Evidence of meeting #38 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Nadeau  President, Barreau du Québec
Lefebvre  Chairman and Co-founder, Crypto Québec
Dufresne  Privacy Commissioner of Canada, Offices of the Information and Privacy Commissioners of Canada
Marchand  Member, Criminal Law Expert Group, Barreau du Québec
Le Grand Alary  Lawyer, Secretariat of the Order and Legal Affairs, Barreau du Québec
Neuenschwander  Senior Director, User Privacy and Child Safety, Apple Inc.
Israel  Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association
Patell  Director, Government Affairs and Public Policy, Canada, Google
Charlet  Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google
Van Laer  Retired Staff Sergeant, Reservist, Royal Canadian Mounted Police
Thomas Carrique  President, Canadian Association of Chiefs of Police
Brown  Mayor, City of Brampton
Smith  Senior Vice-President, Canadian Telecommunications Association
Ullock  Board Chair, Ontario Child Sexual Exploitation Investigators Association
Chief Nick Milinovich  Deputy Chief of Police, Peel Regional Police
Murray Rankin  Barristor and Solicitor, As an Individual

The Chair Liberal Jean-Yves Duclos

Sorry to cut you off, Mr. Ramsay, but we have to move on to Mrs.—

4:40 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

I have a point of order, please.

For a moment there, I thought it was me and the minister with Mr. Ramsay and our witness, but my point of order has to do with Mr. Lloyd's issue of privilege.

I've spoken with the clerk. I would ask that the clerk confirm on the record and that you, Mr. Chair, confirm on the record that you did not see the submission from the Privacy Commissioner, and that the clerk, to the best of his knowledge, did not forward it to you.

Is it accurate, Mr. Chair, that you did not see the submission from the Privacy Commissioner?

The Chair Liberal Jean-Yves Duclos

I appreciate your question, MP Caputo. As I said earlier, this matter of privilege deserves appropriate attention. My attention now is focused on having the witnesses provide the most from their time and their input. If you allow, I will look at this after the meeting and consider this question of privilege in the appropriate manner.

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

With the greatest of respect, Mr. Chair, we have to decide how we are going to proceed.

If you did not receive this or did receive this, that does impact things. All I'm asking of you, Mr. Chair, is for a yes or no on whether you had seen the submission from the Privacy Commissioner.

The Chair Liberal Jean-Yves Duclos

My understanding is that I did not see this email, but I want to double-check that and be certain that I provide the members of this committee with the most accurate information.

4:40 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

Thank you.

The Chair Liberal Jean-Yves Duclos

Having said that, we'll go to Madame DeBellefeuille.

Mrs. DeBellefeuille, you may go ahead for two and a half minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you, Mr. Chair.

Mr. Nadeau, my questions are along the same lines as the parliamentary secretary's, so I'm going to continue the discussion with Mr. Marchand.

Basically, if I understand correctly, the “reasonable grounds to suspect” threshold in Bill C‑22 applies to specific data that aren't considered sensitive.

You are arguing the opposite. The Minister of Justice, the justice department and department officials are saying this respects the Supreme Court's decision, but you don't seem to agree.

Can you elaborate on why you think that, to help us really understand your point?

4:40 p.m.

Member, Criminal Law Expert Group, Barreau du Québec

Michel Marchand

We don't think it respects the Supreme Court's decision at all. Proposed new section 487.0142 of the Criminal Code is very broad, referring to “all the subscriber information…including transmission data”. That can all be captured through the IP address. Furthermore, if you read the Supreme Court's decision in Bykovets—which isn't that old—properly and carefully, you see that the majority of the court viewed the IP address as a gateway.

Search and seizure doesn't work the same way anymore. Before, when police officers did a search, they showed up at the individual's home and either they found something or they didn't. Now, with the IP address, they can access just about anything about the person, medical records, what they dream about, what they post online and all kinds of other information. On top of that, the bill says that the information can be retained for a year, which is like giving authorities access to a huge data bank they can use to spy on people or find whatever information they want.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you, Mr. Marchand. I think I understand your point now. You're part of an expert group at the Quebec bar association. If a skeptical person shared that view with us, we might not believe them, but you're a very credible source, as far as I'm concerned.

I'm trying to figure out how we can make the bill better. You're recommending that we remove the “reasonable grounds to suspect” threshold.

The commissioner recommends limiting its use.

That's what I understood from your recommendations, Mr. Dufresne.

4:40 p.m.

Privacy Commissioner of Canada, Offices of the Information and Privacy Commissioners of Canada

Philippe Dufresne

Exactly. You have both options.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

To wrap up, I'd like to thank you.

The Chair Liberal Jean-Yves Duclos

Mrs. DeBellefeuille, you're out of time, so I have to stop you there, I'm afraid.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you.

You see how polite he is with me.

The Chair Liberal Jean-Yves Duclos

It saddens me to hear you say such harsh words.

I thank all the witnesses for taking the time to prepare for the meeting and for travelling here or participating via video conference.

We won't have much opportunity to bid you a warm farewell after you leave, because we must begin the second part of the meeting. So, we invite you to have a good rest of your day. Thank you.

The Chair Liberal Jean-Yves Duclos

Good morning, everyone.

We are beginning the second part of this meeting with new witnesses, whom I would like to welcome.

We are joined by Erik Neuenschwander, senior director of User Privacy and Child Safety, from Apple.

From the Canadian Civil Liberties Association, we are joined by Tamir Israel, director of the Privacy, Surveillance, and Technology Program. He is participating in the meeting via video conference.

From Google, we have Katherine Charlet, senior director, and Jeanette Patell, director of Government Affairs and Public Policy, both participating via video conference.

We will now begin the five-minute presentations.

Mr. Neuenschwander, you have the floor.

Erik Neuenschwander Senior Director, User Privacy and Child Safety, Apple Inc.

Thank you.

Good afternoon, Mr. Chair, vice-chairs and members of the committee. My name is Erik Neuenschwander, and I'm the senior director of user privacy and child safety at Apple, where I've been a software engineer for 19 years. I worked as the first data analysis engineer on the first iPhone, and I founded Apple's privacy engineering team. Today, my job is to make sure that Apple's products and services keep our users' information safe. Thank you for the opportunity to speak with you today.

As you know, this may be one of the last times we're permitted to discuss the consequences of this legislation publicly. That's because of the bill's secrecy provisions, which forbid companies like Apple from even discussing, with our users or the public, the orders we receive.

Today, I want to be clear about how we approach privacy at Apple. I want to be clear about why encryption is so important to defending the privacy and security of people in Canada and around the world.

These issues have never been more important because our world is becoming more digital by the day. As users, we depend on our technology to securely store and process highly sensitive data like health metrics, photos and the locations of our loved ones. The places where we keep our money, store our files and conduct business are increasingly online and, sometimes, only online. The critical infrastructure we often take for granted, from the electric grid to transportation networks, is increasingly dependent on connected devices as well.

However, as technology evolves, so do the bad actors trying to steal our data. Canada has witnessed this first-hand. In 2023, Canada was one of the countries most frequently targeted by ransomware attacks. Just last year, malicious actors targeted Canadian telecom and other networks as part of the massive Salt Typhoon attack, not to just steal customer data but to also conduct broad espionage and to control the communications infrastructure that billions of people rely on every day.

As a technology company, Apple is constantly working to anticipate and prevent these threats. As an engineer, I can tell you that end-to-end encryption is one of the most effective security technologies available to defend against them. Encryption protects Canadians from identity theft, fraud, unlawful surveillance and data breaches. It protects critical infrastructure. It protects the data and communications Canadian businesses and government rely on, which are crucial to Canada's economic success and national security.

Our users trust Apple with their most sensitive information. They expect and deserve the strongest protections. That's why we're so concerned about the threat to encryption posed by Bill C-22. As drafted, this bill allows the Government of Canada to force companies to break encryption by inserting back doors into their products, something Apple will never do.

I want to be clear that we share the government's commitment to the safety and security of all Canadians. We have a team of dedicated professionals on call, 24 hours a day, to assist law enforcement. From 2020 to 2024 alone, we received just over 3,200 Canadian government requests for information, about 35% of which were emergency requests. We're committed to supporting law enforcement's work to keep Canadians safe, and we're committed to encryption technology for the same reason, to keep Canadians safe.

Again, speaking as an engineer, I do not know of a way to deploy encryption technology that provides access for only the good guys without creating new ways for the bad guys to break in. In other words, when you build a back door into an encrypted device, anyone can walk through, and because so much depends on encryption, we can't take that risk.

Look no further than Salt Typhoon. The United States passed a law requiring telecommunication companies to build access points for law enforcement into their systems, which state-sponsored actors then exploited. That law was narrower than Bill C-22, so imagine what could happen if more companies were required to create these vulnerabilities.

Apple has provided a written submission outlining targeted amendments that would improve the bill, which I'm happy to discuss. We urge the committee to adopt amendments that would, in particular, explicitly prohibit any requirement that would weaken, bypass or undermine end-to-end encryption. We believe these changes would still expand lawful access and provide Canadian law enforcement with new tools to fight crime in the 21st century.

Again, thank you for the opportunity to speak today, and I look forward to your questions.

The Chair Liberal Jean-Yves Duclos

Thank you very much.

Let us turn now to Tamir Israel for five minutes, please.

Tamir Israel Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association

Mr. Chair and honourable members of the committee, good afternoon. I thank you for inviting me to speak before you today on Bill C-22, an act respecting lawful access.

Part 1 of Bill C-22 represents a meaningful improvement over its predecessor legislation; however, elements of part 1 continue to suffer from overbreadth. These include the use of low standards for judicially authorized access to sensitive subscriber data and a framework that invites unconstitutional collection of publicly available data.

Elements of part 1 also allow Canada to adopt at least one, if not two, international information-sharing agreements, despite a growing tendency to use these tools for cross-border repression and an absence of comparable safeguards.

CCLA is filing a joint brief with Kate Robertson and Cynthia Khoo from the Citizen Lab, which will elaborate on these and other problematic elements of Bill C-22. I'll focus the remainder of my remarks this afternoon on part 2 of the bill, which would enact the supporting authorized access to information sct, or SAAIA.

At various points in time, governments have sought to expand their surveillance capabilities at the cost of cybersecurity, with encryption being a recurring target. Too frequently, these expansions have been justified by the expectation that surveillance capabilities will only be used by lawfully authorized government agencies and not malicious actors, yet time and again, this expectation has been proven false. The Salt Typhoon attack is the latest and perhaps the most potent reminder of this hard lesson.

It's also notable that the case for this legislation has not been made. Indeed, half of our Five Eyes partners have limited their surveillance capability regimes to imposing wiretapping obligations on telecommunications carriers. With a troubling historical track record in mind, SAAIA is fundamentally flawed in three interrelated ways.

First, SAAIA is exceedingly broad. It applies to any provider of any service that has a digital component. Under the Australian version of this law, everything from a fast-food chain that provides its customers' Wi-Fi to an electronics store that helps maintain customers' phones and computers, to any retailer that has a mobile phone application or online website, has been listed as an anticipated target.

SAAIA is also broad in terms of what obligations the government can impose. These range from requiring the ability to covertly reset customer passwords or requiring an automatic tool that generates realistic undercover profiles on social media platforms to requiring the ability to block a target's use of encrypted private messaging services in order to force them to use insecure alternatives.

SAAIA's metadata retention mechanism is equally broad. Services can be required to retain a detailed record of every single person's movements, interpersonal interactions, what applications they use and more. This is highly sensitive data.

Second, stay of limitations and safeguards fails to constrain the multiple ways that privacy, encryption and other data protections might be compromised in light of the law's broad scope. SAAIA's systemic vulnerability limitation, for example, would not apply to a set of algorithmic monitoring tools referred to as client-side scanning. Because these tools bypass encryption rather than compromising it directly, they fall outside the systematic vulnerability limitation as drafted. They nonetheless create systematic vulnerability in practice.

Third, courts remain the primary vehicle for authorizing CSIS and police surveillance activities, but SAAIA does not rely on judicial authorization, despite authorizing powers that frequently rival their Criminal Code counterparts in breadth. For example, if police want to force a company to keep a specific customer's metadata for 90 days, they need a court order, but to force the same company to keep the same metadata on every single customer for up to one year, the government need only impose an obligation through SAAIA. Judicial review is available and even required in some instances, but judicial review is highly deferential to government decision-making and no substitute for independent authorization, de novo review or full appeal rights. This is particularly the case when many of the obligations are imposed in secret, as is the case under SAAIA.

In sum, SAAIA poses a significant threat to privacy and cybersecurity. It's unclear how SAAIA's many overlapping flaws can be remedied through the highly attenuated legislative study it's receiving. Australia's technical capability regime was amended 173 times during a detailed committee study. Despite these changes, they were still held to be likely incompatible with human rights and a mandatory assessment of the legislation.

We therefore urge you to recommend that the government advance Bill C-22 without part 2. This legislation will be in place for years to come, and it's critically important that we get it right. The stakes are simply too high.

Thank you. Those are my opening comments, and I invite your questions.

5 p.m.

Liberal

The Chair Liberal Jean-Yves Duclos

Thank you, Mr. Israel.

I now give the floor to Ms. Jeanette Patell for five minutes.

Jeanette Patell Director, Government Affairs and Public Policy, Canada, Google

Good afternoon, Mr. Chair, vice-chairs and honourable members of the committee.

My name is Jeanette Patell, and I'm the director of government affairs and public policy for Google Canada. I'm joined today by Kate Charlet, a senior director on Google's public policy team, where she leads our work on cybersecurity, privacy and child safety. Before coming to Google, she spent a decade in national security roles at the Pentagon and White House.

Google is committed to supporting the efforts of law enforcement in protecting the public against crime and terrorism. We firmly believe that improving public safety and maintaining user security are highly compatible goals.

As a global leader in building safe and secure products, we take the privacy and security of our users very seriously. Our business is built on the trust our users place in us to keep their data safe. Google products are private and secure by design, protected by multiple layers of security and leading technologies, such as encryption.

I want to be unequivocally clear that Google has never built a back door or any other mechanism to circumvent end-to-end encryption in our products. When we say a product is end-to-end encrypted, it is.

In today's rapidly evolving threat environment, we believe it is critical to find ways to support law enforcement's important work without engineering vulnerabilities into products and services that weaken security for everyone.

Within this context, Google has significant concerns with several elements of part 2 of Bill C-22 as it is currently drafted.

First, the proposed regime contemplates obligations and order-making powers that are unduly broad and practically boundless. It goes well beyond lawful access regimes in other G7 democracies and risks creating new surveillance infrastructure that would introduce serious security vulnerabilities, undermine user trust and hinder our ability to innovate and offer pro-privacy technologies.

Second, the proposed framework for secret ministerial orders is unprecedented and undermines accountability and user trust. Part 2 gives the Minister of Public Safety sweeping powers to issue secret orders mandating providers to create or maintain data interception capabilities, while permanently prohibiting companies from disclosing the existence of these orders. As written, this could give the government the power to secretly force companies to redesign products to include invasive surveillance capabilities, and to do so without sufficient safeguards or oversight.

Ministerial orders are not only alarming but also unnecessary. Canada already has an effective, transparent system where law enforcement can apply to the courts for reasonable assistance orders subject to judicial oversight. Secret orders are out of step with other democratic countries and would severely restrict companies' abilities to be transparent with users about how their data is protected.

Third, the bill's definition of “systemic vulnerability” is dangerously narrow. The legislation sets a very high bar, only recognizing a “substantial risk” of unauthorized access as a vulnerability, while ignoring severe risks to data integrity and availability. The current definition fails to explicitly protect the comprehensive security measures that Canadians rely on, which go far beyond encryption.

Without stronger definitions, the law could be used to force the dismantling of critical privacy architecture, such as breaking encryption, overriding users' data deletion controls or building remote access capability, all of which could facilitate foreign interference and weaken global user privacy. At a time when cyber-threats are increasing in frequency and sophistication and malicious actors are using AI tools to find and exploit vulnerabilities more quickly, we cannot afford to be creating new vulnerabilities.

Finally, the bill imposes overly broad requirements regarding the retention of metadata, without any geographic, temporal or targeted criteria. Such requirements would mandate the blanket and indiscriminate retention of people's communications data and risk treating the entire population as potential suspects.

Unnecessary data retention threatens the fundamental rights and freedoms of Canadians, infringes on their privacy and creates a massive trove of sensitive data that amplifies the consequences of any potential security breach. The existing provisions for targeted retention orders in the Criminal Code already meet law enforcement needs while respecting the rights guaranteed by the charter.

To ensure that Bill C-22 achieves its public safety objectives without compromising the digital security of Canadians, Google has submitted a number of legislative amendments. We'd be pleased to discuss them today.

Thank you for the opportunity to contribute to this process. I look forward to your questions.

The Chair Liberal Jean-Yves Duclos

Thank you very much, Ms. Patell.

Mr. Caputo, you have the floor for six minutes.

5:05 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

Thank you very much, Mr. Chair.

Mr. Neuenschwander, first of all, thank you for being here, and thank you to all of the witnesses. It's rare to get an engineer with your qualifications here. I feel like we could have a whole hour just with you.

Have you been monitoring the committee process on this bill, may I ask?

5:05 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

The team has. We've been keeping abreast. I was here in the prior hour.

5:05 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

I'll be very direct. My view is that this matter has been quite rushed. There are a lot of questions and things like that. Do you share that perspective?