Thank you, Mr. Chair.
Members of the committee, thank you for inviting me to share my views on Bill C‑22.
Last week, I made a written submission to the committee, which I will address in greater detail today.
Bill C‑22 reintroduces lawful access provisions that were originally proposed in Bill C‑2, but with several changes that reflect feedback the government received. Some of these changes are consistent with written recommendations on Bill C‑2 that I submitted to the Minister of Public Safety last November.
Bill C-22 improves on its predecessor, Bill C-2, in several respects. In particular, I welcome the more narrowly tailored confirmation of service demand. I appreciate the addition of potential privacy and cybersecurity impacts as factors that must be considered in the making of regulations and orders under the supporting authorized access to information act, the SAAIA. I'm also pleased to see the act's new oversight role for the intelligence commissioner with respect to ministerial orders.
That being said, in my written brief to this committee, I've highlighted some aspects of Bill C-22 that would warrant, in my view, further amendments to strengthen and ensure privacy protections for Canadians.
Specifically, I recommend narrowing the definition of “subscriber information” to a closed list of discrete identifiers, such as a subscriber's name, address, telephone number and IP address. This would help to avoid capturing information that could attract a heightened expectation of privacy.
I also recommend restricting the range of persons or entities who could be compelled to produce subscriber information to telecommunications service providers, and ensuring that the justice or judge making the order can specify the subscriber information that must be produced.
In addition, I recommend defining “publicly available information” to exclude information in respect of which an individual has a reasonable expectation of privacy, as defined in the Communications Security Establishment Act.
The concept of so-called publicly available information continues to evolve, and an individual does not automatically waive any reasonable expectation of privacy for information that may be available online. Take, for example, a situation where an individual's information was disclosed as a result of a data breach or published without their knowledge or consent.
Another recommended amendment would be to add an overarching requirement that obligations imposed under the SAAIA be limited to what is necessary and proportionate. This would help to ensure that any such obligations, including with respect to the retention of metadata, are tailored to minimize privacy impacts.
On the issue of accessing information, I would recommend amending the definition of “systemic vulnerability” to clarify that it includes any action that would render systemic methods of authentication or encryption less effective, as in Australia's analogous law. In addition, I recommend specifying that regulations and orders must not have the effect of requiring an electronic service provider to introduce, or of preventing an electronic service provider from rectifying, a systemic vulnerability.
Finally, I recommend adding an exemption to the confidentiality rules set out in the supporting Access to Information Act which would expressly authorize electronic service providers to share information with appropriate regulators, such as the Office of the Privacy Commissioner of Canada, to enable them to properly exercise their powers and duties.
Thank you for your attention. I look forward to your questions.
