Evidence of meeting #109 for Access to Information, Privacy and Ethics in the 44th Parliament, 1st Session. (The original version is on Parliament’s site, as are the minutes.) The winning word was question.

A recording is available from Parliament.

On the agenda

MPs speaking

Also speaking

Dominic Rochon  Deputy Minister and Chief Information Officer of Canada, Treasury Board Secretariat
Mario Dion  Former Conflict of Interest and Ethics Commissioner, As an Individual
Konrad von Finckenstein  Commissioner, Office of the Conflict of Interest and Ethics Commissioner
Michael Aquilino  Legal Counsel, Office of the Conflict of Interest and Ethics Commissioner

11 a.m.

Conservative

The Chair Conservative John Brassard

I call the meeting to order. Good morning, everyone.

Welcome to meeting number 109 of the House of Commons Standing Committee on Access to Information, Privacy and Ethics.

Pursuant to Standing Order 108(3)(h) and the motion adopted by the committee on Wednesday, December 6, 2023, the committee is resuming today its study of the federal government's use of technological tools capable of extracting personal data from mobile devices and computers.

Today's meeting is taking place in a hybrid format, pursuant to the Standing Orders. Members are attending in person in the room or remotely using the Zoom application.

Again, as I always do, I would remind you to be mindful of your earpieces so that they don't cause feedback and damage to our interpreters. The interpreters today, by the way, are on a remote basis. I believe all members were notified by the clerk of that yesterday.

I'd now like to welcome our first witnesses for this first hour. We have Minister Anita Anand, President of the Treasury Board.

Welcome, Minister.

With the minister is Dominic Rochon, deputy minister and chief information officer of Canada, Treasury Board Secretariat.

Minister Anand, I understand that you do have opening remarks and that you will be addressing them to the committee.

You have up to five minutes. Please start.

11 a.m.

Oakville Ontario

Liberal

Anita Anand LiberalPresident of the Treasury Board

Thank you very much, Mr. Chair.

Before I begin, I'd like to acknowledge that the lands on which we are standing and gathering constitute unceded territory of the Algonquin Anishinabe peoples.

Thank you for giving me the opportunity to emphasize the government's commitment to ensuring privacy.

I'm joined today by Dominic Rochon, chief information officer of the Government of Canada.

Let me begin with this. Our government takes the privacy rights of Canadians and federal public servants extremely seriously. It is one of our top priorities.

The government manages personal information holdings through a series of policies and directives that align with the legislation. As President of the Treasury Board, I'm the designated minister responsible for administering the Privacy Act, which sets out the privacy requirements for federal institutions. This legislation also gives individuals the right to access and correct the personal information held by federal institutions.

The Treasury Board of Canada develops and implements policies, directives and guidance to assist government institutions in meeting their obligations under this act. However, it is important to note that heads of government institutions, or their delegates, are responsible for the proper implementation of the act as well as overseeing TBS's privacy policies within their institutions.

One of these TBS policies is the directive on privacy impact assessment, which sets requirements for institutions to complete privacy impact assessments, or PIAs. A PIA is required when personal information is used for, or intended to be used as part of, a decision-making process that directly affects an individual. The directive requires that institutions undertake a PIA when implementing a new program or activity, and when substantially modifying an existing program or activity and that involves the creation, the collection and the handling of personal information.

Mr. Chair, it is important to note that the responsibility for privacy impact assessments rests with the institution responsible for the program.

My department is committed to renewing privacy policies. We'll update the directive on privacy impact assessment. This update includes a commitment to streamline privacy impact assessments and look for ways to improve the directive.

We've undertaken government-wide action, we've consulted with privacy experts on changes to the directive on privacy impact assessment and we are engaging with the Office of the Privacy Commissioner. We intend to publish the updated directive this summer. Heads of government institutions or their delegates are accountable for adhering to those rules that are set out in the Privacy Act and TBS privacy policies.

Institutions will be best placed to provide context regarding the use of digital forensic tools in their respective environments. I am happy to be here alongside Mr. Rochon to discuss how TBS policy can be made more clear, streamlined and easier to follow for those institutions on a day-to-day basis as we continue to respect the Privacy Act and privacy laws that are so important for the protection of personal information.

With that, Mr. Chair, I will close my opening remarks. I'm open to your questions.

Thank you.

11:05 a.m.

Conservative

The Chair Conservative John Brassard

Thank you, Minister.

We're now going to start our six-minute rounds. For the first round for today, I'm going to Madame Kusie.

Mrs. Kusie, you have six minutes. Go ahead, please.

Stephanie Kusie Conservative Calgary Midnapore, AB

Thank you, Mr. Chair.

Welcome, Minister, to the ethics committee.

This is, of course, our second day together in a row. Yesterday, in the government operations committee, I expressed my disappointment in your handling of the public purse—the $40-billion deficit and the $500 million. It was indicated that you would make the commitment to try to find out how the majority of those funds are from lapsed funds and reserves, not new amounts of savings.

Of course, you put out the second edition of the managerial guidelines yesterday, since clearly the managerial guidelines of October were not effective in the six-month period. We didn't even have an opportunity to touch on your role in the oversight of the privacy of information. There was so much to cover yesterday. Frankly, I shudder at the thought of having to take over your role, if necessary, because of the incredible amount of work to do.

Let's talk about PIA compliance today, privacy impacts assessments.

When the news broke about the lack of privacy impact assessment compliance across 13 different federal departments and agencies, you stated that each federal institute—as you did today—is responsible for enforcing the laws and policies. I feel this ignores the responsibility of the Treasury Board to provide oversight and ensure departments are enforcing these policies.

After more time for reflection, and I was previously making this point, would you not agree that it's a responsibility of the President of the Treasury Board to ensure that federal departments and agencies are protecting the privacy of your primary constituents, the public service?

Anita Anand Liberal Oakville, ON

The Privacy Commissioner has received no complaints relating to a violation of the Privacy Act. The Privacy Commissioner has engaged in no investigation and has stated that there was no breach of the law.

The role of the Treasury Board is to promulgate rules and policies relating to the governing of the public service, and those rules need to be enforced by deputy heads. That is what is continuing to happen. We play a coordinating role across government to ensure they have what they need in terms of information relating to government policy.

11:05 a.m.

Conservative

Stephanie Kusie Conservative Calgary Midnapore, AB

I believe the term the commissioner used was that it was “an insult” that this sentiment was felt.

Throughout the testimony of the departments accused of not following the Treasury Board privacy policies, we received a number of different responses. Some stated they have the tools and are using them, but are now completing a privacy impact assessment. Others stated they completed a general PIA that covered the tool, rather than specifically analyzing the security concerns of this invasive technology.

Is it concerning to you that 13 departments using the same tool have completely different definitions of what “compliance” means when it comes to following the PIA?

Anita Anand Liberal Oakville, ON

To be clear, as the designated minister under the Privacy Act, I'm responsible for the administration of the act. However, the deputy heads are responsible for implementing Treasury Board policies. I am currently updating the directive on the privacy impact assessments.

I will say that programs and activities require a PIA, not the forensic tools themselves. In fact, a majority of those departments are conducting a PIA. We have reached out to them numerous times, as well as to the Privacy Commissioner.

My CIO, Dominic Rochon, can add to this.

Dominic Rochon Deputy Minister and Chief Information Officer of Canada, Treasury Board Secretariat

Thank you, Minister.

I will add that with regard to the 13 departments in question here, indeed we followed up with all of them. There was a different set-up with regard to the programs and activities in question. Most of them had PIAs. Then there's the question of whether or not they updated those PIAs at different moments in time when it was apparent they took on new tools. We're getting that info.

I think, out of the 13, three departments.... For example, the CRA had a PIA for their activities for their program and also flagged that they would be using forensic tools, so that was fully compliant. In other instances, there was a decision made that the PIAs did not require an update. There were a couple of departments there—the Competition Bureau and the CRTC, for example. Then, in other cases, departments said that out of an abundance of caution, they were going to update their PIA.

11:10 a.m.

Conservative

Stephanie Kusie Conservative Calgary Midnapore, AB

Thank you, Mr. Rochon, for that.

Madam President, you say that you're responsible for the administration of this, but I just don't understand how this doesn't imply that you have complete responsibility and oversight. How can one have responsibility for the administration yet not have the responsibility to ensure that the proper documentation is completed for the protection of Canadians' privacy?

I'll try to get another question in briefly, Mr. Chair. I know my time is coming to an end.

We've heard in this committee that mobile forensic devices, the forensic tools being used by numerous federal departments, are not necessarily spyware but have the same capabilities and are provided by the same suppliers. Do you agree, Minister, that this technology is invasive and violates the privacy of the public servants and the Canadians it is used on?

11:10 a.m.

Conservative

The Chair Conservative John Brassard

I'm going to need a quick response.

Anita Anand Liberal Oakville, ON

There was no violation of the Privacy Act, and the Privacy Commissioner did not launch an investigation or receive any complaints. There was no violation of the Privacy Act.

11:10 a.m.

Conservative

The Chair Conservative John Brassard

Thank you, Minister.

Thank you, Ms. Kusie.

Ms. Khalid, you have six minutes. Go ahead.

Iqra Khalid Liberal Mississauga—Erin Mills, ON

Thank you very much, Chair.

Thank you, Minister, for being here today.

Minister, when did you first find out about this issue, and what steps have you taken since to rectify it?

Anita Anand Liberal Oakville, ON

The issue relates to the use of PIAs relating to privacy law that departments are undertaking. A PIA is like a checklist: It ensures that the protection of personal information of Canadians continues to occur on a department by department basis.

When I was first sworn in, of course I received numerous briefings relating to my obligations as minister, and I will continue to make sure that Treasury Board policies are understood and distributed across government. It was the end of November when the article was released.

Of course, I was briefed by my team at the time, and I will now ask Mr. Rochon if he could elaborate on the steps we took thereafter.

11:10 a.m.

Deputy Minister and Chief Information Officer of Canada, Treasury Board Secretariat

Dominic Rochon

Thank you, Minister.

Indeed, December 4 was when the privacy and responsible data team, which is a team within the office of the chief information officer, followed up with all 13 organizations.

We came up with a series of six questions. Obviously, the first question was on whether your institution used the tools or software described in the article. The second question was on which personal information banks were associated with those programs or activities, because a PIA is required on a program or an activity, not an actual tool. Then, what are the legal authorities under which those programs or activities operate? We then asked whether or not the program area consulted their section 10 delegate as to whether or not the Privacy Act was addressed in looking at those tools, and we also asked some questions about the procurement of those tools as well.

Anita Anand Liberal Oakville, ON

I will just add that I don't know if it is clear, but there are statutory obligations to undertake investigations, in which case these forensic tools are required, but before they are used in the collection of any personal information, a warrant is required from a judicial standpoint, so there is a very high threshold before these instruments are utilized. It is not taken lightly. Obviously, there are legal parameters that must be respected, including the Privacy Act, the governing legislation, as well as judicial authorization relating to a warrant. The threshold is high.

Iqra Khalid Liberal Mississauga—Erin Mills, ON

Thank you. I really appreciate that.

You spoke about the privacy impact assessments in your opening remarks. Why are privacy impact assessments important, do you think?

Anita Anand Liberal Oakville, ON

Institutions are required to undertake a PIA for a program or activity in order to protect the privacy of Canadians. When personal information is being used or is intended to be used as part of a decision-making process, that directly affects the individual. When personal information is intended to be used in modifications to existing programs or activities, privacy impact assessments enable the department and department heads to mitigate privacy risks. That is one of the advantages of the PIA, and I am going to revise the PIA directive. I'll be issuing it this summer, and I will be updating it to ensure that it will be well understood by all departments.

Iqra Khalid Liberal Mississauga—Erin Mills, ON

I appreciate that.

Are departments required to provide PIAs, based on the Privacy Act?

Anita Anand Liberal Oakville, ON

They are not. PIAs are not mandatory.

As I said, it's a checklist of items to make sure that Privacy Act considerations, and the protection of individual personal information is paramount. It enables that assessment and risk analysis to occur. Because those investigations are required under statute.... For example, whether it is the CRA to prevent fraud or to investigate fraud, these forensic tools can be useful, but they can't be implemented without legislative and judicial oversight.

Iqra Khalid Liberal Mississauga—Erin Mills, ON

Do you think there should be legislative oversight in the way PIAs are conducted within different departments?

Anita Anand Liberal Oakville, ON

I spoke with Minister Virani last night. I know he is examining the Privacy Act as a whole from a Minister of Justice standpoint. We are updating our own directive, which is solely within Treasury Board's authority. That is my realm, so I want to make sure that the checklist of items—the PIAs and the risk analysis that will be done by departments—will occur.

Consultations are ongoing. We need to make sure we do this right. That is a systematic process, and I will come forward this summer with more to say on an updated directive.

Iqra Khalid Liberal Mississauga—Erin Mills, ON

Thank you, Minister

11:15 a.m.

Conservative

The Chair Conservative John Brassard

Thank you, Ms. Khalid, and thank you, Minister.

Mr. Villemure, you have the floor for six minutes.

René Villemure Bloc Trois-Rivières, QC

Thank you, Mr. Chair.

Good morning, Mr. Rochon and Ms. Anand. Thank you for being here this morning. I hope that you can shed light on some of the remaining grey areas.

Ms. Anand, were you surprised to find out, in the article published by Radio‑Canada in December, that 13 organizations weren't carrying out privacy impact assessments?