the Service is retained except in the following two situations:
a) Data associated to solicitor-client communications is destroyed at the same time as the content of the communication in application of the solicitor-client communications condition found in the warrants; and
b) Data associated to certain voice communications intercepted under the authority of the [***] warrant is destroyed at the same time as the content of the communication in applications of the conditions found in the warrant.” Contrary to what was said in that letter, such information was not addressed by counsel for the CSIS at the 2015 hearings. Therefore, what the Assistant Deputy Attorney General (Litigation) wrote in his letter was not factual.
Counsel for the CSIS, at the first day of the en banc hearings said the following: “It’s unfortunate that at the hearing of August the addition of associated data in the affidavit was not mentioned.
Looking back it’s definitely something that should have been brought to the attention of the Court to give a bit of context as to why it was added”. (See transcript of en banc hearing dated February 25, 2016, at page 58.) As mentioned above and as I will elaborate later, the Attorney General and the CSIS now concede that the retention program of the data collected through the operation of warrants was not clearly communicated. [ 24 ] The Chief Justice, after receiving more information following an exchange of letters with the Assistant Deputy Attorney General (Litigation), called for another en banc hearing to address the systemic issues arising from the CSIS’s behaviour towards the Court in relation to the retention program of associated data and other related concerns.
This en banc hearing, where both the Deputy Attorney General and the Director of the CSIS appeared, was held in the afternoon of June 10, 2016. The following reasons do not deal with the June 10, 2016 hearing but address the various matters raised in file [***] (this file) which include issues related to the ODAC program and whether the Court was properly informed of its existence.
As said, these reasons also address the amendments sought by the CSIS as a result of the hearings held in file [***], which led to the letter of December 8, 2015 referred to above at paragraph 18. [ 25 ] The en banc hearings on these matters, which I presided over, were held over four days in February, March and April 2016. Five affidavits were filed and three affiants were examined by counsel for the CSIS, by the amici , and by some of the designated judges, including myself. A large number of exhibits were produced.
Both the oral and written evidence address the ODAC, the retention of associated data, and the operational explanations supporting the amendments sought to the warrant templates. Written submissions were filed by both sets of counsel and a reply authored by counsel for the Attorney General and the CSIS was received. Having reviewed the factual underpinnings of these reasons, I will now detail certain useful terms and concepts. C. Terminology and Useful Concepts [ 26 ] Before I begin, I want to establish that the vocabulary and
definitions I use are useful to establish the scope of these reasons but that they are not meant to be binding in any other circumstances. I am cognizant of the fact the CSIS and other parties use varying
definitions and concepts to suit their own needs. First, I will describe the phases of an intelligence investigation. Second, I will delineate the term “associated data” and third, present an outline of the ODAC program as revealed by the evidence.
(1) Phases of an Intelligence Investigation
[ 27 ] First, the CSIS, at the initial stage of an investigation, identifies “persons of interest” (persons, groups, or states) that may, for one reason or another, have come to its attention for possibly being related to a perceived threat. A person may draw the attention of the CSIS through different means, notably from tips, from certain behaviours, or as a by-product of other domestic or international investigations. At this initial step, the CSIS will consult its database and publicly available information in order to assess whether the facts reveal a nexus to a
section 2 definition of “threats to the security of Canada”. At this initial assessment stage, the person investigated is referred to as a “person of interest”. The graph below summarizes the three phases and their associated vocabulary: Step 1 “person of interest” Step 2 “subject of investigation” Step 3 “target of investigation” [ 28 ] Second, pursuant to subsection 12(1), if the CSIS reasonably suspects that the facts involving or implicating the person of interest relate to activities that may constitute a threat to security in accordance with the
definitions of threats found at
section 2, then that person becomes a “subject of investigation”. Once the person is deemed a “subject of investigation”, the CSIS can deploy conventional tools of investigation such as the involvement of a human source, physical surveillance, and any other tool or method normally available to police forces or intelligence services.
This stage of investigation does not permit the use of intrusive investigative methods for which a warrant is required. [ 29 ] Third, if the CSIS believes, on reasonable grounds, that a warrant is required to investigate the threat, then the Service may approach the Minister of Public Safety and Emergency Preparedness to obtain his approval to proceed with an application for a warrant in accordance with subsections 21(1) and 21(2) of the Act . If the CSIS proceeds with such an application and is successful, a warrant is issued and the person designated in the application becomes a “target of investigation”.
The graph below summarizes my explanations; it is not meant to be exhaustive: Step Standard Nomenclature Scope of means of investigation Step 1 The CSIS becomes aware that the person may be of interest. “Person of interest” Publicly available information and searches in databases Step 2 The CSIS has reasonable grounds to suspect that the person may be a threat. “Subject of investigation” (subsections 12(1) and (2)) Conventional investigative means Step 3 The CSIS must reasonably believe that intrusive measures are necessary to investigate the threat, and the warrant is granted. “Target of investigation” (subsections 12(1), (2) and
section 21) All conventional and intrusive investigative means [ 30 ] These descriptions of the phases of an investigation pursuant to the CSIS Act are my own; the CSIS may use different vocabulary or concepts for its own purposes. The purpose of explaining the phases is to show that the present reasons deal with the information collected by the operation of warrants issued by the Federal Court. Specifically, these reasons do not address other forms of collection as no evidence was presented to that effect. Still, the present reasons may establish general principles for future purposes.
Having said that, associated data is an essential component of these reasons and I will frame the concept as the CSIS describes it and also as the evidence reveals.
(2) What is Associated Data? [ 31 ] Although the concept of “associated data” is broad, in fact englobing third party information and target-threat-related information, I am specifically addressing the legality of retaining non-threat information and third party information. Third party information, meaning information unrelated to the threat, is frequently collected through the operation of warrants. The Court is concerned about the retention of such information because it is not target-threat related.
Warrant conditions oblige the CSIS to review third party information it has collected in order to assess whether or not it falls within the conditions’ parameters and thus whether or not it can be retained. The term used by the CSIS to describe this specific type of information when obtained from service providers is “associated data”.
The CSIS described the term as follows in an affidavit, but I note that witnesses sometimes referred to the term more broadly in their testimonies: “[I]nformation associated to a communication such as [***].” (See Supplementary Affidavit of [***], filed February 22, 2016 at page 18, footnote 10.) (See transcript dated Thursday, March 31, 2016 [Examination of [***]] at pages 41 and 42.) (See transcript dated Thursday, March 31, 2016 [cross-examination of [***] by Mr.
Dadour] at pages 77–80, 90 and 100–103.) [ 32 ] As per either the present conditions 2 or 3 of some of the warrant conditions templates, the CSIS must review the information collected through warrant operations [***] to ensure that information involving third parties is indeed threat-related. If the information is deemed unrelated to the threat, it must be destroyed.
When performing its assessment, the CSIS must believe on reasonable grounds that the information may be either related to the investigation of a threat, or of assistance to an intelligence investigation or to a prosecution, to national defence, or to international affairs. Such a test gives the CSIS a certain level of discretion. The condition defining these parameters reads as follows: “Subject to condition 1, any record, document or thing obtained pursuant to this warrant that is not destined to or does not originate from
[the target] […] shall be reviewed by a Regional Director General or his designate and, unless he has reasonable grounds to believe the record, document or thing may (
a) assist in the investigation of a threat to the security of Canada; (
b) be used in the investigation or prosecution of an alleged contravention of any law of Canada; or (
c) relate to the international affairs or defence of Canada, any copy of the record, document or thing shall be destroyed within a period of [***] following its obtention.” (See condition 2 or 3 of certain warrant templates. The above relates to a [***] while the others are written in such a way as to adapt to the specifics of the particular warrant template.
They all contain the same requirement for assessment purposes.) [ 33 ] Over the course of these proceedings, it became clear, through submissions and witnesses, that the definition of “associated data” for the Court consists of data collected through the operation of the warrants from which the content was assessed as unrelated to threats and of no use to an investigation, prosecution, national defence, or international affairs. (See affidavit of [***], received March 24, 2016, at paragraphs 47, 56–67 and 90–92.) [ 34 ] The following graph illustrates where associated data fits within a more general framework of the CSIS’s operations; I am aware that I am slightly diverging from the CSIS’s definition: Step 1: information (content + metadata) is collected (Go to step 2).
Step 2: information is assessed by the CSIS - If the content is threat related, both content and metadata are retained. OR - If the content is not threat-related, content is destroyed but metadata is retained (go to step 3).
Step 3: create and retain “associated data” - Metadata originating from content unrelated to the threat, for which the content has been destroyed, is called “associated data”. - The CSIS retains all associated data it has collected for an indefinite period of time. [ 35 ] As the evidence before the Court now reveals, associated data is retained and inserted into the ODAC program for future investigative purposes.
The CSIS has been retaining associated data indefinitely since 2006. [ 36 ] Having established the phases of investigations and defined associated data for the purposes of these reasons, I now turn to describing the ODAC program itself.
(3) Operational Capacities of the CSIS in Relation to Data Exploitation [ 37 ] In the early 2000’s, the CSIS considered that the information it collected through investigations was underutilised as it was not processed through modern analytical techniques. In April 2006, the CSIS launched the ODAC. The ODAC was designed to be “a centre for excellence for the exploitation and analysis” of a number of databases. It took approximately [***] for the centre to become fully operational. The ODAC assumes numerous tasks: it exploits data banks in order to provide: [***]. (See Executive
Summary of the August 10, 2010 Operational Data Analysis Centre Privacy Impact Assessment , performed by [***] (consultant) and finalized by the ATIP [access to information and privacy] branch of the Canadian Security Intelligence Service. Document located in the book “Documents for Amici” as a supplement to the affidavit of [***] (affirmed April 21, 2016), in file [***], at Tab 8.) [ 38 ] The ODAC, up to late 2010, was hosted within the [***] which itself renders multifaceted and specialized support to the CSIS’s operations.
The ODAC [***]. [ 39 ] More specifically, the ODAC processes information held by the CSIS through: “[…] the authority of a warrant or an approved investigation. As of January 2010 […], the ODAC data holdings consisted of [***].” (See letter dated November 8, 2012 to the Office of the Privacy Commissioner signed by [***], Coordinator - Access to Information and Privacy, at page 4.
Document located in the book Documents for Amici as a supplement to the affidavit of [***] (affirmed April 21, 2016), in file [***], at Tab 10.) [ 40 ] The evidence presented during the hearings did not update this information to 2016 except for what follows.
Aside from analysing and processing these datasets into investigative information, the ODAC: “[…] provides operational support for these investigative activities by developing actionable intelligence [***].” (See letter dated November 8, 2012 to the Office of the Privacy Commissioner signed by [***], Coordinator - Access to Information and Privacy, at pages 3 and 4. Document located in the book: Documents for Amici as a supplement to the Affidavit of [***] (affirmed April 21, 2016), in file [***], at Tab 10.) [ 41 ] [***].
The present reasons should not give the impression that the Court is well informed of the [***] program; only very limited evidence was provided. Given that the program was still called the ODAC at the time of the application, I will use that term and not [***]. [ 42 ] The ODAC is a powerful program which processes metadata resulting in a product imbued with a degree of insight otherwise impossible to glean from simply looking at granular numbers. The ODAC processes and analyses data such as (but not limited) to: [***].
The end product is intelligence which reveals specific, intimate details on the life and environment of the persons the CSIS investigates. The program is capable of drawing links between various sources and enormous amounts of data that no human being would be capable
of [***]. [ 43 ] The Data Exploitation Task Force provides more insight into the initial capacities of the ODAC; [***], yet the evidence presented to the Court to this effect was very limited. [***]. ( Data Exploitation Task Force Draft Report (version 1.3) , dated July 11, 2005, at page 10.
Found at Annex B, Tab 4, of the book provided to the Court in response to the letter of March 23, 2016 from the Chief Justice.) [ 44 ] Information collected through the operation of warrants is fed into the ODAC [***] the information is assessed within [***] by the CSIS; the content is destroyed if it is found to be non-threat-related, or unintended for prosecutorial purposes, international affairs, or the defence of Canada.
If the information remains unassessed at the end of the [***] it must be destroyed as mentioned above. [***] the metadata is retained indefinitely even if the underlying content is found to be non-threat related. As we will see later, understanding [***] is important when discussing whether or not a [***] retention period is necessary and appropriate. [ 45 ] Now that I have broadly described the terminology, underlying concepts, and the ODAC program in general, I will detail the relevant legislation and provide a historical overview of the CSIS Act . D. Relevant Legislation [ 46 ] The central focus of my
interpretation of subsection 12(1) will be to ascertain the meaning of the expression: “to the extent that it is strictly necessary” and its implications for the CSIS’s functions. The primary functions of the CSIS are the collection, retention and analysis of information. These three functions must be assessed in conjunction with the existence of a threat to the security of Canada as defined in
section 2 of the CSIS Act . I should mention that I will not analyse the amendments brought to the CSIS Act in 2015 except to note that they provide additional functions to the Service such as the abilities to work internationally (subsection 12(2)) and to take measures to reduce a threat (subsection 12.1(1)). In addition, I note that the Court no longer adjudicates applications for warrants to obtain information from the Canada Revenue Agency [CRA] following the enactment of the Security of Canada Information Sharing Act , S.C. 2015, c. 20, s. 2 .
The factual underpinnings of this development can be found in the SIRC 2014-2015 Report, at pages 27 and 28. This new piece of legislation expanded and facilitated the sharing of information among certain listed Government of Canada institutions that have jurisdiction or responsibilities concerning national security. In practice, the CSIS no longer needs a warrant to obtain information from the CRA.
No submissions were presented by either sets of counsel in regard to these new capacities; they are limited to subsection 12(1) , sections 2 and 21 of the Act. [ 47 ] Subsection 12(1) of the CSIS Act , following amendments to the Act in 2015, reads: Canadian Security Intelligence Service Act , R.S.C., 1985, c.
C-23 Duties and Functions of Service Collection, analysis and retention 12(1) The Service shall collect, by investigation or otherwise, to the extent that it is strictly necessary, and analyse and retain information and intelligence respecting activities that may on reasonable grounds be suspected of constituting threats to the security of Canada and, in relation thereto, shall report to and advise the Government of Canada . [Emphasis added.] [ 48 ] The wording “threats to the security of Canada” found in subsection 12(1) is defined in
section 2 of the CSIS Act to mean: Canadian Security Intelligence Service Act , R.S.C., 1985, c. C-23
Definitions 2 In this Act , … threats to the security of Canada means (
a) espionage or sabotage that is against Canada or is detrimental to the interests of Canada or activities directed toward or in support of such espionage or sabotage, (
b) foreign influenced activities within or relating to Canada that are detrimental to the interests of Canada and are clandestine or deceptive or involve a threat to any person, (
c) activities within or relating to Canada directed toward or in support of the threat or use of acts of serious violence against persons or property for the purpose of achieving a political, religious or ideological objective within Canada or a foreign state, and (
d) activities directed toward undermining by covert unlawful acts, or directed toward or intended ultimately to lead to the destruction or overthrow by violence of, the constitutionally established system of government in Canada, but does not include lawful advocacy, protest or dissent, unless carried on in conjunction with any of the activities referred to in paragraphs (
a) to (d). ( menaces envers la sécurité du Canada ) [ 49 ]
Section 21 is also important; it is the procedural
section that instructs the CSIS as to how to apply for warrants to the Federal Court if conventional means of investigation are not sufficient to advance the investigation. As
section 21 is quite lengthy, it may be
found in the appendices
section at the end of these reasons. (See Appendices A—Relevant Legislation.) E. Historical Overview [ 50 ] As I will elaborate at paragraphs 117–149 below, the historical record demonstrates that the legislator intended to substantially limit the mandate and functions of the CSIS in regard to subsection 12(1) . The results of multiple factors found in the various sources of legislative intent are highly convergent.
All sources, from the McDonald Commission’s recommendations, to the Pitfield Report, to the Solicitor General’s explanations during the clause-by-clause review of the Standing Committee on Justice and Legal Affairs, point to the overarching principle that the mandate and functions of the CSIS should be strictly defined and limited (details below). [ 51 ] Following the establishment of the Royal Commission of Inquiry into Certain Activities of the RCMP in 1977, also known as the McDonald Commission, and the final publication of its recommendations in 1981, the government of the day introduced Bill C-157 [ An Act to establish the Canadian Security Intelligence Service , 1st Sess., 32nd Parl., 1983] in the House of Commons to establish a civilian intelligence security service.
Although I chose 1977 as the most relevant start date, it is obviously possible to refer to relevant events and publications dating further back, such as the Royal Commission on Security in 1969 (the MacKenzie Commission) and the Kellock- Taschereau Commission in 1946 (the Gouzenko Affair). (Canada. Commission of Inquiry Concerning Certain Activities of the Royal Canadian Mounted Police (Ottawa: Supply and Services Canada, 1979, 1981).
There are several reports and several volumes, see Appendix B—Bibliography for details.) [ 52 ] In June 1983, following widespread opposition, Bill C-157 was referred to a special committee of the Senate, which recommended substantial changes to the bill. In November 1983, the Special Committee of the Senate on the Canadian Security Intelligence Service tabled its comprehensive report titled Delicate Balance: A Security Intelligence Service in a Democratic Society (the Pitfield Report).
Bill C-157 was subsequently allowed to die on the order paper and a revamped Bill C-9 [ An Act to establish the Canadian Security Intelligence Service, to enact
An Act respecting enforcement in relation to certain security and related offences and to amend certain Acts in consequence thereof or in relation thereto , 2nd Sess., 32nd Parl., 1984] was tabled in its stead. (Canada. Parliament. Senate. Report of the Special Committee of the Senate on the Canadian Security Intelligence Service. Delicate Balance: A Security Intelligence Service in a Democratic Society (November 1983) (Chair: P.M. Pitfield).) [ 53 ] Following the Pitfield Report, the government issued a written response where it indicated which recommendations it accepted, rejected, or accepted in part.
The response indicated that the Pitfield Report’s recommendation to limit the primary function of CSIS by the addition of a test of “necessity” was accepted. As such, clause 14(1) of Bill C-157 was modified and became clause 12(1) in Bill C-9. Bill C-157 Bill C-9 Functions of Service Duties and Functions of Service 14.
(1) The Service shall collect, by investigation or otherwise, and analyse and retain information and intelligence respecting activities that may on reasonable grounds be suspected of constituting threats to the security of Canada and, in relation thereto, shall report to and advise the Government of Canada. 12.
(1) The Service shall collect, by investigation or otherwise, to the extent that it is strictly necessary , and analyse and retain information and intelligence respecting activities that may on reasonable grounds be suspected of constituting threats to the security of Canada and, in relation thereto, shall report to and advise the Government of Canada. [Emphasis added.] [ 54 ] Bill C-9 was introduced in January 1984 during the second session of the 32nd Parliament. Bill C-9 included virtually all the changes recommended by the Pitfield Report.
It was given first reading in January 1984 and referred to the Standing Committee on Justice and Legal Affairs in March. Bill C-9 passed third reading and was given royal assent in June and was proclaimed in force in two parts over July and August 1984. [ 55 ] The CSIS Act enacted in 1984 contained a review clause calling for a review of the legislation to be performed five years following the coming into force of the Act. Such a review was completed in 1990 and the government issued a report in reply in 1991.
From 1991 until today, the CSIS Act has occasionally been amended, notably by the addition and specification of certain functions in 2015. I will now review the arguments of both the Attorney General and counsel for the CSIS and the amici . II. Arguments A.
Arguments of the Attorney General and Counsel for the CSIS [ 56 ] Summarily, in regard to the CSIS’s duty of candour towards the Court, the Attorney General of Canada and counsel for the CSIS (collectively the AGC) suggest that the Court was indeed advised of the retention program, although not as thoroughly as warranted; no evidence of “systemic obfuscation” has been adduced. Regardless, the Service has committed, going forward, to advise the Court of any proposed changes in practice without delay.
In regard to the amendments to the warrant conditions proposed by the amici , the AGC contends that the amici ’s suggestions are impractical. [ 57 ] In the next paragraphs, I will detail the more complex arguments the AGC puts forward. I will first summarize the AGC’s argument contending that subsection 12(1) and
section 21 are separate schemes operating independently from each other. Later, concerning the legality of the associated data retained, I will detail the AGC’s arguments contending that the amici ’s analysis of privacy interests in relation to
section 8 of the Charter is flawed, and will elaborate on what the AGC considers justifiable in respect to the retention of such data. Since I am concluding that the CSIS does not have the jurisdiction to retain non-threat information related to third parties, I will not deal with the privacy arguments submitted, apart from making brief comments further below. However, I have included the arguments for the sake of future reference and completeness. ( Canadian Charter of Rights and Freedoms , being
Part I of the Constitution Act, 1982 ,
Schedule B, Canada Act 1982 , 1982, c. 11 (U.K.) [R.S.C., 1985, Appendix II, No. 44] (the Charter).) (1) Subsection 12(1) does not Apply to
Section 21 of the CSIS Act [ 58 ] Contrary to the amici ’s basic position, the AGC asserts that subsection 12(1) does not apply to
section 21 of the CSIS Act . In
other words, the limits to the Service’s actions defined at subsection 12(1) should not apply to the collection of information following the issuance of a valid warrant. In essence, the AGC suggests that the collection and retention of information operates in two distinct phases with different sets of parameters. In the first phase, the Service is permitted by subsection 12(1) to obtain basic information. In the second phase, following the granting of a warrant, subsection 12(1) no longer applies and the collection of information is instead controlled exclusively by the parameters set in
section 21. [ 59 ] Limitations found in subsection 12(1) should only apply to information collected from the application of a warrant issued under
section 21 if: (
a) section 21 explicitly or implicitly incorporates subsection 12(1); or (
b) if subsection 12(1) applies to warranted collection under
section 21. In the AGC’s opinion, both of these options are inapplicable. There is nothing in the wording of
section 21 that suggests it was intended to incorporate the restrictions present in subsection 12(1) . Interpreting the matter otherwise risks creating conflicting standards between terms and conditions of warrants and subsection 12(1). [ 60 ] Alternatively, because subsection 12(1) and
section 21 are found in different parts of the CSIS Act , respectively “Duties and Functions of Service” and “Judicial Control”, they should not be found to apply to one another. Sections 15 and 16 would, for example, be limited by subsection 12(1) as they are all found in the same part (Part I [sections 3 to 20]) of the CSIS Act, but
section 21 would not be as it is in the next part (Part II [sections 21 to 28]). The AGC argues that provisions in one part of a statute may only affect provisions in another
part if legislative language supports it. Considering the structure of the scheme, the AGC argues that there is no clear interpretative basis for applying limitations in subsection 12(1) to some activities of the Service (ex.
section 21 ) but not to others (ex. sections 15 and 16). [ 61 ]
Section 21 does not expressly incorporate subsection 12(1). In addition, subsection 21(4), which lists matters that must be specified in a warrant, does not reflect any of subsection 12(1)’s language. Likewise,
section 21 does not implicitly incorporate any requirements found in subsection 12(1) . In fact, subsection 21(3) provides the judge issuing the warrant the power to authorize the interception of “any communication or obtain any information, record, document or thing”. [ 62 ] The AGC responds to the amici ’s argument that the “strictly necessary” qualifier in subsection 12(1) applies to both collection and retention by submitting that such an
interpretation of the wording runs contrary to the structure of subsection 12(1) and to the Supreme Court’s decision in Charkaoui II, above, at paragraph 38. In addition, the AGC asserts that a sentence from a larger explanation given by Minister Kaplan, the Solicitor General at the time the CSIS Act was enacted, shows that the expression “to the extent that is strictly necessary” qualifies the collection function but not the retention function: Mr. Kaplan : Well I had followed in this amendment the exact recommendation of the Senate committee.
The Senate committee looked at the function of collection as the one that ought to be limited to what is strictly necessary. We do not want them to collect any more than is strictly necessary because it is the collection that is the potential violation of people’s privacy rights. As it will be seen later, the AGC, by presenting such a limited sample of a larger discussion, presents Mr. Kaplan as saying something that is contradicted when read in its full context. (Canada. Parliament. House of Commons.
Minutes of Proceedings and Evidence of the Standing Committee on Justice and Legal Affairs , 32nd Parl., 2nd Sess., Issue No. 28 (24 May 1984), at page 28:52 (Chair: Claude- André Lachance).) [ 63 ] The AGC opines that the Supreme Court of Canada, in R. v. Vu , 2013 SCC 60 , [2013] 3 S.C.R. 657, has established that the judiciary effectively balances private and state interests through the issuance of warrants. As such, subsection 12(1) does not need to apply to
section 21 in order for privacy interests to be protected by judges. The only link between subsection 12(1) and
section 21 is that the Service must have initiated an investigation under subsection 12(1) in order to ascertain the facts required to satisfy the Court that a warrant is required.
(2) Arguments on Privacy Interests [ 64 ] The AGC believes the amici ’s
section 8 analysis in relation to privacy interests and the existence of an expectation of privacy is flawed; they overlook relevant cases and propose an approach unsupported by jurisprudence. The amici ’s conclusion that the analysis of associated data creates insights into core biographical information of persons is not supported by the evidence presented to the Court. [ 65 ] The Supreme Court of Canada did not in fact conclude that the existence of an expectation of privacy depends on the potential to draw intrusive conclusions from the information analysed.
Rather, the Supreme Court of Canada indicated that what matters most is the intended use for a specific purpose of that information. In short, the Court should not look at the potential intrusiveness of the information following analysis . Rather, the only appropriate option is to look at the level of intrusiveness of the granular information on its face ( pre-combination and analysis ). The correct approach is to look at the present circumstances only, not at the future potential level of intrusion.
The fact that content is not retained and that associated data does not reveal core biographical information means that there is in fact no intrusion. [ 66 ] More specifically, the AGC contends that common law jurisprudence in regard to
section 8 permits the collection of associated data through the authority conferred by the warrant itself. It is the warrant conditions themselves that allow the CSIS to collect and retain the associated data. In regard to intrusions into the privacy of third parties, the AGC admits that their interests are indeed affected. But, case law permits an inevitable intrusion of privacy following a balancing between private and collective interests performed by the judge when deciding whether to grant the warrant or not.
An intrusion of privacy does not necessarily render the authorization to collect information unreasonable; it also does not need to be minimized as the balancing has already been performed.
(3) Suggested Amendments to the Conditions [ 67 ] The AGC finally proposes amendments to the warrant conditions templates which can be read in the “Factual Context” section, at paragraphs 9 to 25. In general, the AGC contends that the [***] assessment period found in the current warrant conditions is sufficient as it is tied to a high threshold for retention i.e. the “reasonable grounds to believe” used by the Court when determining whether to issue the warrant or not. The AGC proposes a longer period to deal with [***] as it will be seen in the “Practical Ef
[…]
Loading document…