Thank you very much.
I think the primary comparison here is to privacy principles. We think of privacy principles around data minimization and user controls and about the potential that Bill C-22 could undermine those privacy principles.
Just as an example, if we look at Google's provision of user controls, we offer users the ability to choose to delete their data after three months. Retention requirements or product changes that require us to make changes that would require retention for longer than three months would be against the wishes of a user. We look at this with concern in terms of privacy principles that are global in nature.
On your question regarding U.S. law, we look to U.S. law—CALEA specifically. CALEA does explicitly forbid governments from forcing a company to break encryption. That is a similar protection that we would be seeking in Bill C-22.
