Thank you, Mr. Chair.
Good evening, and thank you for the opportunity to appear before the committee today. My name is Rachel Curran. I'm head of public policy for Canada at Meta. Joining me is my colleague Robyn Greene, who is an expert in the subject matter under consideration. Please direct your technical questions to her.
Meta is deeply committed to keeping our Canadian users safe online and off-line. We routinely engage with Canadian law enforcement agencies at all levels of government, including by proactively reporting threats we identify or by responding to valid legal demands and emergency requests from Canadian authorities.
We commend the government for addressing many of the concerns that were raised about part 14 of Bill C-2. With narrowly tailored amendments, we think the current part 1 of Bill C-22 would provide law enforcement with an effective legal framework for obtaining the necessary data in a timely manner. However, part 2 is a different story and could ultimately make Canadians less safe, not more.
First, the technical assistance obligations in part 2 could conscript private companies into service as an arm of the government’s surveillance apparatus. As drafted, the bill could require companies like Meta to build or maintain capabilities that break or undermine encryption and force providers to install government spyware directly on their systems.
The bill purports to protect against risks to encryption by allowing providers to challenge demands that would introduce a “systemic vulnerability”. However the definition of “systemic vulnerability” is unclear. Essential terms like “encryption” are left to be defined in regulation, while ministerial orders can override those same regulations. Moreover, the bill contains no process for challenging a problematic order, or liability protections for companies while a challenge is pending.
The technical community's consensus on this is clear. It is not possible to build back doors to encrypted systems for law enforcement without creating vulnerabilities that will be—not could be, but will be—exploited by malicious actors. Weakening encryption does not just affect the target of an investigation. It affects every Canadian who depends on secure private communications to do banking, access health care, run a business or simply talk to their family.
This is not a hypothetical risk. Governments around the world are still dealing with a fallout from China's state-sponsored Salt Typhoon cyber-attacks, which exploited the U.S.'s far narrower technical assistance laws. Canada's own security agencies understand this and issued guidance that specifically advised adopting encryption to defend against these kinds of cyber-attacks.
Part 2 of Bill C-22 would move Canada in the opposite direction and out of step with our closest allies. Last year, France and Sweden both abandoned similar proposals, and the EU guaranteed robust encryption protections in its agreement on online safety. The U.K.'s use of a similar authority ordering Apple to break its encrypted cloud service drew condemnation from the U.S. government and 200 global civil society organizations, and ultimately resulted in Apple withdrawing its advanced data protection service.
Imposing these obligations would also chill domestic innovation and investment and harm Canadian competitiveness abroad.
In addition, overly broad non-disclosure orders in part 2 risk undermining public trust and transparency. The bill's data retention provisions would create a framework to capture the private information of ordinary Canadians with no connection to any crime, and also grant warrantees the authority to search company premises and seize data.
In light of these significant challenges, we urge policy-makers to separate part 2 from Bill C-22 so that these critically important issues receive the time and attention they deserve.
To avoid the worst privacy and security outcomes, required changes include removing obligations for companies to add government or third party surveillance tools or other software to their systems, and strengthening the definition of “systemic vulnerability” to explicitly rule out any requirement that would weaken or break encryption, and codify the process for companies to challenge requests.
Thank you, Mr. Chair.
