Standing Committee on Public Safety and National Security — Evidence — Tuesday, May 26, 2026 (Meeting 38, 45th Parliament, 1st Session) — Chair: Jean-Yves Duclos

SECU / 45-1 / Meeting 38 / EV14129354

House Committees

Standing Committee on Public Safety and National Security — Evidence — Tuesday, May 26, 2026 (Meeting 38, 45th Parliament, 1st Session) — Chair: Jean-Yves Duclos

SECU / 45-1 / Meeting 38 / EV14129354

House Committees

EVIDENCE

Standing Committee on Public Safety and National Security NUMBER 038 1st SESSION 45th PARLIAMENT Tuesday, May 26, 2026 Le mardi 26 mai 2026 Standing Committee on Public Safety and National Security CANADA [Recorded by Electronic Apparatus] EVIDENCE May 26, 2026 Committee NUMBER 038 NUMBER 038 NUMÉRO 038 38 26 05 2026 2026/05/26 15:45:00 House Of Commons Comité permanent de la sécurité publique et nationale Standing Committee on Public Safety and National Security SECU Chair Jean-Yves Duclos 1 45

(1545) [ Translation ]

The Chair (Hon. Jean-Yves Duclos (Québec Centre, Lib.)) :

Good morning, everyone. This meeting is called to order. Welcome to meeting number 38 of the House of Commons Standing Committee on Public Safety and National Security. If I may, I would like to move right away that we adopt the three budgets that the clerk sent last week. There was one for the study of the main estimates, a second for the study on the management of the Canada-United States border, and a third for the study of Bill C‑22 , which we are continuing today. As you know, the amounts that have been provided to us are estimates. The committee could spend less than planned.

Any unspent funds will be returned to the Liaison Committee. If you have any questions, the clerk will be happy to answer them. Is it the committee's pleasure to adopt the three budgets?

Some hon. members: Agreed. We will now move on to the main topic of our meeting today. Pursuant to the House of Commons order of reference of April 20, 2026, we are meeting today for consideration of Bill C‑22 ,

An Act Respecting Lawful Access. Today we are fortunate to have with us many distinguished witnesses, whom I would like to welcome. From the Barreau du Québec, we welcome Marcel‑Olivier Nadeau, president of the Barreau du Québec, who is joining us by video conference; Nicolas Le Grand Alary, lawyer from the Secretariat of the Order and Legal Affairs, who is with us; and Michel Marchand, member of the Criminal Law Expert Group, who is joining us by video conference.

We also welcome Luc Lefebvre, chair and co-founder of Crypto Québec; as well as Philippe Dufresne and Marc Chénier, from the Offices of the Information and Privacy Commissioners of Canada. I want to welcome each and every one of you back. You will each have the floor for five minutes for your presentations. Mr. Marcel‑Olivier Nadeau, you have the floor.

Marcel-Olivier Nadeau (President, Barreau du Québec) :

Thank you, Mr. Chair. Members of the committee, thank you for having us here today. Allow me to introduce myself. My name is Marcel‑Olivier Nadeau, and I am the president of the Barreau du Québec. I am accompanied by Michel Marchand, a member of the Criminal Law Experts Group, and Nicolas Le Grand Alary, a lawyer with the Secretariat of the Order and Legal Affairs of the Barreau. The Barreau du Québec thanks you for inviting us to take

part in the consultations on Bill C‑22 . Let us recall that the mission of the Barreau du Québec is to protect the public, to promote accessible justice and to defend the rule of law. It is in that capacity that we are speaking today. To begin, I would like to remind you of a fundamental principle. The concept of the rule of law is at the heart of our democracy. It requires that state powers be exercised, particularly in criminal investigations, within a framework, predictably and subject to independent judicial review.

It also requires that laws uphold the fundamental rights guaranteed by the Canadian Charter of Rights and Freedoms, including the right to privacy and protection against unreasonable search and seizure. This balance is not theoretical. It is essential to maintaining public trust in our institutions. The Barreau du Québec recognizes the legitimate objective of the bill, which is to modernize investigative tools in an ever-changing digital environment. We are nonetheless concerned about several provisions that could undermine fundamental rights, particularly when it comes to privacy and constitutional guarantees.

Our goal is therefore to improve the bill so that it achieves its objectives without compromising the principles central to the rule of law or provoking court challenges. Our recommendations focus on four main points. First, the definition of subscriber information is too broad. The bill provides a very broad definition that is likely to reveal sensitive personal information when combined with other data, such as a person's name, alias, address, phone number and email address.

The Supreme Court has also reminded us that the reasonable expectation of privacy must be analyzed in the current social and technological context, in which a massive quantity of data is collected, cross-referenced and retained. As a result, even isolated information can reveal a great deal when combined with other information. Furthermore, the lack of a clear definition of the term “person providing services to the public” increases the risks of the invasion of privacy, as it allows for broad

interpretation and potentially abusive applications. In the absence of legislative safeguards, this generic wording is likely to apply to a wide range of entities. That includes not only Internet service providers, but also companies and organizations with sensitive personal information. This wording also creates uncertainty for the entities concerned, which could be forced to pass on sensitive information without clearly knowing whether they are legally required to do so. We recommend clarifying and narrowing these

definitions to avoid overbreadth. Second, the bill sets out an insufficient legal threshold for obtaining production orders. Under the bill, certain orders could be authorized on the basis of “reasonable grounds to suspect”, which is a lower threshold than is generally required for infringements of fundamental rights. Let us not forget that the Supreme Court has established that subscriber information has a high level of constitutional protection, warranting rigorous judicial oversight.

In our opinion, by stipulating the lower standard of mere suspicion, which does not require probability but only a reasonable possibility that an offence has been or will be committed, the bill does not meet constitutional privacy requirements. We therefore propose that, as with other similar orders currently in the Criminal Code, the threshold of “reasonable grounds to believe” be considered. Third, there is a lack of judicial oversight in certain situations.

Indeed, in certain cases, the bill allows for voluntary disclosure of information without judicial authorization, which we consider a significant departure from traditional safeguards in criminal law. Let us not forget that even information that is considered “basic”, such as a subscriber's contact information or IP address, can, when linked to other elements, provide a detailed profile of the person in question. In this regard, the courts have found that it is imperative that the disclosure of this information be accompanied by procedural safeguards, including the requirement for prior judicial authorization.

We recommend removing these mechanisms or, at the very least, requiring prior judicial oversight in all cases.

(1550) Fourth, the protection of solicitor-client privilege and computer data is at risk. The bill makes useful changes for the review of computer data. We maintain, however, that there should be a requirement that the extraction of computer data must be carried out by a person whose only role in the investigation of the offence in question is precisely to extract that data. That would be an effective way to avoid contamination of the investigation and, at the same time, to preserve solicitor-client privilege, which is a principle of fundamental justice as defined in the Canadian Charter of Rights and Freedoms.

The Chair :

Mr. Nadeau, I'm going to have to ask you to speed things up.

Marcel-Olivier Nadeau :

I'm done, Mr. Chair. In conclusion, I would say that the Barreau du Québec invites legislators to review the bill in order to maintain a fair balance between the effectiveness of investigations and the protection of fundamental rights. We look forward to your questions. I'm sorry that I went a little bit over.

The Chair :

I'm sorry to have interrupted you. If you wish, you will probably have an opportunity later on to elaborate on the last point you mentioned quickly. Mr. Lefebvre, you have the floor for five minutes.

Luc Lefebvre (Chairman and Co-founder, Crypto Québec) :

Mr. Chair, members of the committee, I appear before you today on behalf of Crypto Québec. When I last appeared before this committee, as part of the consultations on Bill C‑8 , I concluded by saying that the Quebec model increased overall security by harmonizing security and privacy protections, and that the government should draw inspiration from this approach, which has already proven to be effective. [ English ] However, today we find ourselves faced with a bill that many information security professionals in the country and abroad, as well as several technology organizations, consider fairly dangerous.

These are organizations whose applications are used daily by a very large number of elected Canadian officials as well as law enforcement. I am notably thinking of Signal from the Signal Foundation, which is threatening to leave the country if this bill is passed, so as not to weaken the encryption of its application. In our opinion, this bill should be withdrawn and completely rethought. The basic premise of this bill is flawed. [ Translation ] Bill C‑22 is based on a premise that has never been rigorously publicly demonstrated, which is that encryption is the main threat to public safety in Canada today.

There is no evidence of that. We've heard anecdotes from certain police forces and intelligence agencies, but we've never seen any empirical, public evidence that encryption is the greatest threat to Canada's national security. On the contrary, it has been shown that the more data that is collected, the greater the risk of data leaks, without any real improvement in security. [ English ] To that effect, in the U.S., just a few years ago, it was demonstrated by The Washington Post that the FBI had massively overestimated the number of investigations allegedly blocked by encryption.

These figures were then used publicly to justify the expansion of surveillance powers. We should not repeat the same mistake in Canada. While we're being told about encryption being the problem, the actual public reports from the Canadian intelligence agencies, such as those from NSICOP, primarily tell us about foreign interference, deficient resources and the opaque expansion of the national security apparatus. The problem is thereby pretty clear. There's a lack of human, technical and financial resources as well as an excessive increase in data collection powers without any real oversight capacity.

Bill C-22 addresses none of that. [ Translation ] Encryption is not the heart of this crisis; it is the solution. Despite this, Bill C‑22 proposes nothing less than the creation of a permanent digital monitoring infrastructure. It would be an infrastructure in which service providers could be forced to keep more data, maintain technical access capabilities, respond to secret orders, and participate in extraction processes, even though the word “oversight” appears exactly zero times in the text of the bill. The bill also makes no specific reference to robust democratic checks and balances.

This is extremely concerning. A healthy democracy is founded on privacy, freedom of association, confidentiality of communications, and spaces where citizens can discuss and criticize power without fear of permanent structural monitoring. (1555) [ English ] To Albertans and Quebeckers alike, I say this.

No federal government should ever possess expanded structural surveillance capabilities in a context where major democratic and constitutional debates may one day oppose Ottawa and the provinces. [ Translation ] Canada's history reminds us that national security tools can sometimes extend beyond external threats and affect domestic political movements. That's precisely why stellar democratic guardrails are needed.

It is also important to note that if this bill passes in its current form, all the efforts made in terms of digital sovereignty in Quebec will become null and void. [ English ] Protecting democracy in Canada requires strong institutions that balance security and privacy with robust oversight, checks and balances. Bill C-22 , unfortunately, gives the impression that the main threat to Canada is becoming increasingly internal rather than external. We all know this is a slippery slope for a liberal democracy.

In closing, we believe that the Canadian Parliament should not adopt such a fundamentally transformative bill based on unfounded assumptions, fears or premises that have not been publicly demonstrated. There is no back door that is only used by the good guys. The history of cybersecurity shows us precisely the opposite. [ Translation ] Since the likelihood of potential abuses and their effects are too great, we are calling for Bill C‑22 to be withdrawn in its entirety. Thank you.

The Chair :

Thank you, Mr. Lefebvre. Mr. Dufresne, you have the floor for five minutes.

Philippe Dufresne (Privacy Commissioner of Canada, Offices of the Information and Privacy Commissioners of Canada) :

Thank you, Mr. Chair. Members of the committee, thank you for inviting me to share my views on Bill C‑22 . Last week, I made a written submission to the committee, which I will address in greater detail today. Bill C‑22 reintroduces lawful access provisions that were originally proposed in Bill C‑2 , but with several changes that reflect feedback the government received. Some of these changes are consistent with written recommendations on Bill C‑2 that I submitted to the Minister of Public Safety last November. [ English ] Bill C-22 improves on its predecessor, Bill C-2 , in several respects.

In particular, I welcome the more narrowly tailored confirmation of service demand. I appreciate the addition of potential privacy and cybersecurity impacts as factors that must be considered in the making of regulations and orders under the supporting authorized access to information act, the SAAIA. I'm also pleased to see the act's new oversight role for the intelligence commissioner with respect to ministerial orders.

That being said, in my written brief to this committee, I've highlighted some aspects of Bill C-22 that would warrant, in my view, further amendments to strengthen and ensure privacy protections for Canadians. Specifically, I recommend narrowing the definition of “subscriber information” to a closed list of discrete identifiers, such as a subscriber's name, address, telephone number and IP address. This would help to avoid capturing information that could attract a heightened expectation of privacy.

I also recommend restricting the range of persons or entities who could be compelled to produce subscriber information to telecommunications service providers, and ensuring that the justice or judge making the order can specify the subscriber information that must be produced. [ Translation ] In addition, I recommend defining “publicly available information” to exclude information in respect of which an individual has a reasonable expectation of privacy, as defined in the Communications Security Establishment Act.

The concept of so-called publicly available information continues to evolve, and an individual does not automatically waive any reasonable expectation of privacy for information that may be available online. Take, for example, a situation where an individual's information was disclosed as a result of a data breach or published without their knowledge or consent. [ English ] Another recommended amendment would be to add an overarching requirement that obligations imposed under the SAAIA be limited to what is necessary and proportionate.

This would help to ensure that any such obligations, including with respect to the retention of metadata, are tailored to minimize privacy impacts. On the issue of accessing information, I would recommend amending the definition of “systemic vulnerability” to clarify that it includes any action that would render systemic methods of authentication or encryption less effective, as in Australia's analogous law.

In addition, I recommend specifying that regulations and orders must not have the effect of requiring an electronic service provider to introduce, or of preventing an electronic service provider from rectifying, a systemic vulnerability. (1600) [ Translation ] Finally, I recommend adding an exemption to the confidentiality rules set out in the supporting Access to Information Act which would expressly authorize electronic service providers to share information with appropriate regulators, such as the Office of the Privacy Commissioner of Canada, to enable them to properly exercise their powers and duties.

Thank you for your attention. I look forward to your questions.

The Chair :

Thank you to all three of you for your presentations. Mr. Caputo, you have the floor for six minutes.

Frank Caputo (Kamloops—Thompson—Nicola, CPC) :

Thank you, Mr. Chair. Thank you to our witnesses. [ English ] I'm going to start with Commissioner Dufresne. Thank you for being here again. Can you please tell this committee how you were consulted on the drafting of this bill?

Philippe Dufresne :

We were consulted by the Minister of Public Safety following Bill C-2 . We made some recommendations to the minister. My staff met with staff from the minister's office. We had the opportunity to provide feedback. Some of it was taken up; some of it was not.

Frank Caputo :

Am I correct in saying then that you, as the Privacy Commissioner, were not consulted on what should be in a bill that touches on so many people's online privacy?

Philippe Dufresne :

As I said, we had an exchange. We were consulted post-Bill C-2 on what the next version should be. I would not say that we were not consulted in this instance. We made a number of recommendations. A number of them were taken and I've highlighted those improvements, but there remain many that were not: necessity and proportionality, safeguarding, the narrowing of the definition.... There remain privacy concerns, hence my submission to this committee.

Frank Caputo :

I'm not sure if you've been watching this committee process, Commissioner Dufresne. One of the chief issues I have here is how quickly we are moving. How many eminent witnesses do we have here? We have six very qualified witnesses representing three parties. This really should be divided up into two panels, in my view. I won't get to ask half the questions. Can you comment? Does it feel to you like this has been a bit too rushed? You gave us five or six substantive amendments here. We're not even going to be able to ask you about a lot of them because we're quite short on time, without even getting to other valid points. From your observation, has this been rushed?

Philippe Dufresne :

The committee is the master of its proceedings, but I did send a written brief last week, knowing that there was less time. We've made attempts to make it user-friendly and clear as to what our expectations are. We have eight specific recommendations to improve the bill from a privacy standpoint.

Frank Caputo :

I'm mindful of that. I know you really can't weigh in. Mr. Lefebvre, you have been observing this. Does this not feel rushed to you? It feels quite rushed to me.

Luc Lefebvre :

Absolutely, it feels pretty rushed, particularly knowing that this is a bill that has an impact on every Canadian. You know what they say. With extraordinary power comes extraordinary responsibility. I have the impression that they are asking for extraordinary power, but we don't know why. It seems that it has not been profoundly thought through, because it has many implications for everyone. We understand that this comes from a place of need and requirements from law enforcement and our intelligence agencies, but the impacts are so great that it needs to be discussed further.

Frank Caputo :

I would agree with you. No one is doubting that we want to catch bad people, like terrorists, and—as in my prior life—catch people who abuse kids. There's no doubt about it. You also hit the nail on the head. Not only has this been rushed, but the communications from the government have been awful, if I'm going to be candid about this. The minister would not declare whether he would be open to an amendment on encryption, which is something that you highlighted. I don't know why we're using cute phrases like “encryption-neutral”. We don't know any of that.

Amendments have to be in tomorrow, yet we're hearing from officials on Thursday. We've had one hour from officials. From your standpoint, can you see why it would be prudent to actually study this bill further?

(1605) Luc Lefebvre :

Like I said before, the implications are grand. Every country that went that way, because there are other countries in the Five Eyes that went that way.... When I think of Australia and the United Kingdom, they took the time to think about it. They went a different way from what I wish they would have gone, but they took more time. This matter affects businesses. It affects every citizen, and it affects every part of everyday life. It needs to be more thought through.

Frank Caputo :

I understand. I'm sorry, but I have to cut my time short with you because I'm down to about 45 seconds. Mr. Nadeau, one of the things you talked about was oversight and people getting caught. Right now, the intelligence commissioner has to approve or sign off on a ministerial order. What would you say to an amendment that would require judicial oversight? In other words, rather than the intelligence commissioner, having the Federal Court of Canada.... Rather than having to go through judicial review as an extra step, it would go to the Federal Court of Canada in order to approve a ministerial order.

[ Translation ]

Marcel-Olivier Nadeau :

Thank you for your question, sir. I will let our expert, Mr. Marchand, answer.

Michel Marchand (Member, Criminal Law Expert Group, Barreau du Québec) :

Hello. That's a broad question and one that is difficult to answer. We'll have to see what the content of the ministerial order is. It's hard to answer the question without knowing all the parameters.

The Chair :

Thank you for that brief answer. In any case, we've gone over the six minutes allotted for this round. Ms. Acan, you have the floor for six minutes.

Sima Acan (Oakville West, Lib.) :

Thank you, Mr. Chair. [ English ] Monsieur Dufresne, the scope of this legislation is to provide basic information on an individual, not the content of their data, not what they browse and not what is in their emails. The department has taken the time to carefully consider privacy concerns and charter considerations. However, we have heard concerns that the current wording in proposed

section 487.011 could capture services outside Internet service providers, worded as “who provides services to the public”. As the Privacy Commissioner, what language changes would you suggest to narrow the scope of services captured in proposed

section 487.011 so that these concerns are addressed, while ensuring law enforcement have tools to access the information they need?

Philippe Dufresne :

Absolutely, it's important that this bill balance the need for police forces to have the tools they need with protecting Canadians' privacy, and we can do that. It's not a zero-sum game between privacy and security. We address this in our written brief in our first three recommendations. Specifically, the first thing that should be done is to narrow the definition of “subscriber information”.

Change it from what it is here, which includes broader concepts like “information that may be used to identify” individuals or “information relating to the services”, and narrow that to specific items such as the name, address, telephone number and email address. We specify that in our brief. The second thing is to restrict the scope of who can get those orders to telecommunications service providers. That's already there for the warrantless requests on confirmation of service demand, but in terms of the subscriber information, it's open to “a person who provides services”. That in our view is too broad.

It could capture medical offices and law offices, and capture any amount of sensitive information. The last element is that you should provide more specificity in terms of what the judge's order will be. Right now, it says “any subscriber information” and “all the subscriber information” related to something, and that could be broad. We're suggesting a narrowing of that language. I'll flag the last element in terms of the non-warrant search or confirmation of service demand. There's an exception for medical and privileged information, and that exception is also absent in terms of the subscriber information.

Those are the recommendations I would make.

Sima Acan :

Thank you very much, Mr. Dufresne. To continue, we also had the privilege of hearing from the National Security and Intelligence Review Agency and the intelligence commissioner, who holds our national security regime accountable. In contrast, as the Privacy Commissioner, you play an important role to ensure federal departments and agencies adhere to personal information-handling practices. What would you recommend to be added in relation to ministerial orders that will take this legislation to the next step?

(1610) Philippe Dufresne :

I welcome the addition of the intelligence commissioner review role. That is an important improvement that was made, and I fully support it. I think the addition of necessity and proportionality to the scope of orders that could be made by the Governor in Council and by the minister is critical. That's a concept in privacy law that's shared around the world. In fact, the signatories to the OECD's December 2022 declaration on government access to private sector information unanimously and expressly called for “necessity” and “proportionality”. It's very important.

I believe Intelligence Commissioner Noël also talked about the notion of reasonableness and proportionality. That is a very important standard. There's some language in the legislation that calls for a consideration of privacy impacts. That's a good thing, but it needs to go further, in my view, to be necessary and proportional.

Sima Acan :

Thank you, Mr. Dufresne. Monsieur Nadeau, from my understanding, you would like a tighter definition of “subscriber information”. Currently in

part 1 of the bill, a confirmation of service demand asks a simple yes-or-no question to determine if an individual uses the service. In addition, the definition of “subscriber information” in proposed

section 487.011 focuses on identifiers—in other words, basic information. It's not the content of the data, such as what you browse or what's in your email. Could you explain what you would like to see added to proposed

section 487.011 to narrow the definition and the scope?

[ Translation ]

Marcel-Olivier Nadeau :

Thank you for your question. I think the commissioner gave some great examples just now. I don't have any more to add, but I will let Mr. Marchand or Mr. Le Grand Alary provide you with other examples, if they have any. The ones that were just given by the Privacy Commissioner are excellent, and I would adopt them, as well as the principles he set out.

[ English ]

Sima Acan :

Thank you very much.

[ Translation ]

Nicolas Le Grand Alary (Lawyer, Secretariat of the Order and Legal Affairs, Barreau du Québec) :

Thank you, Mr. Nadeau. I was actually going to add one point. I think the commissioner did a good job of explaining the concerns. There's the concept of subscriber information and also the court order. All of these elements are problematic; it's the whole thing. The three

definitions need to be tightened up. I think the commissioner did a good job of explaining the issue.

[ English ]

Sima Acan :

Thank you very much, Mr. Chair. My time is up.

[ Translation ]

The Chair :

Thank you very much, Ms. Acan. Mr. Lloyd, please go ahead for six minutes. I'm sorry, it's your turn, Mrs. DeBellefeuille. My humble apologies. It's impossible to forget you, but I still managed to do so. You have the floor for six minutes.

Claude DeBellefeuille (Beauharnois—Salaberry—Soulanges—Huntingdon, BQ) :

Thank you, Mr. Chair. Let me start by saying how disappointed I am to have so little speaking time with such a rich panel of witnesses. Since time is limited, I will try to keep my questions short, so you can provide clear answers. Personally, the more I learn, the more confused I am. The views on the bill are vastly divergent and very polarized, depending on whether we're speaking to a police officer or a privacy advocate. My goal is to tell stakeholders that, yes, this is an important and necessary bill, but also to figure out what that balance is going to look like. Mr.

Dufresne, I'm always surprised that your recommendations aren't heeded before a bill is drafted. We're always a bit behind. We went through that with Bill C‑8 . No one bothered to consult you. Now you're here with your recommendations, and opposition parties are the ones proposing them as amendments to the bill. I find that strange, especially since we have so little time to debate them. We would have preferred that the government do its job, listen to you and include your seemingly reasonable recommendations in the bill. It would have made for a better bill and saved us time. Mr.

Lefebvre, you got my attention when you said a lawful access regime had not been shown to lead to a decrease in crime in the U.S. There is no evidence of that. Weaker encryption doesn't necessarily equal less crime. Here's what police tell us: They'll be more effective, they'll stop more criminals and they'll be able to combat organized crime. You seem to be telling us it's not that straightforward. Can you give us more information on that?

(1615) Luc Lefebvre :

The tendency to try to control what we call lawful access in Five Eyes countries goes back 10 or 15 years. Australia's and the United Kingdom's laws are particularly robust when it comes to collecting data for the stated purpose of combatting pedocriminality, going after criminals and such. To date, however, there is no evidence that crime decreases when law enforcement has greater access and more say over the level of encryption of applications, messaging platforms and other tools. Those broader powers have not been shown to lead to a decrease.

At the end of the day, more information is being collected, but crime isn't going down. That's all this is doing. What we actually see with the broadening of powers is that criminals tend to go dark. They use other methods, other tools, and the trail ends up going cold anyway. Nevertheless, more and more data are being collected on ordinary people—people who aren't involved in these activities.

Claude DeBellefeuille :

Let's look at models we want to draw on, the U.K.'s, for instance, or New Zealand's or Australia's. The U.K. even installed cameras that record citizens as they go about their everyday lives. It's taken surveillance to the extreme. Has it been shown to bring the crime rate down?

Luc Lefebvre :

That correlation hasn't been made. The U.K. is known for its widespread use of closed-circuit TV, or CCTV, monitoring. In addition, the U.K. has passed very robust laws on data collection and freedom of expression. A correlation between that and a significant reduction in crime hasn't been shown, but that was the official excuse that was given.

Claude DeBellefeuille :

I attended an event put on by the Canadian Association of Chiefs of Police, and there was a lot of excitement in that room. People said they'd been waiting 30 years for legislation like this. Why do you think the government is in such a rush to pass this bill? Are there any countries pushing us in that direction?

Luc Lefebvre :

I would say two things to that. First, it makes sense that police services would welcome this legislation. I come from a family of police officers who were involved in fighting pedocriminality and the like. I completely understand the excitement, and it's necessary. It's no surprise that police forces are pleased about this. It's perfectly commendable. Second, my sense is that the pressure is coming mainly from members of the Five Eyes group, which is looking for more and more visibility across the network, as well as from allies.

Canada is indeed lagging behind when it comes to being able to provide access to those data. There's clearly some political pressure to do that. It's probably the easiest solution for the government to say that it's going to bypass encryption to give police forces access to Canadians' data. Police will be happy. It's easier than allocating more financial, technical and human resources to fighting crime. At the same time, it will make our allies happy. That's the impression I have.

Claude DeBellefeuille :

Mr. Dufresne, as you know, the deadline for us to submit our amendments is 5 p.m. tomorrow. Are your recommendations already in amendment form, so we can use them and submit them as is?

Philippe Dufresne :

They aren't drafted how the Office of the Law Clerk would draft them, but I don't think it should be too difficult to turn them into amendments, given how we've laid them out in our brief. We refer to existing regimes, such as Australia's law, which stipulates that orders must not have the effect of rendering encryption less effective. That amendment is in there. One of the provisions in the bill we're concerned about says that the provider is not required to comply with an order. We feel it's important to state that the order shouldn't be made at all. It puts the provider in a tough spot.

They are being ordered to do something but are allowed to disobey the order under the law. I think things should be done right from the start. We addressed necessity and proportionality, referring to Great Britain, which takes those factors into account. Australia does too. They are core principles, so it's not hard. They can be added to the factors the minister or Governor in Council has to take into account. The eight recommendations we've made are targeted and concise. Essentially, they're intended to achieve that critical balance.

(1620) Claude DeBellefeuille :

Thank you very much, gentlemen.

The Chair :

Thank you, Mrs. DeBellefeuille.

[ English ]

Dane Lloyd (Parkland, CPC) :

I have a point of order.

The Chair :

Go ahead, MP Lloyd.

Dane Lloyd :

Thank you, Mr. Chair. I wanted to wait until my colleague Madame DeBellefeuille was finished. I heard the Privacy Commissioner tell us about a submission he made to this committee. I believe the submission was sent to the chair on May 21. We had not received that submission until just now. I'm not trying to attribute malice to anyone, but my ability, as a parliamentarian, to scrutinize this legislation and be prepared for today's meeting was really impacted. By not receiving documents sent in by witnesses, I have no ability to properly review them.

As an aside on another point, we still don't have the transcript from our meeting two weeks ago. I just raised this with our clerk, who assures me that it's coming. You know, we had a two-week break. If we're not able to get critical information to help us do this, given the rushed nature of this legislation we're sending through.... I have very serious reservations about how quickly this process is going, as we're not being given adequate information and evidence to get this bill done.

The Chair :

Thank you. That is not exactly a point of order. It's more like a point of privilege, but I think we understand the value of it. The clerk just informed me a couple of minutes ago that for reasons that are human, he wasn't able to send it earlier. He wants to express his discomfort with that. Now he has received it, so I encourage everyone to look at your emails. The full document was just shared. On the transcript, maybe I should know a bit more about what the clerk has to provide as a matter of precision. Mr. Clerk.

The Clerk of the Committee (Paul Cardegna) :

Thank you, Mr. Chair. With regard to the transcript, we have been informed that the publications department of the House of Commons has set service standards. I can look into those service standards and get back to the committee, as I don't have them with me right now. However, they wrote to me on Friday indicating that there have been some delays, notwithstanding the length of the meeting on May 7, which was four hours instead of two, and the large volume coming through their office as well. They've indicated that they are working as hard as they can to get that transcript out.

I can send the blues to you right now, Mr. Lloyd, and I will do that. The blues are usually available within the firewall. If any member cannot access them, we can send copies to them. With regard to the document from the Privacy Commissioner, that mistake was entirely mine. I do apologize to the committee. Unfortunately, it slipped through my fingers and I did not get it out in as timely a fashion as I would have preferred. I beg the committee's indulgence on that. You have my apologies. Thank you.

The Chair :

MP Lloyd, go ahead, and then we'll go to to MP Caputo.

Dane Lloyd :

Maybe I'll cede the floor to Mr. Caputo.

Frank Caputo :

Chair, I'm fine with MP Lloyd going first. He has a train of thought.

Dane Lloyd :

Thank you. I really do appreciate the explanation from the clerk. We know that accidents like this happen. I was told that we could access the blues within the firewall on our devices. I have my House of Commons phone here. I just looked, and the blues are not available on my House of Commons phone.

You know, despite the fact that this does look like it was an honest mistake, given the gravity of the legislation we have before us, I feel that I've been really disadvantaged and that my privilege has been violated by not being able to have the correct information available to me in order to participate in the session. I'm looking for some guidance from the chair. I believe my privilege has been violated here.

The Chair :

Thank you. I'll take that into consideration and work with the clerk—not now but immediately after this meeting—to see, with everyone else's input, what we can do to facilitate the important work that needs to be done in such a short amount of time. Everyone, please note that you now have the document shared earlier by the commissioner. We can use that with our teams to move forward. Again, I'll come back to this aspect of the breach of privilege, which you correctly stated. Having said that, MP Caputo, would you like to say something before we turn to MP Lloyd for his five minutes?

(1625) Frank Caputo :

Yes. I'll intervene just briefly. Given what Mr. Lloyd has reflected on, that his privilege has been breached, and not even as a prima facie breach but as an obvious breach, I would ask, Mr. Chair, if you and the clerk would be able to canvass the Privacy Commissioner's ability to return next week and, in any event, prior to clause-by-clause consideration. I also think the appropriate remedy here is that we do not have amendments close tomorrow. I think it's very obvious that this is the only remedy in what is already a very rushed process.

I think this is symptomatic of the fact that we have been moving very quickly. I do not place any blame on the clerk. These things happen. Mistakes happen. We've had four-hour meetings. We're in the midst of another four-hour meeting. I won't say any more. Thank you.

The Chair :

On that, first, we have important work to do now, so I suggest we do it now. Second, as I said, I will review the matter of the breach of privilege raised by MP Lloyd, and third, thereafter, we will work together—I'll work with you in particular, MP Caputo—to see how the suggestion of changing the

schedule for consideration of this bill may be accepted by other members of the committee.

Frank Caputo :

I am concerned, actually, Mr. Chair. This is something I'm thinking about contemporaneously here. Does a question of privilege not need to be dealt with now, at the first possible instance? I would ask that you please consult with the clerk if we need to suspend. It is important that we get this done right, not that we get this done quickly.

The Chair :

Questions of privilege don't have to be decided now by the chair. I can ask for the indulgence of the committee to reflect on that—with the assistance of the clerk, obviously, and others—after the meeting to see how we proceed there. If it were a point of order, it would be different. This is a question of privilege, and I can take it into consideration after this meeting. I would advise the committee that we do this and take advantage of the witnesses who are now present to push forward the analysis of the bill under consideration. Having said that, would you like to start your five-minute intervention, MP Lloyd?

Dane Lloyd :

Just as soon as I.... Oh, I'm sorry.

[ Translation ]

The Chair :

Go ahead, Mrs. DeBellefeuille.

Claude DeBellefeuille :

Mr. Chair, I want to echo the important point Mr. Lloyd made. I was waiting for that brief to prepare amendments. I'm always shocked at the fact that the Privacy Commissioner of Canada's recommendations are never taken into account before measures are drafted. I was eagerly waiting for the brief, because I knew what a tight deadline we had. I think the point of privilege is relevant. I think it's really important to look at how you're going to proceed. We want to feel that we're able to submit those recommendations and that the commissioner's comments have been taken into account.

The Chair :

As I said a moment ago, I will consider the matter. The information should have been available a while ago. It's available now. It's a four-page document. As the commissioner himself said, the recommendations are well laid out. They are clear and should be fairly easy for committee members to understand. That said, I suggest we resume the discussion with the witnesses we have today. I can give you the various experts' opinions and recommendations, including the clerk's, after the meeting. I hope that's okay with you, Mr. Lloyd. We need to keep going. Otherwise, things will have wait until the next meeting.

[ English ]

Dane Lloyd :

Thank you to the witnesses. Commissioner Dufresne, we had another witness here today who said that he believes the reasonable suspicion threshold for subscriber data is too low. Do you have thoughts on that, or is that outside your scope?

Philippe Dufresne :

I would think it's too low with the current framing of the scope of subscriber information: the definition and the parties that can receive it. My recommendation is to fix the scope. If you fix the scope, I think you can keep the suspicion, but if you don't, that would be the alternative.

Dane Lloyd :

Okay. Thank you for that. You're giving us multiple options here. What are your thoughts about the non-disclosure rules? If an authority goes to an electronic service provider for a subscriber request, they can place a non-disclosure so that the provider can't tell the subject of that request that there's been a disclosure. What are your thoughts on that?

(1630) Philippe Dufresne :

There could be some valid reasons for that confidentiality. There are improvements in the bill in terms of reports from the minister to Parliament and so on. One of the gaps I'm identifying in my eight recommendations is that the confidentiality would prevent the provider from notifying my office if there's a breach and if there's relevant information in a ministerial order. That is, in my view, a gap that should be addressed, because it prevents us from doing our work.

Dane Lloyd :

Would it be fair to say that your recommendation is that any time an authority asks for subscriber information your office be notified?

Philippe Dufresne :

Not necessarily, but I would not want to have the confidentiality provision prevent sharing of information where it's appropriate: with my office, for instance, in a privacy breach. That's the most obvious situation. When we're dealing with this issue of subscriber information and the encryption, the safeguarding of information is absolutely key.

Dane Lloyd :

Yes. I think there are cases where non-disclosure is absolutely necessary: for example, active investigations. Do you think adding judicial authorization when seeking a non-disclosure order would be an appropriate way to strengthen?

Philippe Dufresne :

It strengthens it from a privacy standpoint. You would have to weigh that with the impact on the police work. This is not one of my priority eight recommendations that I've made, but it's a consideration.

Dane Lloyd :

It's a trade-off.

Philippe Dufresne :

I suspect it would create some delays.

Dane Lloyd :

Okay. Thank you. Now, about metadata, there's been a lot of talk about a requirement to hold metadata for a year. You talked about “necessary and proportional”. Is it necessary and proportional to hold the metadata of all Canadians for up to a year?

Philippe Dufresne :

I think that condition of necessity and proportionality has to be there whenever you exercise that power, whether it's cabinet in terms of the orders or whether it's the minister. With that framing, you're going to deal with it on a case-by-case situation. There may be situations where it's so severe and it's so significant that there may be some reasons. That would be for the government to provide that or for the police to provide that. I don't want to prejudge it. Without that framing, then, you risk having the orders being too long and too broad. This is why necessity and proportionality are such a key part of privacy law.

Dane Lloyd :

Are you concerned about the privacy implications of companies being mandated to hold on to Canadians' metadata for a year?

Philippe Dufresne :

The longer you keep information, the more there's a risk in terms of a privacy breach and the more there is an impact if there's a privacy breach. One of the principles we put forward is to not retain information longer than is necessary. Again, that's why necessity and proportionality are so important. There will be cases where you need to keep it longer, but that should be tested in every case.

Dane Lloyd :

We've heard of systemic vulnerability. The government has said that it will not introduce systemic vulnerabilities. However, it looks like, under the ministerial orders, it could very well order companies to install things that could create vulnerabilities. What are your thoughts on that?

Philippe Dufresne :

I know that there have been debates on this. The bill now has a definition of “systemic vulnerability”. I think I heard government officials say that it is not their intention to diminish this. What I'm proposing is to make that clear in the legislation. We have a model for that in Australia, where it—

Dane Lloyd :

I'm sorry. With my final bit of time, Mr. Lefebvre, I heard from a constituent who came to my office last week. He's concerned that if we create potential back doors, which could definitely be done under this legislation—maybe not right away—damaging information about people could be fabricated and added to their accounts to make them look like they're guilty. Is this a tactic that extortionists use? Could they exploit encryption breakthroughs to do this?

Luc Lefebvre :

If there's a back door, it can basically be used by anybody, even the people who are not supposed to use it. Obviously, once you have access to data, you can manipulate it in any way. It's obviously something that I would say bad actors, criminals or adversaries could use to fabricate some claim about somebody.

[ Translation ]

The Chair :

Thank you, Mr. Lloyd. We now go to Mr. Ramsay for five minutes.

Jacques Ramsay (La Prairie—Atateken, Lib.) :

Mr. Lefebvre, are metadata encrypted?

Luc Lefebvre :

It depends. Some—

Jacques Ramsay :

I don't think so.

Luc Lefebvre :

Actually, some metadata are encrypted, depending on the system. Signal is a great example. On Signal, the metadata are encrypted. Data that aren't encrypted include the account creation date and the last date of a user's connectivity. However, once a user is connected to Signal and in their account, there's no way to know who a user is communicating with, when or what the content of their discussions is, as opposed to email. With an email application, certain data are available: who communicated with who and when, what server the email was sent on, what the subject of the email was.

The content of the message isn't necessarily available, but those metadata are. It all depends on the type of system, on the type of encryption the application uses. In this case, the purpose is to access data that weren't previously available, such as in Signal, by reducing the level of encryption.

(1635) Jacques Ramsay :

Okay. I accept your definition, Mr. Lefebvre. Signal stands out because of the secrecy around its metadata. Unless I'm mistaken, messages are encrypted most of the time, and the government made clear that it didn't want any information in the messages. We are talking about dates, locations and other such data. That isn't encrypted information. The government isn't on a mission to decrypt people's communications. Mr. Dufresne, you say that the government is there to go after the bad guys. We aren't there to look at information about people's health. We aren't there for that.

Given that we and our colleagues opposite didn't see your report, can you tell us your main recommendation to ensure that the legislation captures only information relating to criminal activity?

Philippe Dufresne :

I would say recommendations 1, 2 and 3 in the brief. The purpose is to limit the type of information that can be obtained. I think that's what the government is trying to do, so specifying the information in question will reassure those who are concerned. The idea is also to limit the types of persons and entities subject to these orders. As it stands, the production order applies to any person who provides services to the public. That's a broad range of people, so it would be possible to obtain people's medical information, for instance.

I think it should be limited to telecommunications service providers, as in the earlier provisions relating to non-warrant requests. I think that would restrict access to only the information the bill is really trying to capture.

Jacques Ramsay :

All right. Thank you. Now I'd like the Quebec bar association representatives to help me out. I'm not a lawyer, but the lawyers you represent include prosecutors. Isn't that right?

Marcel-Olivier Nadeau :

I wouldn't say we represent them, Mr. Ramsay, but they are indeed members.

Jacques Ramsay :

They have to be, since they pay dues.

Marcel-Olivier Nadeau :

Absolutely.

Jacques Ramsay :

Did you consult them when you were preparing your brief?

Marcel-Olivier Nadeau :

Yes. We consulted a panel of criminal law experts. Half the members are criminal lawyers, and the other half are prosecutors.

Jacques Ramsay :

All right. You talked about the threshold and the difference between “reasonable grounds to suspect” and “reasonable grounds to believe”. Obviously, no one is against virtue. Everyone would prefer a higher threshold. The premise of the government, however, is that the information being sought, in other words, metadata, isn't evidence that can be presented to the court. It's information that will help further an investigation, to obtain evidence that can ultimately be used in court. That is why the government used the “reasonable grounds to suspect” threshold instead of “reasonable grounds to believe”. It is an accepted, recognized and well-known legal standard, after all.

Marcel-Olivier Nadeau :

I'm going to let Mr. Marchand speak to that.

Michel Marchand :

In our view, suspicion is too low of a threshold. In Bykovets, the Supreme Court points out how much providing access to an individual's IP address violates their privacy. Obtaining an IP address provides access to everything. The way the bill is currently worded, with reasonable grounds to suspect as the threshold for a confirmation-of-service demand, the purpose is merely to obtain information that will assist in the investigation. The reason for the demand is not that the suspect may have committed an offence. It's that the information will assist in the investigation.

The authoritative decision on reasonable suspicion establishes that this standard captures a lot of people who are not involved. It was therefore—

(1640) Jacques Ramsay :

The second condition is precisely why the information will assist in the investigation and—

The Chair :

Sorry to cut you off—

Jacques Ramsay :

I don't agree with you that this provides access to everything. That's not true.

The Chair :

Sorry to cut you off, Mr. Ramsay, but we have to move on to Mrs.—

[ English ]

Frank Caputo :

I have a point of order, please. For a moment there, I thought it was me and the minister with Mr. Ramsay and our witness, but my point of order has to do with Mr. Lloyd's issue of privilege. I've spoken with the clerk. I would ask that the clerk confirm on the record and that you, Mr. Chair, confirm on the record that you did not see the submission from the Privacy Commissioner, and that the clerk, to the best of his knowledge, did not forward it to you. Is it accurate, Mr. Chair, that you did not see the submission from the Privacy Commissioner?

The Chair :

I appreciate your question, MP Caputo. As I said earlier, this matter of privilege deserves appropriate attention. My attention now is focused on having the witnesses provide the most from their time and their input. If you allow, I will look at this after the meeting and consider this question of privilege in the appropriate manner.

Frank Caputo :

With the greatest of respect, Mr. Chair, we have to decide how we are going to proceed. If you did not receive this or did receive this, that does impact things. All I'm asking of you, Mr. Chair, is for a yes or no on whether you had seen the submission from the Privacy Commissioner.

The Chair :

My understanding is that I did not see this email, but I want to double-check that and be certain that I provide the members of this committee with the most accurate information.

Frank Caputo :

Thank you.

The Chair :

Having said that, we'll go to Madame DeBellefeuille. [ Translation ] Mrs. DeBellefeuille, you may go ahead for two and a half minutes.

Claude DeBellefeuille :

Thank you, Mr. Chair. Mr. Nadeau, my questions are along the same lines as the parliamentary secretary's, so I'm going to continue the discussion with Mr. Marchand. Basically, if I understand correctly, the “reasonable grounds to suspect” threshold in Bill C‑22 applies to specific data that aren't considered sensitive. You are arguing the opposite. The Minister of Justice , the justice department and department officials are saying this respects the Supreme Court's decision, but you don't seem to agree. Can you elaborate on why you think that, to help us really understand your point?

Michel Marchand :

We don't think it respects the Supreme Court's decision at all. Proposed new

section 487.0142 of the Criminal Code is very broad, referring to “all the subscriber information…including transmission data”. That can all be captured through the IP address. Furthermore, if you read the Supreme Court's decision in Bykovets—which isn't that old—properly and carefully, you see that the majority of the court viewed the IP address as a gateway. Search and seizure doesn't work the same way anymore. Before, when police officers did a search, they showed up at the individual's home and either they found something or they didn't.

Now, with the IP address, they can access just about anything about the person, medical records, what they dream about, what they post online and all kinds of other information. On top of that, the bill says that the information can be retained for a year, which is like giving authorities access to a huge data bank they can use to spy on people or find whatever information they want.

Claude DeBellefeuille :

Thank you, Mr. Marchand. I think I understand your point now. You're part of an expert group at the Quebec bar association. If a skeptical person shared that view with us, we might not believe them, but you're a very credible source, as far as I'm concerned. I'm trying to figure out how we can make the bill better. You're recommending that we remove the “reasonable grounds to suspect” threshold. The commissioner recommends limiting its use. That's what I understood from your recommendations, Mr. Dufresne.

Philippe Dufresne :

Exactly. You have both options.

Claude DeBellefeuille :

To wrap up, I'd like to thank you.

The Chair :

Mrs. DeBellefeuille, you're out of time, so I have to stop you there, I'm afraid.

Claude DeBellefeuille :

Thank you. You see how polite he is with me.

The Chair :

It saddens me to hear you say such harsh words. I thank all the witnesses for taking the time to prepare for the meeting and for travelling here or participating via video conference. We won't have much opportunity to bid you a warm farewell after you leave, because we must begin the second part of the meeting. So, we invite you to have a good rest of your day. Thank you.

(1645) The Chair :

Good morning, everyone. We are beginning the second part of this meeting with new witnesses, whom I would like to welcome. We are joined by Erik Neuenschwander, senior director of User Privacy and Child Safety, from Apple. From the Canadian Civil Liberties Association, we are joined by Tamir Israel, director of the Privacy, Surveillance, and Technology Program. He is participating in the meeting via video conference. From Google, we have Katherine Charlet, senior director, and Jeanette Patell, director of Government Affairs and Public Policy, both participating via video conference. We will now begin the five-minute presentations. Mr. Neuenschwander, you have the floor.

(1650) [ English ]

Erik Neuenschwander (Senior Director, User Privacy and Child Safety, Apple Inc.) :

Thank you. Good afternoon, Mr. Chair, vice-chairs and members of the committee. My name is Erik Neuenschwander, and I'm the senior director of user privacy and child safety at Apple, where I've been a software engineer for 19 years. I worked as the first data analysis engineer on the first iPhone, and I founded Apple's privacy engineering team. Today, my job is to make sure that Apple's products and services keep our users' information safe. Thank you for the opportunity to speak with you today.

As you know, this may be one of the last times we're permitted to discuss the consequences of this legislation publicly. That's because of the bill's secrecy provisions, which forbid companies like Apple from even discussing, with our users or the public, the orders we receive. Today, I want to be clear about how we approach privacy at Apple. I want to be clear about why encryption is so important to defending the privacy and security of people in Canada and around the world. These issues have never been more important because our world is becoming more digital by the day.

As users, we depend on our technology to securely store and process highly sensitive data like health metrics, photos and the locations of our loved ones. The places where we keep our money, store our files and conduct business are increasingly online and, sometimes, only online. The critical infrastructure we often take for granted, from the electric grid to transportation networks, is increasingly dependent on connected devices as well. However, as technology evolves, so do the bad actors trying to steal our data. Canada has witnessed this first-hand.

In 2023, Canada was one of the countries most frequently targeted by ransomware attacks. Just last year, malicious actors targeted Canadian telecom and other networks as part of the massive Salt Typhoon attack, not to just steal customer data but to also conduct broad espionage and to control the communications infrastructure that billions of people rely on every day. As a technology company, Apple is constantly working to anticipate and prevent these threats. As an engineer, I can tell you that end-to-end encryption is one of the most effective security technologies available to defend against them.

Encryption protects Canadians from identity theft, fraud, unlawful surveillance and data breaches. It protects critical infrastructure. It protects the data and communications Canadian businesses and government rely on, which are crucial to Canada's economic success and national security. Our users trust Apple with their most sensitive information. They expect and deserve the strongest protections. That's why we're so concerned about the threat to encryption posed by Bill C-22 .

As drafted, this bill allows the Government of Canada to force companies to break encryption by inserting back doors into their products, something Apple will never do. I want to be clear that we share the government's commitment to the safety and security of all Canadians. We have a team of dedicated professionals on call, 24 hours a day, to assist law enforcement. From 2020 to 2024 alone, we received just over 3,200 Canadian government requests for information, about 35% of which were emergency requests.

We're committed to supporting law enforcement's work to keep Canadians safe, and we're committed to encryption technology for the same reason, to keep Canadians safe. Again, speaking as an engineer, I do not know of a way to deploy encryption technology that provides access for only the good guys without creating new ways for the bad guys to break in. In other words, when you build a back door into an encrypted device, anyone can walk through, and because so much depends on encryption, we can't take that risk. Look no further than Salt Typhoon.

The United States passed a law requiring telecommunication companies to build access points for law enforcement into their systems, which state-sponsored actors then exploited. That law was narrower than Bill C-22 , so imagine what could happen if more companies were required to create these vulnerabilities. Apple has provided a written submission outlining targeted amendments that would improve the bill, which I'm happy to discuss. We urge the committee to adopt amendments that would, in particular, explicitly prohibit any requirement that would weaken, bypass or undermine end-to-end encryption.

We believe these changes would still expand lawful access and provide Canadian law enforcement with new tools to fight crime in the 21st century. Again, thank you for the opportunity to speak today, and I look forward to your questions.

(1655) The Chair :

Thank you very much. Let us turn now to Tamir Israel for five minutes, please.

Tamir Israel (Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association) :

Mr. Chair and honourable members of the committee, good afternoon. I thank you for inviting me to speak before you today on Bill C-22 ,

an act respecting lawful access.

Part 1 of Bill C-22 represents a meaningful improvement over its predecessor legislation; however, elements of

part 1 continue to suffer from overbreadth. These include the use of low standards for judicially authorized access to sensitive subscriber data and a framework that invites unconstitutional collection of publicly available data. Elements of

part 1 also allow Canada to adopt at least one, if not two, international information-sharing agreements, despite a growing tendency to use these tools for cross-border repression and an absence of comparable safeguards. CCLA is filing a joint brief with Kate Robertson and Cynthia Khoo from the Citizen Lab, which will elaborate on these and other problematic elements of Bill C-22 . I'll focus the remainder of my remarks this afternoon on

part 2 of the bill, which would enact the supporting authorized access to information sct, or SAAIA. At various points in time, governments have sought to expand their surveillance capabilities at the cost of cybersecurity, with encryption being a recurring target. Too frequently, these expansions have been justified by the expectation that surveillance capabilities will only be used by lawfully authorized government agencies and not malicious actors, yet time and again, this expectation has been proven false. The Salt Typhoon attack is the latest and perhaps the most potent reminder of this hard lesson.

It's also notable that the case for this legislation has not been made. Indeed, half of our Five Eyes partners have limited their surveillance capability regimes to imposing wiretapping obligations on telecommunications carriers. With a troubling historical track record in mind, SAAIA is fundamentally flawed in three interrelated ways. First, SAAIA is exceedingly broad. It applies to any provider of any service that has a digital component.

Under the Australian version of this law, everything from a fast-food chain that provides its customers' Wi-Fi to an electronics store that helps maintain customers' phones and computers, to any retailer that has a mobile phone application or online website, has been listed as an anticipated target. SAAIA is also broad in terms of what obligations the government can impose.

These range from requiring the ability to covertly reset customer passwords or requiring an automatic tool that generates realistic undercover profiles on social media platforms to requiring the ability to block a target's use of encrypted private messaging services in order to force them to use insecure alternatives. SAAIA's metadata retention mechanism is equally broad. Services can be required to retain a detailed record of every single person's movements, interpersonal interactions, what applications they use and more. This is highly sensitive data.

Second, stay of limitations and safeguards fails to constrain the multiple ways that privacy, encryption and other data protections might be compromised in light of the law's broad scope. SAAIA's systemic vulnerability limitation, for example, would not apply to a set of algorithmic monitoring tools referred to as client-side scanning. Because these tools bypass encryption rather than compromising it directly, they fall outside the systematic vulnerability limitation as drafted. They nonetheless create systematic vulnerability in practice.

Third, courts remain the primary vehicle for authorizing CSIS and police surveillance activities, but SAAIA does not rely on judicial authorization, despite authorizing powers that frequently rival their Criminal Code counterparts in breadth. For example, if police want to force a company to keep a specific customer's metadata for 90 days, they need a court order, but to force the same company to keep the same metadata on every single customer for up to one year, the government need only impose an obligation through SAAIA.

Judicial review is available and even required in some instances, but judicial review is highly deferential to government decision-making and no substitute for independent authorization, de novo review or full appeal rights. This is particularly the case when many of the obligations are imposed in secret, as is the case under SAAIA. In sum, SAAIA poses a significant threat to privacy and cybersecurity. It's unclear how SAAIA's many overlapping flaws can be remedied through the highly attenuated legislative study it's receiving.

Australia's technical capability regime was amended 173 times during a detailed committee study. Despite these changes, they were still held to be likely incompatible with human rights and a mandatory assessment of the legislation. We therefore urge you to recommend that the government advance Bill C-22 without

part 2. This legislation will be in place for years to come, and it's critically important that we get it right. The stakes are simply too high. Thank you. Those are my opening comments, and I invite your questions.

(1700) [ Translation ]

The Chair :

Thank you, Mr. Israel. I now give the floor to Ms. Jeanette Patell for five minutes.

[ English ]

Jeanette Patell (Director, Government Affairs and Public Policy, Canada, Google) :

Good afternoon, Mr. Chair, vice-chairs and honourable members of the committee. My name is Jeanette Patell, and I'm the director of government affairs and public policy for Google Canada. I'm joined today by Kate Charlet, a senior director on Google's public policy team, where she leads our work on cybersecurity, privacy and child safety. Before coming to Google, she spent a decade in national security roles at the Pentagon and White House. Google is committed to supporting the efforts of law enforcement in protecting the public against crime and terrorism.

We firmly believe that improving public safety and maintaining user security are highly compatible goals. As a global leader in building safe and secure products, we take the privacy and security of our users very seriously. Our business is built on the trust our users place in us to keep their data safe. Google products are private and secure by design, protected by multiple layers of security and leading technologies, such as encryption. I want to be unequivocally clear that Google has never built a back door or any other mechanism to circumvent end-to-end encryption in our products.

When we say a product is end-to-end encrypted, it is. In today's rapidly evolving threat environment, we believe it is critical to find ways to support law enforcement's important work without engineering vulnerabilities into products and services that weaken security for everyone. Within this context, Google has significant concerns with several elements of

part 2 of Bill C-22 as it is currently drafted. First, the proposed regime contemplates obligations and order-making powers that are unduly broad and practically boundless. It goes well beyond lawful access regimes in other G7 democracies and risks creating new surveillance infrastructure that would introduce serious security vulnerabilities, undermine user trust and hinder our ability to innovate and offer pro-privacy technologies. Second, the proposed framework for secret ministerial orders is unprecedented and undermines accountability and user trust.

Part 2 gives the Minister of Public Safety sweeping powers to issue secret orders mandating providers to create or maintain data interception capabilities, while permanently prohibiting companies from disclosing the existence of these orders. As written, this could give the government the power to secretly force companies to redesign products to include invasive surveillance capabilities, and to do so without sufficient safeguards or oversight. Ministerial orders are not only alarming but also unnecessary.

Canada already has an effective, transparent system where law enforcement can apply to the courts for reasonable assistance orders subject to judicial oversight. Secret orders are out of step with other democratic countries and would severely restrict companies' abilities to be transparent with users about how their data is protected. Third, the bill's definition of “systemic vulnerability” is dangerously narrow. The legislation sets a very high bar, only recognizing a “substantial risk” of unauthorized access as a vulnerability, while ignoring severe risks to data integrity and availability.

The current definition fails to explicitly protect the comprehensive security measures that Canadians rely on, which go far beyond encryption. Without stronger

definitions, the law could be used to force the dismantling of critical privacy architecture, such as breaking encryption, overriding users' data deletion controls or building remote access capability, all of which could facilitate foreign interference and weaken global user privacy.

At a time when cyber-threats are increasing in frequency and sophistication and malicious actors are using AI tools to find and exploit vulnerabilities more quickly, we cannot afford to be creating new vulnerabilities. [ Translation ] Finally, the bill imposes overly broad requirements regarding the retention of metadata, without any geographic, temporal or targeted criteria. Such requirements would mandate the blanket and indiscriminate retention of people's communications data and risk treating the entire population as potential suspects.

Unnecessary data retention threatens the fundamental rights and freedoms of Canadians, infringes on their privacy and creates a massive trove of sensitive data that amplifies the consequences of any potential security breach. The existing provisions for targeted retention orders in the Criminal Code already meet law enforcement needs while respecting the rights guaranteed by the charter. [ English ] To ensure that Bill C-22 achieves its public safety objectives without compromising the digital security of Canadians, Google has submitted a number of legislative amendments. We'd be pleased to discuss them today.

Thank you for the opportunity to contribute to this process. I look forward to your questions.

(1705) [ Translation ]

The Chair :

Thank you very much, Ms. Patell. Mr. Caputo, you have the floor for six minutes.

[ English ]

Frank Caputo :

Thank you very much, Mr. Chair. Mr. Neuenschwander, first of all, thank you for being here, and thank you to all of the witnesses. It's rare to get an engineer with your qualifications here. I feel like we could have a whole hour just with you. Have you been monitoring the committee process on this bill, may I ask?

Erik Neuenschwander :

The team has. We've been keeping abreast. I was here in the prior hour.

Frank Caputo :

I'll be very direct. My view is that this matter has been quite rushed. There are a lot of questions and things like that. Do you share that perspective?

Erik Neuenschwander :

We're here to engage with the committee with whatever time it has.

Frank Caputo :

Would it be helpful if the committee had more time to discuss this bill, in your eyes?

Erik Neuenschwander :

Again, I'm just happy to be here and to answer questions, as we will.

Frank Caputo :

Mr. Israel, can I ask you that same question, please?

Tamir Israel :

It would certainly be helpful to have more time. This committee has had three sitting days to hear from witnesses. That's not sufficient for legislation with this level of complexity. I mentioned the review that the Australian version of this got. It was much more comprehensive. This committee studied Bill C-8 for two months maybe, and it's a similar regime that raises similar questions but of less complexity and scope. I would say, yes; more time is needed to study this bill.

Frank Caputo :

Yes, I think that this bill is actually much more technical than Bill C-8 because, with Bill C-8, we could understand what different components meant. I think we'll have a witness in the next round who actually talks about what metadata is. We actually haven't gotten into the technical aspects of this. We have largely heard from people like you—people from Google, people from Apple—about their concerns, but we haven't even had time to delve into the technical aspects as to what this encryption means. Is that with respect to all aspects? Is it end-to-end encryption?

I'm not an expert on these things, and we haven't heard about that data or about that analysis from experts. I'm quite concerned. Mr. Neuenschwander and Ms. Patell, you can weigh in on this. The minister was equivocal when I asked about encryption. Even though we as Conservatives will be putting forward amendments that will clearly say that encryption will be offside when this bill is studied clause by clause, are you still concerned with respect to this bill touching encrypted technology?

Erik Neuenschwander :

We would welcome that amendment and seeing it, but we do have concerns that go beyond encryption in terms of how risk is being looked at. As strong encryption protects all users of our services, not just Apple's but across the industry, we think it is critical that this remain protected as Bill C-22 moves forward.

Frank Caputo :

Ms. Patell, do you have a comment on that?

Jeanette Patell :

Yes. In a similar vein, we've put forward a number of suggested recommendations in terms of how to strengthen this bill. I think encryption is one area that we could speak to, but like Apple, we would point to the definition of “systemic vulnerability” as an area that could be strengthened, as well as the sweeping ministerial orders. I know that my colleague, Kate, would be happy to speak more to how that could be strengthened to be more consistent with international [ Technical difficulty—Editor ].

Frank Caputo :

I'm going to ask a question on that. One of the issues that I see here is that the government has tried to put in a check and balance in the form of the approval by the intelligence commissioner, though the order would remain secret. I think judicial review is actually the ultimate form of check and balance. W hat do you say to that, either Ms. Charlet or Ms. Patell?

Jeanette Patell :

I'll turn to Kate to speak to the need for oversight.

Katherine Charlet (Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google) :

Thanks very much for the question. I do believe that it's instructive to look at some of the models that are out there. Judicial oversight certainly is an important protection. It is not the only protection. If you look at U.S. law, for example, it does require a federal judge to review before ordering a technical modification. The EU electronic evidence regulation explicitly states that any obligation to decrypt data or re-engineer systems for access is not part of the powers. The U.K. Investigatory Powers Act does include a judicial commissioner review. None of those protections is available in Bill C-22 .

We recommend that a judicial review be a part of this, but it is perhaps not the only safeguard that could be added here.

(1710) Frank Caputo :

Along those lines, would you agree....? This is an exercise in comparative legislation and drafting. One of the deficiencies I think we've had in this committee process is that we haven't heard from experts on EU law or on Australian law, where they keep metadata for even longer but I don't know exactly what categories of metadata they're keeping. Do you see it as a deficiency in this study when we don't actually have people from other jurisdictions, which is something that we heard about from the committee process?

Would it concern you, as an outside observer, that this committee isn't looking at other models and hasn't heard from witnesses who are experts on other models so that we can compare them in order to get the best possible outcome?

Katherine Charlet :

I do agree that it's instructive to look at those other models. From our assessment, it does appear that Bill C-22 would be the only G7 regime that does not include judicial oversight but does have the expansive ministerial order powers. Certainly others could weigh in on this as well, but I do think it's an instructive part of the conversation.

Frank Caputo :

Thank you.

The Chair :

Thank you very much for that. Let me turn to MP Zuberi for six minutes, please.

[ Translation ]

Sameer Zuberi (Pierrefonds—Dollard, Lib.) :

Thank you, Mr. Chair. [ English ] Mr. Israel, I would like to pick up on the last comment by Ms. Charlet. Given that you're in the Canadian Civil Liberties Association, can you comment on what Ms. Charlet just said with respect to what other jurisdictions are doing?

Tamir Israel :

The Australian regime does not include judicial authorization. This has been one of the heaviest criticisms levelled at the regime, including by an independent review of the regime that was conducted two years ago. It was the single biggest flaw that the independent review considered needed to be fixed right away. The U.K. regime does rely on judicial review by a commissioner. Under Canadian law, judicial review, as a mechanism, is different from judicial authorization, and it's important to keep the differences in mind.

Judicial review is an assessment of whether the decision-maker made a reasonable decision based on the information in front of them. In contrast, when judges are authorizing a search warrant or something of that nature, they are the ones who are weighing the different considerations. Given the nature of the bill, it's particularly problematic to rely on judicial review alone, as opposed to a stronger type of independent scrutiny.

Sameer Zuberi :

In other Five Eyes or comparable jurisdictions, is there judicial authorization in advance or only judicial review?

Tamir Israel :

In the U.K., it's judicial review, although the mechanisms of judicial review may differ from what's here in Canada. That regime is currently under constitutional challenge. In the U.S., the entire regime is overseen by an independent regulator—the Federal Communications Commission—so that's more comparable to judicial authorization.

Sameer Zuberi :

Thank you. Mr. Neuenschwander—

Erik Neuenschwander :

“Erik” is also fine.

Sameer Zuberi :

Erik, in terms of what we just heard, are you familiar with other jurisdictions and how they're dealing with these concerns to balance catching bad actors online and protecting civil liberties? Are you familiar with what other jurisdictions are doing?

Erik Neuenschwander :

From an engineering standpoint, I am in terms of the scope of what the orders might be able to request.

Sameer Zuberi :

With respect to the legislation and the engineering standpoint that you mentioned you're familiar with and that exists in other jurisdictions, do other jurisdictions have the concern that we have, in the sense that we cannot necessarily catch all of the bad culprits that we should be catching within a reasonable period of time, and this legislation seeks to shorten and address that concern about a reasonable time?

(1715) Erik Neuenschwander :

It's hard for me to speak for other jurisdictions, but in general, I would say that the desire to catch bad actors is a universal one.

Sameer Zuberi :

I ask because the comparative is interesting. Ms. Charlet, if you have knowledge on this particular question, then feel free to answer. Otherwise, I'll continue to other questions.

Katherine Charlet :

Google appreciates the challenges that law enforcement faces, and we're here to support those efforts. That's part of our effort to provide constructive recommendations on how to amend the bill.

Sameer Zuberi :

Erik, earlier you mentioned encryption. We've heard many times from the government's perspective that it is not being asked that encryption be unlocked. How is it that you still are coming to the committee and the main thrust of your testimony is around encryption and your concerns about it being unlocked? How do you square that circle?

Erik Neuenschwander :

Again, I'm certainly not an expert on legislative text, but in reviewing it with the team, I don't see anything written within the bill itself that provides those protections against encryption. I do grant that the bill does not actually specify what these orders would do. That's kind of left for later. To bring this into a real-world analogy, I might say something like we're concerned about a hole being put in a wall. I would say that the bill does not put a hole in the wall. It merely allows for secret orders to force putting a hole in the wall. Our concern is motivated because, at the end of the day, there would still be a hole in the wall.

Sameer Zuberi :

If your concerns, as the the government puts forth, are moot, then do you have any other amendments or suggestions with respect to the legislation that you would like to put on the table?

Erik Neuenschwander :

The primary ones are around protecting encryption explicitly and strengthening the definition of systemic risk, as encryption is just one aspect of where making everyone less safe, we think, would be a counterproductive outcome for society. We would welcome additional judicial review. We would welcome relaxation of some of the secrecy protections, because I would like conversations such as this one to still be able to occur in the future. We also have some concerns around the breadth of the inspection powers that are in the bill and the possibility of installing third party equipment into secure networks.

Sameer Zuberi :

Mr. Israel, I'd like to open up the floor to you for the next few moments to add anything that you'd like to add.

Tamir Israel :

A definition that encompasses the need to exclude any obligations that cause systemic vulnerabilities would need to take into account the multiplicity of ways and proposals that keep emerging for getting around encryption. Many of these don't compromise encryption directly, but try to get at it indirectly by circumventing it or bypassing it, yet still have the same impact in terms of the vulnerabilities that they ultimately create. The current definition doesn't capture all of these. It's limited in scope. I would also really encourage your committee to consider blocking that.

Sameer Zuberi :

Thank you.

[ Translation ]

The Chair :

Thank you, Mr. Zuberi. Mrs. DeBellefeuille, you have the floor for six minutes.

Claude DeBellefeuille :

Thank you very much, Mr. Chair. I thank the witnesses for joining us. Ms. Patell, I thank you and congratulate you for taking the time to deliver part of your remarks in French. Your French is excellent, as is your pronunciation. So, thank you very much. Your company operates in all Five Eyes countries, if I am not mistaken. Therefore, you are already subject to legal access regimes or laws, such as those in the United States. When compared to the United States, we see that Canada has more laws, mechanisms and institutions that protect privacy. At least, that is my

interpretation. So, given that your company also operates in the United States and that you say you find the Canadian government's bill too restrictive, can you tell us how, in your view, it compares to that of the United States?

Jeanette Patell :

Thank you for your question and for your kindness regarding my French. I will now turn the floor over to my colleague Ms. Charlet, because it is clear that there is tension regarding the Privacy Act and Bill C‑22 . (1720) [ English ] I'll pass it on to my colleague Kate to speak more with regard to the privacy considerations that are invoked by this law in particular, in comparison with the U.S. regime.

Katherine Charlet :

Thank you very much. I think the primary comparison here is to privacy principles. We think of privacy principles around data minimization and user controls and about the potential that Bill C-22 could undermine those privacy principles. Just as an example, if we look at Google's provision of user controls, we offer users the ability to choose to delete their data after three months. Retention requirements or product changes that require us to make changes that would require retention for longer than three months would be against the wishes of a user.

We look at this with concern in terms of privacy principles that are global in nature. On your question regarding U.S. law, we look to U.S. law—CALEA specifically. CALEA does explicitly forbid governments from forcing a company to break encryption. That is a similar protection that we would be seeking in Bill C-22 .

[ Translation ]

Claude DeBellefeuille :

Experts and civil society organizations say that the U.S. CLOUD Act grants U.S. authorities the power to demand access to data held by companies subject to U.S. law, regardless of where the data is stored. If Bill C‑22 is passed, do you believe Canada will be equipped to deal with this requirement? Many companies and citizens are afraid. They fear that, once Bill C‑22 is passed, our data will become accessible to countries that do not share our concerns regarding privacy protection or even respect for human rights.

[ English ]

Katherine Charlet :

I would say that this law does have global impact. Bill C-22 could require, under the ministerial orders, a company to make product changes. It is essentially unbounded in terms of what those product changes could be, as well as the secrecy requirements involved. Google and other companies are global companies and Canadians interact with people all over the world, so there are global impacts to a proposal such as this one.

[ Translation ]

Claude DeBellefeuille :

Ms. Charlet, you say that Bill C‑22 is more intrusive in terms of legal access than the laws in the United States.

[ English ]

Katherine Charlet :

Yes, ma'am. The essentially unbounded nature of the powers that are afforded to direct product changes by companies in secrecy and without judicial oversight, in the case of the ministerial orders, goes beyond any regime that I'm familiar with.

[ Translation ]

Claude DeBellefeuille :

Were you consulted prior to the drafting of Bill C‑22 ? Did you express your concerns to the government during the bill’s drafting process?

[ English ]

Katherine Charlet :

We have provided a submission with some specific recommendations, but I will pass this to my colleague, Jeanette, on your broader question.

Jeanette Patell :

We have shared these concerns with the government. I don't believe we were in a consultation process prior to tabling, but we welcome the opportunity to engage with this committee to find workable solutions here that can support law enforcement in its legitimate need to conduct investigations, while also preserving user privacy and maintaining the security of our products and services. Thank you for the constructive engagement.

The Chair :

Thank you, Madame DeBellefeuille. We'll now go to Ms. Kirkland for six minutes, please.

(1725) Rhonda Kirkland (Oshawa, CPC) :

Thank you, Chair. I would like to start with just—

The Chair :

I said six, but it's five minutes.

Rhonda Kirkland :

You said six, so it's too late. I want those seconds back, though. I'd like to start by talking about the fact that this is rushed. We've mentioned this before. It feels rushed to me as a parliamentarian. I had questions in the last hour that I really wanted to get to and wasn't able to because of how fast all this is proceeding. I made the statement early on that I thought we should be careful not to just race to royal assent. If we're going to do this, then we need to get it right. I know that we've missed getting some submissions to the committee, and I don't fault anyone for that.

I know there was no malice intended. I don't fault the clerk for that. It's to be expected in such a rushed environment that those types of things will happen. Mr. Neuenschwander, it is my understanding that you did provide submissions to this committee. I don't believe it has come through the clerk yet, but thankfully, you sent them to each of us directly. I appreciate that very much. I want to backtrack with regard to what I hear over and over again, the term “back door”. I think Canadians really need to understand what that means.

On the Government of Canada website from five days ago, under lawful access, it says, “Bill C-22 does not require ESPs to create 'backdoors' to their systems or [to] weaken electronic protections, including encryption.” Also said in testimony by Mike McGuire was:

This part does not create new powers for law enforcement or CSIS to intercept communications or obtain information, nor does it allow direct government access to electronic service providers' systems. It also explicitly prohibits the creation of systemic vulnerabilities, to ensure that a regulation or ministerial order does not weaken encryption or create back doors.

The minister said:

This part also includes an explicit safeguard to prevent the introduction of systemic vulnerabilities in electronic protections. Our government does not support the creation of back doors.

Testimony today seems to make that obviously not really the case, so I need some clarification. I'm happy for each one of you to provide that clarification. I think the word “explicit” is worth taking a longer look at, because it doesn't seem to be explicit in this legislation. I know that there are ways that we can make it explicit, so I'd like each of you to talk about that briefly. Thank you. We'll start with Mr. Neuenschwander.

Erik Neuenschwander :

I did not hear that testimony directly, but in our reading of the bill, we don't see some of those claims explicitly in the language. There's not a mention of protection of encryption, which we would support being added to the bill. In the definition of systemic risk or “systemic vulnerability”, it mentions the term but without a definition of that term. The intentions aren't coming through clearly in the language, from our perspective. That's why, as you've mentioned, we've given a written submission and suggested amendments.

Rhonda Kirkland :

Thank you. You used a very important word, which is “intention”. We're often told that this bill does not intend to do X, Y or Z. I'll say again that Canadians really don't care what the bill intends to do. They care about what the bill will allow the government to access, and that's a real concern. Thank you for bringing that up. I'll take it to Mr. Israel first, and then we'll go on to Google.

Tamir Israel :

I echo your concerns about intent versus application. It took seven or eight years before the U.K. version of this law was used to strip all people in the U.K. of a critical encryption safeguard for their Apple iCloud backup. It's not the immediate intent of the government that's relevant. It's how the bill could be applied over time. In this instance, the bill does prohibit the imposition of systemic vulnerabilities, but that, by definition, does allow non-systemic vulnerabilities, first. Second, it leaves a lot of e-terms in the definition open to

interpretation through regulation. A big problem with the constant attempt to maintain end-to-end encryption secure is the multiple ways that governments and bad actors keep coming up with to get around encryption. Some of these mechanisms directly compromise encryption. I've seen government

definitions of back doors limited to those examples, but other tools that are commonly advanced, for example, client-side scanning, which essentially places an AI tool on everybody's device that monitors their content before it's encrypted and sent onwards and has been assessed by leading security technologists around the world as creating systemic vulnerabilities, do not compromise encryption in the way that this exception would prevent. You need a comprehensive exception that rules out all back doors and all ways of bypassing encryption. Thank you. I'm sorry for the long answer.

(1730) The Chair :

Thank you, Ms. Kirkland. We'll go to MP Housefather for five minutes, please.

Anthony Housefather (Mount Royal, Lib.) :

Thank you very much. Mr. Neuenschwander from Apple and Ms. Patell from Google, I appreciate your testimony and your being here. I've read your submissions. As a general counsel for a computer company before I went into politics, I'm sympathetic to strengthening protection for encryption and clarifying the definition of “systemic vulnerability” and some of the other provisions you mentioned. I want to respond to something Ms. Kirkland said. Authorities provisions are standard in any compliance framework.

They are in many federal laws, and they don't really specifically relate to the core lawful access provisions of this bill. I just wanted to get that out. Mr. Neuenschwander, I've read what you said. Has Apple ever gone before a parliamentary committee or made a submission to a national parliament on a lawful access regime that Apple actually supported?

Erik Neuenschwander :

I'm more on the engineering side than our government affairs side. I'm not familiar with all of our submissions, but we are supportive of parts of Bill C-22 and modernization overall to enable law enforcement to become better and more efficient—

Anthony Housefather :

I understand that. I understand that both Apple and Google are largely supportive of the idea but have objections to specific provisions of the bill. I just wanted to establish whether you have ever seen a bill that you didn't have objections to some portions of. I think people are overstating some of the objections. I don't disagree with some of the objections you raised, but I don't think some of the claims that are being made—for example, surveillance equipment that could be installed in devices and forcing companies, even under orders, to put in surveillance equipment—are reasonable or logical.

I don't think they bear out in the wording of the bill. What I'm asking is this: Have you guys ever gone before a committee or made a submission in the U.K., in Australia or in the U.S. and said, “Wow, we think this bill is great”?

Erik Neuenschwander :

As we're doing here today, we have frequently gone to engage in constructive—

Anthony Housefather :

Yes, you've gone to engage and to object to provisions in the bill, which is your job. We as legislators have to look at it with multiple lenses. You have a specific obligation related to the company. The company's obligation is often to respect its user agreements with end-users and to do what's best in the company's interest, not necessarily in the national interest. All I'm asking is if you have ever come to a committee and said, “The bill is great.” I doubt that you have.

Erik Neuenschwander :

With respect, I think we're trying here to act in the interests of users, both Canadian and worldwide, and ensure that we can provide the strongest protections possible while supporting law enforcement.

Anthony Housefather :

I don't disagree with you. I think that's part of the overall goal. Let me also ask.... You are the chief privacy officer. You're in charge of privacy at Apple.

Erik Neuenschwander :

I am from the engineering standpoint, yes.

Anthony Housefather :

It's from the engineering standpoint. That's right. You may think this is a negative question, but I don't. I think this is actually a lesson. Has Apple ever created something that you later regretted? With respect to privacy interests, I'll give you the IDFA as an example.

Erik Neuenschwander :

I don't know that I would go so far. For those less into the technology, the IDFA is an advertising identifier. I think it was appropriate for its time. What we do is we continue to evolve the protections on the privacy and security side as the world continues to change.

Anthony Housefather :

You did create something that eventually had ramifications that you and your team probably didn't even realize when you first created it. Developers actually used this to thwart what you thought would be users' preferences. I remember that.

Erik Neuenschwander :

I take it as a given that attacks and uses of data only increase and grow stronger over time, which is why we continue to move forward and innovate on the protection side. I wouldn't put IDFA in the class of attacks, but when we're thinking about attacks generally, we have to continually move forward to continually protect against the stronger attacks.

Anthony Housefather :

I agree, and that's why, when we look at this bill, we have to look at some of the concerns that are being raised, even if we don't necessarily think that those are likely to happen. We know that we have to provide for contingencies. We have to make sure that we avoid getting ourselves into a situation where pernicious effects could occur. I'm actually sympathizing with what you're saying, because whether it's in the bill or not, I think we want to provide for the concerns that are there. Ms. Patell, I carefully read your submission as well.

If we were able to limit the definition of “systemic vulnerability” and we were able to guarantee or make it clear that encryption was not to be broken, would those be the two major points that you would have with respect to the bill that would alleviate the concerns that Google has expressed?

(1735) Jeanette Patell :

We certainly welcome all of the statements that have been made with regard to the government's intent, and specifically with regard to the desire to protect encryption. We simply want to see that reflected in the text of the bill itself. I would point to a few other areas where we've put forward four recommended amendments. A few others relate to both the metadata retention provisions and to the sweeping nature of the ministerial orders. That's something that we believe is unprecedented and unnecessary, and we would therefore recommend the elimination of secret ministerial orders as well. I don't know if my colleague Kate wants to weigh in as well on anything else.

Anthony Housefather :

I think the chair might not allow that since it seems as though my time is up.

The Chair :

I'm sorry. Unfortunately, your time is up, Mr. Housefather, so is the time for answering those great questions. [ Translation ] Mrs. DeBellefeuille, you have the floor for two and a half minutes.

Claude DeBellefeuille :

Thank you, Mr. Chair. Mr. Israel, do you share these concerns? In your view, does the bill increase the risks associated with sharing information with states that have a troubling human rights record?

[ English ]

Tamir Israel :

Yes, in two respects. First of all, the bill paves the way for the adoption of international information-sharing agreements, including with countries that have problematic human rights records. That's one problem. A related problem is that the metadata retention regime has no limitations on who can access that metadata. Once it's kept, any government can force a multinational company that's active in their jurisdiction to disclose that data, which would not have been kept if the company was not forced to keep it, about people in Canada.

[ Translation ]

Claude DeBellefeuille :

In that regard, have you ever expressed your concerns to members of the government regarding the exchange of personal information with states that have a rather troubling human rights record? This is not the first time you have expressed such concerns to members of the government.

[ English ]

Tamir Israel :

We've expressed our concerns regarding the information agreements I mentioned. However, we were not made aware of the inclusion of the mandatory data retention regime until Bill C-22 was tabled, so we did not have a chance to mention it in advance.

[ Translation ]

Claude DeBellefeuille :

In your opinion, should we give more powers to accountability and oversight bodies to monitor government activities and better protect users’ privacy?

[ English ]

Tamir Israel :

Absolutely. I think judicial authorization will be a critical addition here. Having more direct oversight from bodies like NSIRA and the Office of the Privacy Commissioner would also be helpful. This is a very powerful set of tools that are being brought into place. Also, as a civil liberties organization, we don't appear at many legislative committees to encourage an expansion of police powers. However, I do want to say that we are very selective in when we show up and how aggressively we object. This regime really is on the broader end, which is why we are here and expressing our concerns.

[ Translation ]

The Chair :

Thank you, Mrs. DeBellefeuille. Mr. Baber, you have the floor for five minutes.

[ English ]

Roman Baber (York Centre, CPC) :

Thank you. Erik from Apple Inc., welcome to public safety and national security. I see a comment, which was made by the Apple company, in The Globe and Mail that this legislation could allow the Canadian government “to force companies to break encryption by inserting back doors into their products—something Apple will never do.” For the record, Conservatives oppose the breaking of encryption. However, I'd like you to follow up on this comment by Apple that breaking encryption by inserting back doors into your products is something you would never do. Let's say that this legislation passes in its current form and the Liberals get their way. What happens then?

(1740) Erik Neuenschwander :

We will remain committed to providing the highest level of security we can for Canadians. We hope that the bill will be amended to provide those explicit protections for encryption so as to avoid putting those things in tension.

Roman Baber :

I appreciate that, but what if Conservatives are unsuccessful, and you're forced to insert a back door and break encryption? What will Apple then do? Will that be a first for Apple, or will that mean that Apple will be leaving Canada?

Erik Neuenschwander :

I can't speculate what would happen in that situation. Through this engagement and the continued dialogue we hope to, again, have positive amendments made to the bill.

Roman Baber :

Can you tell us what happened in the U.K. vis-a-vis the same question, when Apple decided that the legislation in the present form was unacceptable to it?

Erik Neuenschwander :

Apple filed comments in both the initial round of the bill and then as public comments during its amendment phase, more recently.

Roman Baber :

Okay. To Google, I see in your brief a comment that, “Google has never built a back door or any other mechanism to circumvent end-to-end encryption in our products.” Is that limited to Canada, or is that global?

Jeanette Patell :

That is global.

Roman Baber :

In other words, this would be a first. If this legislation is successful and if it passes in its current form, Google would be forced to do something it has never done anywhere in the world.

Jeanette Patell :

If this legislation passes in its current form, the minister would have the power to order Google or any other electronic service provider to comply with the core obligations that are listed in proposed subsection 5(2). We're here today to ensure that the committee takes the time to have this conversation and arrive at a piece of legislation that is workable and strikes the right balance in preserving user safety and security while supporting law enforcement efforts.

Roman Baber :

Thank you. You write that the scope of these potential obligations is largely “boundless”. Could you tell us some of the boundaries that may be tested here that have not been tested before, other than the breaking of encryption?

Jeanette Patell :

There are in fact comprehensive layers of security architecture that are at stake here that go well beyond encryption. I think my colleague Kate can speak to what that could entail.

Katherine Charlet :

I'd say the reason that we view these as essentially boundless is that the powers for the ministerial orders as well as the core provider obligations really are essentially boundless in the sense of the notices that could be given to persons; the installation, use, operation, management and testing of any device or equipment; and numerous other enumerated powers that go beyond some of the authorities that are given in other countries around the world.

Roman Baber :

If I understand your submission correctly, not only is the scope of those ministerial orders potentially boundless, but the framework for these ministerial orders also immunizes them from any appropriate scrutiny or accountability, because you can't appeal them. You can't go to a court and say that you're not comfortable doing what the minister orders you to do. There is no judicial oversight. Is that correct?

Katherine Charlet :

It's correct that this is done entirely in secret. I do believe that there is an ability to appeal. However, during that appeal period, there is no stay, so if there is an order on the company, the company would be obligated to implement the change before getting a decision on an appeal.

Roman Baber :

I want to clarify that the public safety minister , the government, CSIS and the RCMP already have an ability to seek and obtain a search warrant and ask Google to comply with requests for information. Is that correct?

Katherine Charlet :

That is correct.

Roman Baber :

Then I'm not exactly sure why there is the requirement to overbear. I want to talk for a minute about the electronic—

The Chair :

Unfortunately, the time is up, MP Baber. I'm sorry for that. Let me turn to MP Powlowski for five minutes, please.

Marcus Powlowski (Thunder Bay—Rainy River, Lib.) :

Because I'm a boomer, my kids can run circles around me with respect to everything involving computers, and I have to say that I'm still trying to figure out this bill. The bill pertains to service providers and data providers. Is Apple one or both of those, Erik?

(1745) Erik Neuenschwander :

I might guess so, but it seems unspecified within the bill.

Marcus Powlowski :

How would you define a service provider and a data provider?

Erik Neuenschwander :

I don't count myself as an expert on legislative text, but I would think that it's trying to look at service providers that hold information as part of doing business.

Marcus Powlowski :

I'm sorry. Is that the service provider and the data provider? Maybe I don't need to ask you that. Tell me about the cost implications of this bill for Apple. How is this going to affect you financially? Specifically, there is a requirement for retaining metadata for up to a year. You're a computer guy. You're an engineer. How do you maintain metadata? Where does that happen? Is that up in your cloud? Where does that take place, and what are the costs for your company in keeping that kind of data?

Erik Neuenschwander :

Primarily, I don't think we're overly focused on the costs. We're focused on the risks that would arise from that increased metadata retention. Currently, we maintain the minimum amount of data necessary to provide the service. My understanding from the current draft is that it could force an increase beyond that time. What we're looking at then is just a larger amount of data that could be breached by an attacker and used to commit other crimes. We're not aware of that ever having happened to Apple so far, and I will touch wood, but part of that is because we reduce that threat profile today as much as possible.

Marcus Powlowski :

You do not think the cost implications are of concern to your company.

Erik Neuenschwander :

As an engineer, it's probably a little outside of my area, but again, I would be concerned mostly with security.

Marcus Powlowski :

Let me ask Google the same question. Do you consider yourself a service provider, a data provider or both of those?

Jeanette Patell :

Similar to Apple, some of those

definitions are left for future regulation, so we await further clarity in terms of the scope. Our understanding is that, either way, we would be captured by the legislation.

Marcus Powlowski :

I'm a little surprised. Given the size of Google and Apple, how big these companies are, I'm a little confused that legislation can be so vague that you don't even know whether this applies to you.

Jeanette Patell :

It's a very good point about the opportunity for clarity and precision in the legal text so that the companies that are operating in Canada have a clear sense of the obligations that apply to them.

Marcus Powlowski :

Can I ask you about the cost implications of this? Maybe I should ask generally before I get into the specifics of retaining metadata for up to a year. Just generally, what do you see as the cost implications for Google?

Jeanette Patell :

Similar to Apple, the cost considerations have not been our primary consideration. We've been focused on the vulnerabilities that this would introduce to our—

Marcus Powlowski :

Let me challenge that. You are corporations. I think you do very well as a corporation. I may even have stocks in your corporation, which—thank you very much—do very well, but I think you are driven and mandated as a company to look after the financial bottom line. I'm a little surprised that you're not concerned about the financial implications of this.

Jeanette Patell :

Our goal here is to first preserve users and the systems that we operate. We invest quite a lot of resources in doing that for users globally, including from some of our incredible team out of Montreal. Maybe Kate can speak to what we see in terms of the compliance burdens that might come with regimes like this.

Katherine Charlet :

I agree with the comments made so far on cost, but what I would add is that global companies seek to build one product experience, not have 100 different product experiences and systems that they have to build around the world. Of course, we're a large company. We can handle complex compliance regimes but, in terms of the product experience, it's a better experience for users when they move across borders to have a similar experience.

Marcus Powlowski :

We've already heard that—

The Chair :

I'm sorry, MP Powlowski, to cut you off, but that's my obligation, given that the time is over for this second hour. Thank you, witnesses, for taking the time to be with us either in person or virtually. We will suspend for a few moments until the other group comes in. Again, thank you, and have a great day.

(1750) (1755)

[ Tran

Document details

CollectionHouse Committees
CitationSECU / 45-1 / Meeting 38 / EV14129354
Typecommittee
Volume / chapterSECU / Meeting 38
Languageen
Formatxml
SourceCOMM_HOC
Identifier6092134ef8279e5718ff56922c4be89cf2cd123a

Source file is stored in the law ingest library (xml).