Evidence of meeting #36 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was metadata.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

McGuire  Director General, International and Border Policy, Department of Public Safety and Emergency Preparedness
Hiegel  Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness
Ho  Director, Intelligence Policy, Department of Public Safety and Emergency Preparedness
Nashef  Director General, Canadian Security Intelligence Service
Burchill  Director General, Technical Investigation Services, Royal Canadian Mounted Police
LeBel  Counsel, Criminal Law Policy Section, Department of Justice
Gibner  Deputy Assistant Deputy Minister, Policy Sector, Department of Justice
Gary Anandasangaree  Minister of Public Safety
Sean Fraser  Minister of Justice
Giles  Deputy Director, Canadian Security Intelligence Service

4:20 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

I'll start off and then I'll flip it over to Fenton.

We've taken a look at a multitude of other countries that have this type of legislation in place and have found ways to work with companies to pull the information out so that it can be provided to investigators for their specific investigations.

I don't feel that there's necessarily a contradiction between the two parts, because we are going to set objectives. We, the government, are not going to tell companies—or core providers, essentially—what and how they need to create—

Dane Lloyd Conservative Parkland, AB

I understand what you're saying, which is that the government isn't dictating how the companies are to do it, but it is mandating the companies to do it, and in order to comply, companies may have to create vulnerabilities in their system that can be exploited by hackers. Wouldn't you agree?

4:20 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

I would say that companies create all sorts of changes within their systems for purposes that they see fit. Through this piece of legislation, we're hoping and we expect to find safe ways to maintain their cybersecurity, as Canada expects.

Canada, first and foremost, puts priority on cybersecurity—

4:20 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

I'll interrupt you there.

If it comes to a choice between a company complying with the legislation and creating a vulnerability that can be exploited by hackers, what is the end goal or outcome of the Government of Canada?

4:20 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

I think the expectation is that, in consultation with government, we will find solutions to this. It is a problem that desperately needs a solution. Working with industry to be able to get information to the investigators to investigate so many crimes that are now going unsolved—

4:25 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

If you can't find a solution, at least in the short term, is it acceptable to the government that telecommunications companies be forced to create systemic vulnerabilities in order to comply with the legislation?

4:25 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

There are partners we already work with right now, so I would question the idea that there's no way to be able to put solutions in place.

4:25 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

The Canadian Chamber of Commerce has said that this legislation is going to force their members to create vulnerabilities in their systems. That's a pretty big stakeholder, including many stakeholders that the Government of Canada works with.

This is a big concern, so I just I want it clear: If the only way to comply with this legislation is to create systemic vulnerabilities, does the government still think companies need to comply with this legislation?

4:25 p.m.

Director, Intelligence Policy, Department of Public Safety and Emergency Preparedness

Fenton Ho

We're talking about various capabilities. It's not one universal capability. Also, these capabilities already exist right now. A lot of the major telecoms, because of the licensing regime, already have the capability to address certain requests from law enforcement or CSIS, so in that case, the bill basically creates a level playing field for what exists.

However, if you're looking at a particular application, a particular capability that doesn't exist, if it hits a systemic vulnerability, the answer would be no.

4:25 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

I have 45 seconds left, so if I can get that in writing from you, please send that in writing.

In my last 45 seconds.... The Secretary of State for Combatting Crime said that many stakeholders are calling this an essential first step and that they need to broaden this legislation. Is the Department of Public Safety working on or envisioning a follow-up piece of legislation to expand the powers given under Bill C-22 at this time?

4:25 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

No, not at this time.

4:25 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Can you say that the department has done any studies on what the next steps would be, should this legislation pass, for follow-up legislation in this area?

4:25 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

No, we are very focused on the regulatory step that would follow, if we are successful in getting royal assent.

4:25 p.m.

Conservative

Dane Lloyd Conservative Parkland, AB

Thank you.

The Chair Liberal Jean-Yves Duclos

Thank you very much, MP Lloyd.

MP Powlowski, you have five minutes, please.

Marcus Powlowski Liberal Thunder Bay—Rainy River, ON

I have a letter before me entitled “Joint Call for the Withdrawal of Bill C-22”, which is signed by a number of seemingly pretty reputable organizations, such as the British Columbia Civil Liberties Association, the Canadian Association of University Teachers, the Canadian Civil Liberties Association and the Canadian Council for Refugees. In it, they talk about the “enormous overreach of Bill C-22 and the unprecedented, open-ended powers it introduces”. Then it goes on.

There's one specific provision I want to ask you about, but let me read the whole paragraph. It says:

Bill C-22 makes some improvements to Bill C-2's proposal for wide-ranging warrantless access to sensitive subscriber information. The warrantless demand power can now only be used to require telecommunications service providers to confirm if someone is a customer. However, Bill C-22's approach to subscriber data remains flawed, dropping the judicial authorization standard for a warrant from “reason to believe” to the far lower “reason to suspect” threshold despite Supreme Court decisions recognizing the significant privacy interests engaged by this form of data access.

If we're worried about overreach and if we're worried—as they are—about mass surveillance of all Canadians, I would tend to agree that “reason to suspect” seems a very low threshold for accessing potentially personal data. Does somebody want to answer this accusation?

Kimberly Gibner Deputy Assistant Deputy Minister, Policy Sector, Department of Justice

I'll take that question.

I think my colleague touched on that and highlighted that there are all sorts of Criminal Code provisions that use the reasonable grounds to suspect standard. In this case, what you're looking at in terms of the subscriber information is essentially a name and an address. On the balance of that type of information with the privacy concerns, reasonable grounds to suspect was chosen as the appropriate standard.

Just to speak to your point about Spencer, what the decision said was that it was critical that there be lawful authorization, so since 2014, police have been calling for lawful authorization. That's what Bill C-22 does. It provides lawful authorization.

Marcus Powlowski Liberal Thunder Bay—Rainy River, ON

Now, for end-to-end encrypted services, like Signal, where the providers never possess the unencrypted data or decryption keys, these providers would not be expected to degrade their encryption to comply. Is that correct?

4:30 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

That is correct.

Marcus Powlowski Liberal Thunder Bay—Rainy River, ON

Okay.

Lastly, you talk about collecting metadata. What sort of metadata? If I'm on the Internet and if I'm sympathetic to the people of Gaza and searching about Gaza and inadvertently something comes up on Hamas, is there a reason for the government to further investigate me because of the possibility that I may be somehow doing things to promote a terrorist organization? What sort of metadata are you looking for? Metadata seems pretty broad. I mean, that's everything we do. If you put it into computer AI, you'd find something on Marcus Powlowski.

4:30 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

It's understandable to be concerned about that. What I would like to do is turn it over to my RCMP colleague, who, along with his team, is going to help define the very specific elements of metadata that are required. They will be regulated, but my colleague can give some specific examples.

4:30 p.m.

Director General, Technical Investigation Services, Royal Canadian Mounted Police

Richard Burchill

I can give four examples of metadata retention that are helpful for law enforcement in an investigation. One is Internet transmission data, which includes time-stamps, IP addresses and device identifiers. As you can appreciate, we don't start an investigation immediately when something happens. When something happens and there's online activity, there generally needs to be a report made and an investigation generated. If we're looking to get metadata, there has to be a judicial authorization; there's criminality involved, and there are victims involved at the front end of this. By the time we get to the point where we're seeking the metadata, it's to try to link people to places. That's Internet transmission data.

Tower signalling data is also helpful to locate folks at a point in time when there is an offence that happened or a call, if it's a kidnapping or something, where we need to find the location of somebody who had a vehicle or a phone at a certain time.

The Chair Liberal Jean-Yves Duclos

I'm sorry, but I have to interrupt you abruptly so we can move to Madame DeBellefeuille.

Mrs. DeBellefeuille, you have the floor for two and a half minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you very much, Mr. Chair.

Ms. Hiegel, Bill C‑22 still gives the intelligence commissioner an important role. Have you assessed the additional work the adoption of this bill could cause them?

4:30 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

Thank you for the question.

I apologize. I'm going to speak in English.

We actually have met with the intelligence commissioner himself and his staff to talk about the role. Once it is approved, he will be the second key. He has spoken to the fact that.... We have given some sense of what we expect and how many ministerial orders there may be on an annual basis.