Evidence of meeting #37 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

West  Associate Professor, As an Individual
Darcy Fleury  Chief of Police, Thunder Bay Police Service
Myron Demkiw  Chief of Police, Toronto Police Service
Diab  Professor, Faculty of Law, Thompson Rivers University, As an Individual
Geist  Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual
Fraser  Partner, McInnes Cooper, As an Individual
St-Germain  General Counsel, Canadian Centre for Child Protection
Pierce  Vice-President, Government Relations, Canadian Chamber of Commerce
Beth Moellenkamp  Chief Executive Officer, Peel Children's Aid Society
Curran  Head of Public Policy, Meta Platforms Inc.
Marie Deschamps  Chair, National Security and Intelligence Review Agency
Simon Noël  Intelligence Commissioner, Office of the Intelligence Commissioner
Greene  Director, Privacy and Public Policy, Meta Platforms Inc.

4:35 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Thank you, all, for being here again for the second hour.

We have two witnesses here in person and one appearing by video conference. I understand that Mr. Fraser, who is on video, has been sound checked.

Thank you for appearing.

We also have Dr. Robert Diab from Thompson Rivers University.

Lastly, we have Dr. Michael Geist from the University of Ottawa.

Professor Diab, could you please go ahead with your five-minute opening statement?

Robert Diab Professor, Faculty of Law, Thompson Rivers University, As an Individual

Thank you, Mr. Chair and members of the committee, for the invitation to appear today.

I'm a professor in the faculty of law at Thompson Rivers University, and my area of specialty is section 8 of the charter, which protects against “unreasonable search or seizure”.

I want to begin by acknowledging that Bill C-22 marks a meaningful improvement over its predecessor, Bill C-2. Several of the powers in the bill have been more appropriately tailored—

4:35 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Wait one moment, please, Professor Diab.

I understand we're having some difficulties.

Anthony Housefather Liberal Mount Royal, QC

I'm just wondering if Professor Diab might be able to speak up, because I'm having trouble hearing him.

4:40 p.m.

Professor, Faculty of Law, Thompson Rivers University, As an Individual

Robert Diab

Okay, thank you. I'll try.

Anthony Housefather Liberal Mount Royal, QC

Thank you, Mr. Chair.

4:40 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Thank you.

4:40 p.m.

Professor, Faculty of Law, Thompson Rivers University, As an Individual

Robert Diab

Several of the powers in the bill have been more appropriately tailored to the needs of law enforcement and to the privacy interests at stake, but I would like to highlight and briefly walk the committee through what I believe are three significant weaknesses with the bill that remain.

The first is the new production orders for subscriber information to be added to the Criminal Code. The government's charter statement defends this power on the basis that subscriber info is not particularly sensitive, since it reveals only the name and address of a person obtaining a service from an entity like Rogers, but the power as drafted would disclose much more than this. Police can obtain not only a name and address tied to an account, but also the types of services a person subscribes to, the tiers or channels associated with those services and the identifiers of every device associated with the account.

It also applies to any person who provides a service, not just companies like Rogers. All of this certainly allows for capturing sensitive information like, for example, what cable packages a person subscribes to or what medical services they receive. A power to obtain this shouldn't rest on reasonable suspicion alone. The scope of the power should be narrowed. As it stands, I think it would likely be struck down under section 8.

A second concern I would like to raise is the definition of “systemic vulnerability”. I understand that Professor West dealt with this earlier, but I'll try to target my remarks here. There is a definition, and that's good, but it remains too narrow in two ways.

The test for what constitutes a vulnerability here is defined to be one “that creates a substantial risk that secure information could be accessed by a person” without authorization. That's too high a threshold. Developments with AI in recent weeks reveal its far greater power for hacking, so even a remote or theoretical vulnerability now could be readily exploited.

The definition also applies only to vulnerabilities in the electronic protections of an electronic service. It may not extend the definition to the operating systems of devices, so a ministerial order could, in principle, require Apple or Google to build extraction capabilities into an operating system without engaging the safeguard, even if the practical effect would be to undermine end-to-end encryption.

The third concern with the bill is, in my view, the most serious, which is the metadata preservation power that the committee spent time on a few minutes ago. This would require core providers to retain transmission data for every communication for up to a year. That's when and where we used our phones and the coordinates of who we were in touch with, when and where.

The charter statement doesn't address this at all. Its position appears to be that compelling a provider to preserve metadata is not itself an interference with privacy, because police still need a warrant or other authority to access the data. It implies that it is not a seizure and does not engage section 8, but this is not so.

We know from ample case law that metadata is private, and under these provisions, when the minister compels Shaw or Telus to preserve our metadata, the company is doing so on behalf of the state and for a law enforcement purpose. Those are the basic elements of a seizure under section 8.

It's worth noting that Parliament assumed precisely this 12 years ago when it added to the Criminal Code the power to make a preservation demand or order, which requires individualized suspicion, reasonable suspicion or a warrant, depending on the case. This is key: It makes it a criminal offence to hold data, if you're Shaw or Telus, etc., beyond whatever the period at issue is. Why would Parliament have assumed authority was needed to preserve data if it didn't engage section 8?

Nothing here changes, in my view, in light of the fact that police are saying they won't look at it unless they go get a warrant. That's also true right now. In order to see the things they demand to be preserved, they need a warrant, but even preserving it is—

4:40 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Thank you, Professor Diab.

In Parliament, we're used to it going down, so I apologize for cutting you off.

I would like to welcome MPs Kayabaga and Baber to the table as well.

Dr. Geist, please go ahead with your five-minute opening statement.

Michael Geist Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Good afternoon, everyone. Thank you for the invitation.

My name, as you heard, is Michael Geist. I'm a law professor at the University of Ottawa, where I hold the Canada research chair in Internet and e-commerce law. I appear in a personal capacity, representing only my own views.

In preparation for today's hearing, I looked back at the history of my engagement with lawful access policy. I found that I wrote my first op-ed on the issue more than 20 years ago, and first began appearing before committees, about various bills, a few years after that.

As I'm sure you know, lawful access has been the subject of legislative debate in Canada for decades, under both Liberal and Conservative governments. The technologies change and the governments may change, but the challenge has always been the same: to give law enforcement and security agencies the tools they need to address serious crime while respecting Canadians' privacy rights and the constitutional framework the Supreme Court has built around privacy in decisions such as Spencer and Bykovets.

Bill C-2 is what happens when the balance is not well struck, as its warrantless information demand power envisioned compelling disclosure of subscriber information, of any provider of a service in Canada, without court oversight. The decision to drop that power was the right one, and replacing it with a confirmation of service demand is a meaningful change. Bill C-22, nevertheless, contains some serious problems, and I'll focus on three. They're going to echo what we just heard from Professor Diab.

First, I'm going to focus on the mandatory metadata retention regime, which would require providers to retain metadata for up to a year on every subscriber, regardless of suspicion. On a mobile network, that data includes cell towers each phone connects to. When retained at scale, the aggregate amounts to a comprehensive surveillance map of virtually every Canadian, where and when they go, and who they interact with. This is the kind of bulk data retention regime that the Court of Justice of the European Union struck down in the Digital Rights Ireland case, and in the Tele2 Sverige case extended to mandated private sector retention of traffic and location data. Germany's Federal Constitutional Court has reached similar conclusions, yet, remarkably, the charter statement about Bill C-22 fails to address the regime, despite the obvious charter implications.

The committee is being asked to entrench a surveillance architecture and accept the security risks that come with it. The obvious approach is to remove this entirely, as it is disproportionate and, I believe, likely to be struck down in its current form by the Supreme Court. Alternatively, perhaps a 30-day cap on metadata retention would suffice in terms of meeting the immediate investigative needs, while allowing for a court order if a longer period is required.

The second concern involves systemic vulnerability safeguards in the technical capability provisions. Proposed sections 5 and 7 of the SAAIA—that's part 2—say providers are not required to comply with an order if doing so would create a “systemic vulnerability”. Proposed sections 12 and 13 make compliance unconditional and provide that orders prevail over inconsistent regulations. That leaves a safeguard that exists in name only, largely cloaked in secrecy, with the burden of invoking it falling on the providers. The consequence is a backdoor capability mandate that could weaken encryption, place user data at risk and lead companies to remove privacy-enhancing services from Canada.

This needs a fix, which should include amending proposed section 12 to make compliance subject to the provisions of proposed sections 5 and 7. Further, the definition of “systemic vulnerability” should be expanded by the statute, clarifying that there will be no requirement to weaken or break encryption or to introduce any security weakness.

The third concern is the production order threshold for subscriber information. Bill C-22 sets the standard at “reasonable grounds to suspect” rather than the current “reasonable grounds to believe”. The Spencer and Bykovets decisions establish a high informational privacy interest in subscriber data, yet the charter statement nevertheless asserts that the “subscriber information sought does not, by itself, constitute particularly sensitive information”. I think that sentence is difficult to reconcile, both with Supreme Court jurisprudence and the technical reality of what subscriber information may reveal. Setting the bar lower invites further charter litigation, placing the provision on shaky legal ground.

Now, none of the changes that I've discussed here would be incompatible with effective law enforcement tools. Rather, they're about ensuring a framework that can withstand charter scrutiny, respect Canadians' privacy rights, avoid creating a surveillance infrastructure and sustain public interest and confidence.

I look forward to your questions.

4:50 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Thank you, Dr. Geist.

Now we move to Mr. Fraser for five minutes.

David Fraser Partner, McInnes Cooper, As an Individual

Mr. Chairman and honourable members, thank you very much for the kind invitation to share my views on Bill C-22.

I'm a partner at the law firm McInnes Cooper in Halifax, where, among other things, I advise clients who are on the receiving end of orders for customer information. I also teach at the Dalhousie law school. I'm appearing in my personal capacity with my own views, and I'm not speaking on behalf of any of my clients.

I have to commend the government for its comprehensive consultation with stakeholders since Bill C-2, to which I contributed, but I still have a number of concerns and recommendations. I'll note that, in particular, part 2 of Bill C-22 is very problematic. I can't cover all my concerns in five minutes, so I look forward to the rest of our discussion.

First, I agree with my colleagues. We need to narrow the scope of subscriber information production orders or raise the bar up to reasonable belief. The bill lowers the threshold for police to obtain a production order for subscriber information—which they can get today—from “reasonable grounds to believe” to merely “reasonable grounds to suspect”.

The organizations that could be on the receiving end of these orders are any that provide services to the public, which include banks, hospitals, grocery stores and hotels. We're well beyond telcos here. Even though the definition is narrowed from ones in previous bills, police could still demand all the subscriber information that a service provider holds. This would go beyond name and address, as my colleagues pointed out. It would include the types of services provided and device identifiers, like the serial number of the CPAP machine from your doctor's office. It would compel Apple to hand over the digital IDs of every single device you have, including your AirTags and iPads. That's too much. I suggest narrowing the scope of these orders or raising the bar to reasonable belief. Otherwise, it will ultimately be found to have violated the charter.

I'll move on to part 2, the supporting authorized access to information act.

Nobody has made a compelling case for anything in part 2. The government has had 20-plus years to build its case, but, as NSICOP observed, it has only anecdotes. We should not be undermining the privacy and safety of every single Canadian based on anecdotes.

Part 2 of the bill targets electronic service providers, but the definition is so broad that it would likely include most businesses in Canada. Everybody deals with digital information. If it proceeds, the bill should include necessary guardrails. Under no circumstances should the government be allowed to require—particularly with a secret order—an electronic service provider to make changes to products or services it provides in the ordinary course, to collect and retain any data beyond what the business requires for its own purposes or to make any changes that would affect functionality, including adding additional functionality for any products or services offered by the business. As the bill is written, the Minister of Public Safety could issue a secret order to turn your Amazon Alexa into a listening device, as in an example given by the previous panel. CSIS has explicitly said, in connection with this bill, that it wants to be able to track every single cell phone in Canada in real time, and that telcos would have to change their services to make every cell phone trackable. That would be disproportionate and, in my view, absurd.

Now, the government says that it doesn't plan to undermine encryption and that there would be no back doors, but you just have to read the words in the bill to see that there's nothing to prevent this. Government officials said at this committee—I think it was on Tuesday—that the bill is “encryption-neutral”, but Canadians are not encryption-neutral. The words of the bill would clearly permit, and certainly would not prohibit, back doors and mandatory decryption. That would be in secret, with no transparency to Canadians and with very little accountability. What the government intends is not relevant. What is relevant is what words end up in the statutes.

Under part 2, the Minister of Public Safety could issue these secret orders to electronic service providers—very broadly defined—that come with mandatory permanent secrecy. Currently, the police and CSIS can apply to a judge for something called an assistance order. This orders a service provider to provide all reasonable assistance to give effect to a judicial warrant. It can be accompanied by a gag order if it's appropriate. That is judicial control. Nobody from law enforcement has offered evidence that assistance orders are inadequate or should be replaced by these secret ministerial orders. The U.K. equivalent of a ministerial order was used by the U.K. government to secretly order Apple to remove encryption on iCloud, globally. Part 2 of Bill C-22 does not contain any guardrails that would prevent such overreach in Canada. Secret ministerial orders have to go.

We also have the issue of metadata retention, which my colleagues already spoke about. This would include your location history. The government could require everyone's cell phone to become a retrospective tracking device going back a full year, without any suspicion of wrongdoing. This will almost certainly be found to have violated the charter. Collected metadata would be sought by Canadian and non-Canadian authorities based on mere suspicion. That would be a record of everyone who sought reproductive health care in Canada, which might be of interest to law enforcement in a Five Eyes partner.

Finally, as legions of cybersecurity experts—

4:55 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

I'm sorry, Mr. Fraser. We will have to stop there. I apologize.

4:55 p.m.

Partner, McInnes Cooper, As an Individual

David Fraser

Thank you.

4:55 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

As chair, I will be leading off this round for six minutes.

I want to thank all of the witnesses. We have a very academic panel this time. I'm very humbled by the three of you coming to spend your time with us today, and what do you know? We're all lawyers here. That's wonderful.

Professor Diab, it's particularly great to have you here as a colleague with whom I dealt at the bar in British Columbia in my time as a prosecutor and also in my time teaching advanced criminal law and sentencing at Thompson Rivers University. I know that everybody's very proud to have you here, so thank you for being here.

With that, I want to expand a little on the question of engagement in section 8 when it comes to the requirement of a third party to retain data. Is there a specific case you're relying on there, Professor?

4:55 p.m.

Professor, Faculty of Law, Thompson Rivers University, As an Individual

Robert Diab

No, I'm just relying on the broad propositions under section 8. Section 8 is engaged whenever a state actor interferes with something over which we have a reasonable privacy interest, so I gather that the question you're asking is about a mere demand by a state agent of a third party to hold on to the private data that belongs to the person over there. Is that an interference with their privacy? Again, 12 years ago, Parliament assumed that, if a court were to look at that, they would find that it would be an interference with their privacy.

In other words, I can't think of a body of case law where police told third parties to preserve data and then it was challenged in courts. I can't think of that. The story for me begins with the power, the preservation power, and when that was added to the code, it was added, I'm assuming, on the premise that requiring a third party to do this for the state for a law enforcement purpose is an interference that engages section 8.

Once again, stand back and ask yourself how you would feel if you were told that Telus, Rogers, etc. are preserving a record of all your movements and the people to whom you sent emails, not the content but those details? How would you feel? They're preserving it for up to a year for the purpose of potentially prosecuting you if necessary.

Maybe one answer is that it's absolutely fine, but I think most Canadians and, I think, courts are likely to say no. They would think that the mere fact that I was visiting this person on this day or talked to this person is private. That should be private. There should be no record kept of it, and that is, I think, the best explanation I can give you as to why.

4:55 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Thank you.

I would like to ask the two professors who are here in person about the reasonable grounds to suspect versus reasonable grounds to believe. It's been a while since I dealt with reasonable grounds to suspect, but my recollection of reasonable grounds to believe is that there has to be a subjective belief, as in you have to personally believe that an offence has been committed, and that belief must be objectively reasonable. That's my recollection. In other words, a reasonable person would say, “Yes, you have a reasonable belief.”

It's below balance of probabilities, so it's not ultrahigh. It's less than 50%, but above the suspect, which is more than a hunch but less than that.

What would you say to the proposition that this is asking for very narrow data and, therefore, we don't have to worry as much that this could be saved under section 1?

Would you agree with that, Professor Geist?

4:55 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

No, I wouldn't, and I wouldn't in two respects.

First, the consistent claim that this data is of low privacy value, I think, is simply inaccurate. We just heard examples from Professor Diab and, perhaps, over the course of the next little bit, we'll have a chance to walk through some of those kinds of examples, but it seems to me that, even with the question that came up towards the very end of your last panel about whether or not someone might know that you asked Siri something, the question isn't the content. The fact is that you raised it and engaged with people. The fact is that members of the public engage with you, and a record would exist of who you communicate with. The fact that there might be orders to have that kind of thing disclosed raises, from my perspective, significant issues.

This may have significant privacy import, so lowering the standard for this information, when there is scant evidence that the higher standard that we've had in place for many years now has posed a problem, seems to me unwarranted.

5 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

I see.

To Mr. Fraser online, I mentioned at the last meeting, when I wasn't the chair, that this is a highly technical bill. We had only one hour with the officials.

I wanted to address one thing you brought up to this committee. You talked about CSIS wanting to have real-time access. I think the committee may want to ask CSIS about that.

For our reference and for our analysts, can you tell us where you got that point, please, in 25 seconds or less?

5 p.m.

Partner, McInnes Cooper, As an Individual

David Fraser

Absolutely. It was mentioned during the technical briefing when the bill was tabled. It was mentioned for Bill C-2 and again for Bill C-22. I have a copy of the slide deck that includes the illustration, if you'd like it.

5 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

I'm sure we have that.

I have 10 seconds left, but we are a bit behind schedule, so we will now go to Mr. Housefather.

Thank you.

5 p.m.

Liberal

Anthony Housefather Liberal Mount Royal, QC

Thank you, Mr. Chair. Ceding those 10 seconds will make a difference, for sure, as to when we end this meeting.

Some hon. members

Oh, oh!

5 p.m.

Liberal

Anthony Housefather Liberal Mount Royal, QC

It's a pleasure to welcome all the witnesses.

With all of the different witness panels, we see a general tension between—

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

On a point of order.