Evidence of meeting #38 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Nadeau  President, Barreau du Québec
Lefebvre  Chairman and Co-founder, Crypto Québec
Dufresne  Privacy Commissioner of Canada, Offices of the Information and Privacy Commissioners of Canada
Marchand  Member, Criminal Law Expert Group, Barreau du Québec
Le Grand Alary  Lawyer, Secretariat of the Order and Legal Affairs, Barreau du Québec
Neuenschwander  Senior Director, User Privacy and Child Safety, Apple Inc.
Israel  Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association
Patell  Director, Government Affairs and Public Policy, Canada, Google
Charlet  Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google
Van Laer  Retired Staff Sergeant, Reservist, Royal Canadian Mounted Police
Thomas Carrique  President, Canadian Association of Chiefs of Police
Brown  Mayor, City of Brampton
Smith  Senior Vice-President, Canadian Telecommunications Association
Ullock  Board Chair, Ontario Child Sexual Exploitation Investigators Association
Chief Nick Milinovich  Deputy Chief of Police, Peel Regional Police
Murray Rankin  Barristor and Solicitor, As an Individual

5:25 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

I did not hear that testimony directly, but in our reading of the bill, we don't see some of those claims explicitly in the language. There's not a mention of protection of encryption, which we would support being added to the bill. In the definition of systemic risk or “systemic vulnerability”, it mentions the term but without a definition of that term.

The intentions aren't coming through clearly in the language, from our perspective. That's why, as you've mentioned, we've given a written submission and suggested amendments.

5:25 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Thank you.

You used a very important word, which is “intention”. We're often told that this bill does not intend to do X, Y or Z. I'll say again that Canadians really don't care what the bill intends to do. They care about what the bill will allow the government to access, and that's a real concern. Thank you for bringing that up.

I'll take it to Mr. Israel first, and then we'll go on to Google.

5:25 p.m.

Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association

Tamir Israel

I echo your concerns about intent versus application. It took seven or eight years before the U.K. version of this law was used to strip all people in the U.K. of a critical encryption safeguard for their Apple iCloud backup. It's not the immediate intent of the government that's relevant. It's how the bill could be applied over time.

In this instance, the bill does prohibit the imposition of systemic vulnerabilities, but that, by definition, does allow non-systemic vulnerabilities, first. Second, it leaves a lot of e-terms in the definition open to interpretation through regulation.

A big problem with the constant attempt to maintain end-to-end encryption secure is the multiple ways that governments and bad actors keep coming up with to get around encryption. Some of these mechanisms directly compromise encryption. I've seen government definitions of back doors limited to those examples, but other tools that are commonly advanced, for example, client-side scanning, which essentially places an AI tool on everybody's device that monitors their content before it's encrypted and sent onwards and has been assessed by leading security technologists around the world as creating systemic vulnerabilities, do not compromise encryption in the way that this exception would prevent. You need a comprehensive exception that rules out all back doors and all ways of bypassing encryption.

Thank you. I'm sorry for the long answer.

The Chair Liberal Jean-Yves Duclos

Thank you, Ms. Kirkland.

We'll go to MP Housefather for five minutes, please.

Anthony Housefather Liberal Mount Royal, QC

Thank you very much.

Mr. Neuenschwander from Apple and Ms. Patell from Google, I appreciate your testimony and your being here. I've read your submissions. As a general counsel for a computer company before I went into politics, I'm sympathetic to strengthening protection for encryption and clarifying the definition of “systemic vulnerability” and some of the other provisions you mentioned.

I want to respond to something Ms. Kirkland said. Authorities provisions are standard in any compliance framework. They are in many federal laws, and they don't really specifically relate to the core lawful access provisions of this bill. I just wanted to get that out.

Mr. Neuenschwander, I've read what you said. Has Apple ever gone before a parliamentary committee or made a submission to a national parliament on a lawful access regime that Apple actually supported?

May 26th, 2026 / 5:30 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

I'm more on the engineering side than our government affairs side. I'm not familiar with all of our submissions, but we are supportive of parts of Bill C-22 and modernization overall to enable law enforcement to become better and more efficient—

Anthony Housefather Liberal Mount Royal, QC

I understand that. I understand that both Apple and Google are largely supportive of the idea but have objections to specific provisions of the bill. I just wanted to establish whether you have ever seen a bill that you didn't have objections to some portions of.

I think people are overstating some of the objections. I don't disagree with some of the objections you raised, but I don't think some of the claims that are being made—for example, surveillance equipment that could be installed in devices and forcing companies, even under orders, to put in surveillance equipment—are reasonable or logical. I don't think they bear out in the wording of the bill.

What I'm asking is this: Have you guys ever gone before a committee or made a submission in the U.K., in Australia or in the U.S. and said, “Wow, we think this bill is great”?

5:30 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

As we're doing here today, we have frequently gone to engage in constructive—

Anthony Housefather Liberal Mount Royal, QC

Yes, you've gone to engage and to object to provisions in the bill, which is your job.

We as legislators have to look at it with multiple lenses. You have a specific obligation related to the company. The company's obligation is often to respect its user agreements with end-users and to do what's best in the company's interest, not necessarily in the national interest.

All I'm asking is if you have ever come to a committee and said, “The bill is great.” I doubt that you have.

5:30 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

With respect, I think we're trying here to act in the interests of users, both Canadian and worldwide, and ensure that we can provide the strongest protections possible while supporting law enforcement.

Anthony Housefather Liberal Mount Royal, QC

I don't disagree with you. I think that's part of the overall goal.

Let me also ask.... You are the chief privacy officer. You're in charge of privacy at Apple.

5:30 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

I am from the engineering standpoint, yes.

Anthony Housefather Liberal Mount Royal, QC

It's from the engineering standpoint. That's right.

You may think this is a negative question, but I don't. I think this is actually a lesson.

Has Apple ever created something that you later regretted? With respect to privacy interests, I'll give you the IDFA as an example.

5:30 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

I don't know that I would go so far.

For those less into the technology, the IDFA is an advertising identifier. I think it was appropriate for its time. What we do is we continue to evolve the protections on the privacy and security side as the world continues to change.

Anthony Housefather Liberal Mount Royal, QC

You did create something that eventually had ramifications that you and your team probably didn't even realize when you first created it. Developers actually used this to thwart what you thought would be users' preferences. I remember that.

5:30 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

I take it as a given that attacks and uses of data only increase and grow stronger over time, which is why we continue to move forward and innovate on the protection side. I wouldn't put IDFA in the class of attacks, but when we're thinking about attacks generally, we have to continually move forward to continually protect against the stronger attacks.

Anthony Housefather Liberal Mount Royal, QC

I agree, and that's why, when we look at this bill, we have to look at some of the concerns that are being raised, even if we don't necessarily think that those are likely to happen. We know that we have to provide for contingencies. We have to make sure that we avoid getting ourselves into a situation where pernicious effects could occur. I'm actually sympathizing with what you're saying, because whether it's in the bill or not, I think we want to provide for the concerns that are there.

Ms. Patell, I carefully read your submission as well. If we were able to limit the definition of “systemic vulnerability” and we were able to guarantee or make it clear that encryption was not to be broken, would those be the two major points that you would have with respect to the bill that would alleviate the concerns that Google has expressed?

5:35 p.m.

Director, Government Affairs and Public Policy, Canada, Google

Jeanette Patell

We certainly welcome all of the statements that have been made with regard to the government's intent, and specifically with regard to the desire to protect encryption. We simply want to see that reflected in the text of the bill itself.

I would point to a few other areas where we've put forward four recommended amendments. A few others relate to both the metadata retention provisions and to the sweeping nature of the ministerial orders. That's something that we believe is unprecedented and unnecessary, and we would therefore recommend the elimination of secret ministerial orders as well.

I don't know if my colleague Kate wants to weigh in as well on anything else.

Anthony Housefather Liberal Mount Royal, QC

I think the chair might not allow that since it seems as though my time is up.

The Chair Liberal Jean-Yves Duclos

I'm sorry. Unfortunately, your time is up, Mr. Housefather, so is the time for answering those great questions.

Mrs. DeBellefeuille, you have the floor for two and a half minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you, Mr. Chair.

Mr. Israel, do you share these concerns? In your view, does the bill increase the risks associated with sharing information with states that have a troubling human rights record?

5:35 p.m.

Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association

Tamir Israel

Yes, in two respects. First of all, the bill paves the way for the adoption of international information-sharing agreements, including with countries that have problematic human rights records. That's one problem.

A related problem is that the metadata retention regime has no limitations on who can access that metadata. Once it's kept, any government can force a multinational company that's active in their jurisdiction to disclose that data, which would not have been kept if the company was not forced to keep it, about people in Canada.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

In that regard, have you ever expressed your concerns to members of the government regarding the exchange of personal information with states that have a rather troubling human rights record? This is not the first time you have expressed such concerns to members of the government.

5:35 p.m.

Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association

Tamir Israel

We've expressed our concerns regarding the information agreements I mentioned. However, we were not made aware of the inclusion of the mandatory data retention regime until Bill C-22 was tabled, so we did not have a chance to mention it in advance.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

In your opinion, should we give more powers to accountability and oversight bodies to monitor government activities and better protect users’ privacy?