Evidence of meeting #37 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

West  Associate Professor, As an Individual
Darcy Fleury  Chief of Police, Thunder Bay Police Service
Myron Demkiw  Chief of Police, Toronto Police Service
Diab  Professor, Faculty of Law, Thompson Rivers University, As an Individual
Geist  Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual
Fraser  Partner, McInnes Cooper, As an Individual
St-Germain  General Counsel, Canadian Centre for Child Protection
Pierce  Vice-President, Government Relations, Canadian Chamber of Commerce
Beth Moellenkamp  Chief Executive Officer, Peel Children's Aid Society
Curran  Head of Public Policy, Meta Platforms Inc.
Marie Deschamps  Chair, National Security and Intelligence Review Agency
Simon Noël  Intelligence Commissioner, Office of the Intelligence Commissioner
Greene  Director, Privacy and Public Policy, Meta Platforms Inc.

5 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

We have a point of order.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

I think the majority of people are not wearing earpieces for interpretation. It's very difficult for me today, because all the discussions are in English. I can't work without interpretation. I'm a big fan of Mr. Housefather, but he speaks very fast.

Could he slow down so I can follow his questions?

I'm sure they'll be good questions.

5 p.m.

Liberal

Anthony Housefather Liberal Mount Royal, QC

Absolutely, I will speak more slowly.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you, Mr. Housefather.

An hon. member

There go your 10 seconds.

5 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

Thank you, Mr. Housefather.

5 p.m.

Liberal

Anthony Housefather Liberal Mount Royal, QC

I'll speak more slowly.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

I don't want to take time away from you.

5 p.m.

Liberal

Anthony Housefather Liberal Mount Royal, QC

Again, thank you all for being here.

I think we have a general tension in this law, as you've rightly pointed out, between the goal to be as safe as possible and the goal to respect privacy rights. We have to find the middle, where most people are comfortable. I don't think we'll ever find a situation where everybody agrees on the details of the bill, but I think we have to try to find that reasonable point.

We start from a premise that the bill is laudable in that it deals with some of the flaws in Bill C-2. The bill is really needed, in terms of law enforcement having access to information that technologically isn't dealt with under current law, but as everybody here said, there are concerns you have expressed.

I've noted a real discomfort with the idea of regulations. I would point out that there's a suspicion as to what's going to be in the regulations, and then we're hearing hypotheticals of what might be in the regulations or how orders might be used. Some people will trust the government and say that it will act reasonably, that the charter still applies and that there's still judicial oversight. Other people say that they won't trust it unless it's written in the bill. I get all that.

I also expressed concern about the interplay between systemic vulnerabilities and the orders. The way I read the bill, the company is exempt from having to do it if it creates a systemic vulnerability. I understand that we might need to look at the definition of systemic vulnerability. However, in an order, the company's obliged to carry out the order.

Mr. Geist, you talked about that issue. Could you express the way you would amend the bill to deal with that?

5 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

I would highlight a couple of things.

First, it is essential that we get greater specificity around this issue, with more clarity around that definition. Many have expressed concern about what this could mean and the implications. This is serious in terms of what it means for our cybersecurity and for people's privacy, so I think we owe it to everyone to ensure that it becomes clearer.

Respectfully, I think there is good reason for people to listen to the debate and think that, in fact, some of those concerns are warranted. For example, during the House debate, I heard the Secretary of State for Combatting Crime talk about this being a first step. I walked into the hearing just before that, and the police officers were talking about wanting metadata for two or three years. Is that the next step—beginning to expand this into multiple years? I don't know, but there are real concerns.

In answer to your question, we need far more specificity around the definition to make very clear that this is not touching encryption and that there will be no orders that will create systemic weaknesses. That's a clear starting point.

Anthony Housefather Liberal Mount Royal, QC

Basically, though, it's saying that proposed sections 5 and 7 are subject to proposed section 10. I also understand adjusting the definition of “systemic vulnerability”.

5:05 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

Yes, that was my other element. There were two: the definition and then this inconsistency we have in the bill that talks about, on the one hand, the ability to raise concerns, but on the other hand, language that suggests you have no real ability to challenge or to at least avoid an order.

Anthony Housefather Liberal Mount Royal, QC

That one, I'm very sympathetic to.

I want to mention something, because I have less agreement with raising the grounds to “reasonable belief” from “reasonable grounds to suspect”. I wanted to point out that the “Conditions for making [the] demand” say:

(2) The peace officer or public officer may make the demand only if they have reasonable grounds to suspect that

(a) an offence has been or will be committed under this Act or any other Act of Parliament; and

(b) the confirmation that is demanded will assist in the investigation of the offence.

I think the combination there does create a situation where there is a reasonable burden, determined by the totality of the circumstances, that makes that threshold to be relatively reasonable in this context.

I understand, though, the idea of limiting what the production order could deal with, but should we do that, should it be, for example, this person's name and this person's address—all the stuff you used to be able to read in the telephone book—and not necessarily every particular service a person had, for example? Would you then agree that was a reasonable threshold? Yes?

That's for you, Professor Diab. I've already asked Mr. Geist this question.

5:05 p.m.

Professor, Faculty of Law, Thompson Rivers University, As an Individual

Robert Diab

Thank you for the question.

I think there are two parts to this.

First of all, on the language you cited at the opening, the preamble, that's standard language. When it's challenged and courts are assessing whether it's a reasonable law under proposed section 8, they are going to be looking at the scope of it in addition to the grounds. One part of the whole question is this: Is “reasonable” suspicion too low even for just the name and address of the subscriber? That's one question left open in the wake of Spencer.

To reiterate a point that Professor Geist made just a couple of minutes ago, in Spencer the court said that we have a “high” privacy interest in the name attached to our subscriber information, because it ties us to a whole search history. It's a high interest. The court didn't say this. It was intimating that probably nothing less than a warrant on probable grounds would be reasonable, but it wasn't asked that question and it didn't have to answer—

5:05 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

I'm sorry, Professor Diab, but I have to cut you off there.

Mrs. DeBellefeuille, you have the floor for six minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you, Mr. Chair.

Dr. Geist, you told us that retaining metadata for one year was too long and that 30 days would be a reasonable period. You specified that, if there is reasonable suspicion that there are criminal grounds, a warrant must be obtained to extend the retention period.

Did I understand your recommendation on this correctly?

5:05 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

Yes. That was what I was suggesting.

In a sense, what I was trying to put forward is that there is always the ability for law enforcement, if it needs this information as part of an ongoing lengthy investigation, to seek the necessary order to have it preserved. The issue that law enforcement I think has identified in this context is that you don't know what you don't know in some circumstances, so you don't know that you might need it. There is this desire to build this giant haystack of information, because maybe you will need the needle at one point in time.

It seems to me that, of course, the haystack is comprised of people who have done no wrong. They're suspicionless. It raises for them real privacy-related concerns. Is there some kind of mechanism that we can find, in the spirit of trying to address law enforcement's concerns, that will allow, on a rolling basis, some of this information to be retained but quickly discarded after an appropriate period?

I heard in the last panel, I think, one of the members of law enforcement who was asked for a use case and talked about a missing person. Wouldn't it be good to be able to get that information? Respectfully, you don't need to retain everybody's metadata for a year for someone who's gone missing. I would think, frankly, that 30 days is more than enough to realize that the person is missing. Then, if there is a need to try to obtain other metadata, you can get the order to get it.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you for your answer, Dr. Geist. That's pretty clear.

You know that Bill C‑22 is important to us here. We all made a commitment to collaborate and, above all, to improve it. So if you have an amendment to propose or specific feedback to offer to improve it, I invite you to share it with us. All your suggestions are welcome, especially if you provide them in both official languages. They will be promptly forwarded to committee members.

Now, I'll ask you my other question.

Unless I misunderstood, I've learned that in Europe, data retention is limited to cases of serious crime, and that Europe is much more cautious when it comes to protecting privacy. In the United States, it's also not very clear whether metadata is retained for a very long period.

Do you consider that, in Bill C‑22, Canada is more intrusive than its Five Eyes partners when it comes to retaining metadata?

5:10 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

Europe has had a whole series of cases, both at the European level and at the national level amongst a number of member states, that have found some of the initiatives around mandatory metadata retention to be disproportionate. You get these cases, and countries begin to respond. It is a bit of a mix in terms of length and also under what circumstances and for what particular instances one might be able to retain that information, but it's very clear that European courts are uncomfortable with what I would characterize now as a Bill C-22–style metadata approach of retaining everything for a year. As you heard in the last panel, we don't see that retention at all in the United States. Clearly, it makes us out of step with some of those countries, but even perhaps more importantly, for the purposes of creating legislation that will sustain a potential challenge, I think it's out of step with where the charter is.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Law enforcement and government officials who have testified or approached us have told us that they want to align with the Five Eyes standards. Now, as I understand it, you're telling us that the measure providing for the collection and retention of data for one year is stricter and more demanding than what we see in the Five Eyes countries, and even more so compared to Europe.

Did I understand correctly, Dr. Geist?

5:10 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

You can find examples where it's consistent, or otherwise. Again, we heard just before the talk about a lot of north-south-related issues with respect to crime. In the United States, we don't see these metadata requirements. In many European countries, we don't either. Canada would certainly be open to creating a system either without this at all or, if it did, for a very short period of time, working in conjunction with the ability to get quick-freeze orders to ensure you could retain it for longer periods. I see little reason to think that would not be viewed as doing our part as compared to our allies.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Dr. Geist, why do you think the government wants to give itself a great deal of regulatory flexibility in its definition of electronic service providers?

Why do you think it wants to retain this power?

5:10 p.m.

Canada Research Chair in Internet and E-Commerce Law, Professor of Law, Faculty of Law, University of Ottawa, As an Individual

Michael Geist

I wish I had a good answer. I mentioned off the top that this is an issue I've been focused on for decades now. My experience is that governments from both parties, whoever is in power, when working with law enforcement to flesh this out—

5:15 p.m.

Conservative

The Vice-Chair Conservative Frank Caputo

I'm sorry, Mrs. DeBellefeuille and Dr. Geist.

The time is done.

Ms. Kirkland, your time begins now, for five minutes, please.

Rhonda Kirkland Conservative Oshawa, ON

Thank you, Mr. Chair.

Mr. Fraser, I appreciate your being here today. My questions will start with you.

Let me start with the difference between what's intended and what's allowable. I think most Canadians would not argue with the intention of this bill. Many times when we ask questions of the department, of both Justice and Public Safety, they rely on the statement, “Well, that's not the intention of this bill.” My concern is more about this: What does it allow versus what does the bill intend?

Yesterday, Public Safety Canada, on the social media platform X, posted this: “Fact or Fiction? Bill C-22 will require electronic service providers to create backdoors to their systems.

“Fiction! C-22 would not require backdoors.”

You responded on X, saying this: “Fact: There is nothing in Bill C-22 that would prevent the ordering of backdoors given the enormous powers granted under s. 5 and s. 7.”

Could you elaborate on that concern for the committee?