It raises an interesting point.
People may recall that this particular issue arose nearly 20 years ago, when the Province of British Columbia was seeking to outsource some of its health information. That health management information was going to go the United States, and there was concern about the applicability of the U.S.A. Patriot Act.
I would say that in the current environment, it speaks to a broader concern. If we think of a spectrum of privacy safeguards around data, with the Europeans and the GDPR having some of the strongest rules, the U.S. in many respects is often viewed as having the most lax rules. They have fairly weak rules. In fact, this agreement builds in the ability for the U.S. to continue to have fairly weak rules without widespread privacy rules. Effectively, as little as telling people what you're going to do with their information, as long as you abide by what you've told them, is good enough. It doesn't set a particularly high floor.
I think there are concerns about the transfer of data into a jurisdiction, notably the United States, where some of those safeguards may not be as strong with respect to privacy. There are questions about the ability of our own Privacy Commissioner to ensure that Canadian privacy rules will be applicable, as well as real doubts among many Canadians about whether their personal information will be appropriately safeguarded in that kind of environment.
