Good afternoon, Mr. Chair, vice-chairs and honourable members of the committee.
My name is Jeanette Patell, and I'm the director of government affairs and public policy for Google Canada. I'm joined today by Kate Charlet, a senior director on Google's public policy team, where she leads our work on cybersecurity, privacy and child safety. Before coming to Google, she spent a decade in national security roles at the Pentagon and White House.
Google is committed to supporting the efforts of law enforcement in protecting the public against crime and terrorism. We firmly believe that improving public safety and maintaining user security are highly compatible goals.
As a global leader in building safe and secure products, we take the privacy and security of our users very seriously. Our business is built on the trust our users place in us to keep their data safe. Google products are private and secure by design, protected by multiple layers of security and leading technologies, such as encryption.
I want to be unequivocally clear that Google has never built a back door or any other mechanism to circumvent end-to-end encryption in our products. When we say a product is end-to-end encrypted, it is.
In today's rapidly evolving threat environment, we believe it is critical to find ways to support law enforcement's important work without engineering vulnerabilities into products and services that weaken security for everyone.
Within this context, Google has significant concerns with several elements of part 2 of Bill C-22 as it is currently drafted.
First, the proposed regime contemplates obligations and order-making powers that are unduly broad and practically boundless. It goes well beyond lawful access regimes in other G7 democracies and risks creating new surveillance infrastructure that would introduce serious security vulnerabilities, undermine user trust and hinder our ability to innovate and offer pro-privacy technologies.
Second, the proposed framework for secret ministerial orders is unprecedented and undermines accountability and user trust. Part 2 gives the Minister of Public Safety sweeping powers to issue secret orders mandating providers to create or maintain data interception capabilities, while permanently prohibiting companies from disclosing the existence of these orders. As written, this could give the government the power to secretly force companies to redesign products to include invasive surveillance capabilities, and to do so without sufficient safeguards or oversight.
Ministerial orders are not only alarming but also unnecessary. Canada already has an effective, transparent system where law enforcement can apply to the courts for reasonable assistance orders subject to judicial oversight. Secret orders are out of step with other democratic countries and would severely restrict companies' abilities to be transparent with users about how their data is protected.
Third, the bill's definition of “systemic vulnerability” is dangerously narrow. The legislation sets a very high bar, only recognizing a “substantial risk” of unauthorized access as a vulnerability, while ignoring severe risks to data integrity and availability. The current definition fails to explicitly protect the comprehensive security measures that Canadians rely on, which go far beyond encryption.
Without stronger definitions, the law could be used to force the dismantling of critical privacy architecture, such as breaking encryption, overriding users' data deletion controls or building remote access capability, all of which could facilitate foreign interference and weaken global user privacy. At a time when cyber-threats are increasing in frequency and sophistication and malicious actors are using AI tools to find and exploit vulnerabilities more quickly, we cannot afford to be creating new vulnerabilities.
Finally, the bill imposes overly broad requirements regarding the retention of metadata, without any geographic, temporal or targeted criteria. Such requirements would mandate the blanket and indiscriminate retention of people's communications data and risk treating the entire population as potential suspects.
Unnecessary data retention threatens the fundamental rights and freedoms of Canadians, infringes on their privacy and creates a massive trove of sensitive data that amplifies the consequences of any potential security breach. The existing provisions for targeted retention orders in the Criminal Code already meet law enforcement needs while respecting the rights guaranteed by the charter.
To ensure that Bill C-22 achieves its public safety objectives without compromising the digital security of Canadians, Google has submitted a number of legislative amendments. We'd be pleased to discuss them today.
Thank you for the opportunity to contribute to this process. I look forward to your questions.
