Good afternoon, everyone. Thank you for the invitation.
My name, as you heard, is Michael Geist. I'm a law professor at the University of Ottawa, where I hold the Canada research chair in Internet and e-commerce law. I appear in a personal capacity, representing only my own views.
In preparation for today's hearing, I looked back at the history of my engagement with lawful access policy. I found that I wrote my first op-ed on the issue more than 20 years ago, and first began appearing before committees, about various bills, a few years after that.
As I'm sure you know, lawful access has been the subject of legislative debate in Canada for decades, under both Liberal and Conservative governments. The technologies change and the governments may change, but the challenge has always been the same: to give law enforcement and security agencies the tools they need to address serious crime while respecting Canadians' privacy rights and the constitutional framework the Supreme Court has built around privacy in decisions such as Spencer and Bykovets.
Bill C-2 is what happens when the balance is not well struck, as its warrantless information demand power envisioned compelling disclosure of subscriber information, of any provider of a service in Canada, without court oversight. The decision to drop that power was the right one, and replacing it with a confirmation of service demand is a meaningful change. Bill C-22, nevertheless, contains some serious problems, and I'll focus on three. They're going to echo what we just heard from Professor Diab.
First, I'm going to focus on the mandatory metadata retention regime, which would require providers to retain metadata for up to a year on every subscriber, regardless of suspicion. On a mobile network, that data includes cell towers each phone connects to. When retained at scale, the aggregate amounts to a comprehensive surveillance map of virtually every Canadian, where and when they go, and who they interact with. This is the kind of bulk data retention regime that the Court of Justice of the European Union struck down in the Digital Rights Ireland case, and in the Tele2 Sverige case extended to mandated private sector retention of traffic and location data. Germany's Federal Constitutional Court has reached similar conclusions, yet, remarkably, the charter statement about Bill C-22 fails to address the regime, despite the obvious charter implications.
The committee is being asked to entrench a surveillance architecture and accept the security risks that come with it. The obvious approach is to remove this entirely, as it is disproportionate and, I believe, likely to be struck down in its current form by the Supreme Court. Alternatively, perhaps a 30-day cap on metadata retention would suffice in terms of meeting the immediate investigative needs, while allowing for a court order if a longer period is required.
The second concern involves systemic vulnerability safeguards in the technical capability provisions. Proposed sections 5 and 7 of the SAAIA—that's part 2—say providers are not required to comply with an order if doing so would create a “systemic vulnerability”. Proposed sections 12 and 13 make compliance unconditional and provide that orders prevail over inconsistent regulations. That leaves a safeguard that exists in name only, largely cloaked in secrecy, with the burden of invoking it falling on the providers. The consequence is a backdoor capability mandate that could weaken encryption, place user data at risk and lead companies to remove privacy-enhancing services from Canada.
This needs a fix, which should include amending proposed section 12 to make compliance subject to the provisions of proposed sections 5 and 7. Further, the definition of “systemic vulnerability” should be expanded by the statute, clarifying that there will be no requirement to weaken or break encryption or to introduce any security weakness.
The third concern is the production order threshold for subscriber information. Bill C-22 sets the standard at “reasonable grounds to suspect” rather than the current “reasonable grounds to believe”. The Spencer and Bykovets decisions establish a high informational privacy interest in subscriber data, yet the charter statement nevertheless asserts that the “subscriber information sought does not, by itself, constitute particularly sensitive information”. I think that sentence is difficult to reconcile, both with Supreme Court jurisprudence and the technical reality of what subscriber information may reveal. Setting the bar lower invites further charter litigation, placing the provision on shaky legal ground.
Now, none of the changes that I've discussed here would be incompatible with effective law enforcement tools. Rather, they're about ensuring a framework that can withstand charter scrutiny, respect Canadians' privacy rights, avoid creating a surveillance infrastructure and sustain public interest and confidence.
I look forward to your questions.