Evidence of meeting #38 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Nadeau  President, Barreau du Québec
Lefebvre  Chairman and Co-founder, Crypto Québec
Dufresne  Privacy Commissioner of Canada, Offices of the Information and Privacy Commissioners of Canada
Marchand  Member, Criminal Law Expert Group, Barreau du Québec
Le Grand Alary  Lawyer, Secretariat of the Order and Legal Affairs, Barreau du Québec
Neuenschwander  Senior Director, User Privacy and Child Safety, Apple Inc.
Israel  Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association
Patell  Director, Government Affairs and Public Policy, Canada, Google
Charlet  Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google
Van Laer  Retired Staff Sergeant, Reservist, Royal Canadian Mounted Police
Thomas Carrique  President, Canadian Association of Chiefs of Police
Brown  Mayor, City of Brampton
Smith  Senior Vice-President, Canadian Telecommunications Association
Ullock  Board Chair, Ontario Child Sexual Exploitation Investigators Association
Chief Nick Milinovich  Deputy Chief of Police, Peel Regional Police
Murray Rankin  Barristor and Solicitor, As an Individual

5:15 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

It's hard for me to speak for other jurisdictions, but in general, I would say that the desire to catch bad actors is a universal one.

Sameer Zuberi Liberal Pierrefonds—Dollard, QC

I ask because the comparative is interesting.

Ms. Charlet, if you have knowledge on this particular question, then feel free to answer. Otherwise, I'll continue to other questions.

5:15 p.m.

Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google

Katherine Charlet

Google appreciates the challenges that law enforcement faces, and we're here to support those efforts. That's part of our effort to provide constructive recommendations on how to amend the bill.

Sameer Zuberi Liberal Pierrefonds—Dollard, QC

Erik, earlier you mentioned encryption. We've heard many times from the government's perspective that it is not being asked that encryption be unlocked.

How is it that you still are coming to the committee and the main thrust of your testimony is around encryption and your concerns about it being unlocked? How do you square that circle?

5:15 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

Again, I'm certainly not an expert on legislative text, but in reviewing it with the team, I don't see anything written within the bill itself that provides those protections against encryption. I do grant that the bill does not actually specify what these orders would do. That's kind of left for later.

To bring this into a real-world analogy, I might say something like we're concerned about a hole being put in a wall. I would say that the bill does not put a hole in the wall. It merely allows for secret orders to force putting a hole in the wall. Our concern is motivated because, at the end of the day, there would still be a hole in the wall.

Sameer Zuberi Liberal Pierrefonds—Dollard, QC

If your concerns, as the the government puts forth, are moot, then do you have any other amendments or suggestions with respect to the legislation that you would like to put on the table?

5:15 p.m.

Senior Director, User Privacy and Child Safety, Apple Inc.

Erik Neuenschwander

The primary ones are around protecting encryption explicitly and strengthening the definition of systemic risk, as encryption is just one aspect of where making everyone less safe, we think, would be a counterproductive outcome for society.

We would welcome additional judicial review. We would welcome relaxation of some of the secrecy protections, because I would like conversations such as this one to still be able to occur in the future. We also have some concerns around the breadth of the inspection powers that are in the bill and the possibility of installing third party equipment into secure networks.

Sameer Zuberi Liberal Pierrefonds—Dollard, QC

Mr. Israel, I'd like to open up the floor to you for the next few moments to add anything that you'd like to add.

5:15 p.m.

Director, Privacy, Surveillance and Technology Program, Canadian Civil Liberties Association

Tamir Israel

A definition that encompasses the need to exclude any obligations that cause systemic vulnerabilities would need to take into account the multiplicity of ways and proposals that keep emerging for getting around encryption. Many of these don't compromise encryption directly, but try to get at it indirectly by circumventing it or bypassing it, yet still have the same impact in terms of the vulnerabilities that they ultimately create. The current definition doesn't capture all of these. It's limited in scope. I would also really encourage your committee to consider blocking that.

Sameer Zuberi Liberal Pierrefonds—Dollard, QC

Thank you.

The Chair Liberal Jean-Yves Duclos

Thank you, Mr. Zuberi.

Mrs. DeBellefeuille, you have the floor for six minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you very much, Mr. Chair.

I thank the witnesses for joining us.

Ms. Patell, I thank you and congratulate you for taking the time to deliver part of your remarks in French. Your French is excellent, as is your pronunciation. So, thank you very much.

Your company operates in all Five Eyes countries, if I am not mistaken. Therefore, you are already subject to legal access regimes or laws, such as those in the United States. When compared to the United States, we see that Canada has more laws, mechanisms and institutions that protect privacy. At least, that is my interpretation.

So, given that your company also operates in the United States and that you say you find the Canadian government's bill too restrictive, can you tell us how, in your view, it compares to that of the United States?

5:15 p.m.

Director, Government Affairs and Public Policy, Canada, Google

Jeanette Patell

Thank you for your question and for your kindness regarding my French.

I will now turn the floor over to my colleague Ms. Charlet, because it is clear that there is tension regarding the Privacy Act and Bill C‑22.

I'll pass it on to my colleague Kate to speak more with regard to the privacy considerations that are invoked by this law in particular, in comparison with the U.S. regime.

5:20 p.m.

Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google

Katherine Charlet

Thank you very much.

I think the primary comparison here is to privacy principles. We think of privacy principles around data minimization and user controls and about the potential that Bill C-22 could undermine those privacy principles.

Just as an example, if we look at Google's provision of user controls, we offer users the ability to choose to delete their data after three months. Retention requirements or product changes that require us to make changes that would require retention for longer than three months would be against the wishes of a user. We look at this with concern in terms of privacy principles that are global in nature.

On your question regarding U.S. law, we look to U.S. law—CALEA specifically. CALEA does explicitly forbid governments from forcing a company to break encryption. That is a similar protection that we would be seeking in Bill C-22.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Experts and civil society organizations say that the U.S. CLOUD Act grants U.S. authorities the power to demand access to data held by companies subject to U.S. law, regardless of where the data is stored.

If Bill C‑22 is passed, do you believe Canada will be equipped to deal with this requirement? Many companies and citizens are afraid. They fear that, once Bill C‑22 is passed, our data will become accessible to countries that do not share our concerns regarding privacy protection or even respect for human rights.

5:20 p.m.

Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google

Katherine Charlet

I would say that this law does have global impact. Bill C-22 could require, under the ministerial orders, a company to make product changes. It is essentially unbounded in terms of what those product changes could be, as well as the secrecy requirements involved. Google and other companies are global companies and Canadians interact with people all over the world, so there are global impacts to a proposal such as this one.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Ms. Charlet, you say that Bill C‑22 is more intrusive in terms of legal access than the laws in the United States.

5:20 p.m.

Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google

Katherine Charlet

Yes, ma'am.

The essentially unbounded nature of the powers that are afforded to direct product changes by companies in secrecy and without judicial oversight, in the case of the ministerial orders, goes beyond any regime that I'm familiar with.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Were you consulted prior to the drafting of Bill C‑22?

Did you express your concerns to the government during the bill’s drafting process?

5:20 p.m.

Senior Director, Privacy, Safety and Security, Government Affairs and Public Policy, Google

Katherine Charlet

We have provided a submission with some specific recommendations, but I will pass this to my colleague, Jeanette, on your broader question.

5:20 p.m.

Director, Government Affairs and Public Policy, Canada, Google

Jeanette Patell

We have shared these concerns with the government. I don't believe we were in a consultation process prior to tabling, but we welcome the opportunity to engage with this committee to find workable solutions here that can support law enforcement in its legitimate need to conduct investigations, while also preserving user privacy and maintaining the security of our products and services.

Thank you for the constructive engagement.

The Chair Liberal Jean-Yves Duclos

Thank you, Madame DeBellefeuille.

We'll now go to Ms. Kirkland for six minutes, please.

Rhonda Kirkland Conservative Oshawa, ON

Thank you, Chair.

I would like to start with just—

The Chair Liberal Jean-Yves Duclos

I said six, but it's five minutes.

5:25 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

You said six, so it's too late. I want those seconds back, though.

I'd like to start by talking about the fact that this is rushed. We've mentioned this before. It feels rushed to me as a parliamentarian. I had questions in the last hour that I really wanted to get to and wasn't able to because of how fast all this is proceeding. I made the statement early on that I thought we should be careful not to just race to royal assent. If we're going to do this, then we need to get it right.

I know that we've missed getting some submissions to the committee, and I don't fault anyone for that. I know there was no malice intended. I don't fault the clerk for that. It's to be expected in such a rushed environment that those types of things will happen.

Mr. Neuenschwander, it is my understanding that you did provide submissions to this committee. I don't believe it has come through the clerk yet, but thankfully, you sent them to each of us directly. I appreciate that very much.

I want to backtrack with regard to what I hear over and over again, the term “back door”. I think Canadians really need to understand what that means.

On the Government of Canada website from five days ago, under lawful access, it says, “Bill C-22 does not require ESPs to create 'backdoors' to their systems or [to] weaken electronic protections, including encryption.”

Also said in testimony by Mike McGuire was:

This part does not create new powers for law enforcement or CSIS to intercept communications or obtain information, nor does it allow direct government access to electronic service providers' systems. It also explicitly prohibits the creation of systemic vulnerabilities, to ensure that a regulation or ministerial order does not weaken encryption or create back doors.

The minister said:

This part also includes an explicit safeguard to prevent the introduction of systemic vulnerabilities in electronic protections. Our government does not support the creation of back doors.

Testimony today seems to make that obviously not really the case, so I need some clarification. I'm happy for each one of you to provide that clarification. I think the word “explicit” is worth taking a longer look at, because it doesn't seem to be explicit in this legislation. I know that there are ways that we can make it explicit, so I'd like each of you to talk about that briefly. Thank you.

We'll start with Mr. Neuenschwander.