Distinguished committee members, thank you for the opportunity to comment on Bill C-22.
Today, virtually every serious criminal investigation has a digital component. Organized crime groups, child predators, fraudsters, violent offenders and extremists rely on encrypted communications, digital platforms, anonymized tools and forum-based services to coordinate criminal activity, evade detection, frustrate prosecution and ultimately victimize innocent Canadians. Criminals are leveraging digital infrastructure and encryption, while the police are hindered by outdated legislation that does not prioritize public safety.
Bill C-22 is not about expanding unchecked police powers. It's about ensuring that judicially authorized investigations can function effectively in a complex and ever-changing digital environment. To the benefit of bad actors, too often debates on lawful access focus exclusively on privacy interests of suspects and the financial interests of big tech, while overlooking the rights of victims to safety, justice and timely intervention.
The police are not asking for, nor does Bill C-22 authorize, broad surveillance. It does not permit warrantless interception of communication. It does not eliminate judicial oversight. It does not provide unrestricted access to browser history or to social media content. The legislation preserves charter protections and maintains judicial authorization requirements for advanced investigative techniques.
Bill C-22 also addresses practical investigative steps. For example, it creates confidential confirmation of the service process with a simple yes or no so that investigators can determine which telecommunication provider actually holds relevant records before spending valuable time seeking judicial authorizations for records that simply may not exist. It creates a production order process for basic subscriber information based on reasonable suspicion, allowing investigators to advance early-stage investigations. It also addresses delays involving foreign-held evidence for cases in which investigators currently rely on mutual legal assistance processes that take many months, often while evidence disappears. In fact, Bill C-22 provides clear statutory rules in areas where courts, providers and investigators currently face inconsistent interpretations and legal uncertainty.
Bill C-22 prevents the harbouring of criminals by setting out the requirement for electronic service providers to develop and maintain systems capable of providing police with communication and information that they are legally authorized to obtain and that they require to advance criminal investigations.
It's important to note that Bill C-22 is not a surveillance tool; it's a lawful access framework. Metadata would be retained for a maximum of one year, including information such as date, time, duration and origin of transmission. It's critical to note that there will be no obligation to retain content such as emails, web browsing history or social media activities.
Furthermore, retention does not equal access. Judicial authorization will still be required. Metadata is the bare minimum of information that could assist investigators in complex investigations, such as those for homicides, international child sexual exploitation, extortion, cross-border auto theft, human trafficking and the smuggling of drugs and firearms. These types of crimes can far exceed a one-year investigation period that can involve the need for lawful access.
Absent reasonable suspicion of criminal activity, police will not and cannot judicially seek and lawfully obtain communication metadata about a private citizen of Canada going about their daily activities. Additionally, there are other safeguards built into the bill. Regulations made by the Governor in Council must consider privacy and cybersecurity implications, feasibility, cost to providers and impacts to customers, and the intelligence commissioner must approve orders prior to their issuance on an electronic service provider.
Bill C-22 also prevents any requirement that would cause an electronic service provider to introduce a systemic vulnerability, defined in the bill as “a substantial risk that secure information could be accessed by a person who does not have any right or authority to do so.”
Frankly, from a law enforcement perspective, the concerns by some major telecommunication companies and special interest privacy advocates about encryption and cybersecurity are overstated. The legislation as written does not compel companies to weaken encryption or create vulnerabilities; rather, under a legislative framework, it ensures that electronic service providers are not serving as a safe haven for criminal and terrorist-related activity and compromising public safety locally, nationally and internationally.
