Mr. Chair and honourable members of the committee, good afternoon. I thank you for inviting me to speak before you today on Bill C-22, an act respecting lawful access.
Part 1 of Bill C-22 represents a meaningful improvement over its predecessor legislation; however, elements of part 1 continue to suffer from overbreadth. These include the use of low standards for judicially authorized access to sensitive subscriber data and a framework that invites unconstitutional collection of publicly available data.
Elements of part 1 also allow Canada to adopt at least one, if not two, international information-sharing agreements, despite a growing tendency to use these tools for cross-border repression and an absence of comparable safeguards.
CCLA is filing a joint brief with Kate Robertson and Cynthia Khoo from the Citizen Lab, which will elaborate on these and other problematic elements of Bill C-22. I'll focus the remainder of my remarks this afternoon on part 2 of the bill, which would enact the supporting authorized access to information sct, or SAAIA.
At various points in time, governments have sought to expand their surveillance capabilities at the cost of cybersecurity, with encryption being a recurring target. Too frequently, these expansions have been justified by the expectation that surveillance capabilities will only be used by lawfully authorized government agencies and not malicious actors, yet time and again, this expectation has been proven false. The Salt Typhoon attack is the latest and perhaps the most potent reminder of this hard lesson.
It's also notable that the case for this legislation has not been made. Indeed, half of our Five Eyes partners have limited their surveillance capability regimes to imposing wiretapping obligations on telecommunications carriers. With a troubling historical track record in mind, SAAIA is fundamentally flawed in three interrelated ways.
First, SAAIA is exceedingly broad. It applies to any provider of any service that has a digital component. Under the Australian version of this law, everything from a fast-food chain that provides its customers' Wi-Fi to an electronics store that helps maintain customers' phones and computers, to any retailer that has a mobile phone application or online website, has been listed as an anticipated target.
SAAIA is also broad in terms of what obligations the government can impose. These range from requiring the ability to covertly reset customer passwords or requiring an automatic tool that generates realistic undercover profiles on social media platforms to requiring the ability to block a target's use of encrypted private messaging services in order to force them to use insecure alternatives.
SAAIA's metadata retention mechanism is equally broad. Services can be required to retain a detailed record of every single person's movements, interpersonal interactions, what applications they use and more. This is highly sensitive data.
Second, stay of limitations and safeguards fails to constrain the multiple ways that privacy, encryption and other data protections might be compromised in light of the law's broad scope. SAAIA's systemic vulnerability limitation, for example, would not apply to a set of algorithmic monitoring tools referred to as client-side scanning. Because these tools bypass encryption rather than compromising it directly, they fall outside the systematic vulnerability limitation as drafted. They nonetheless create systematic vulnerability in practice.
Third, courts remain the primary vehicle for authorizing CSIS and police surveillance activities, but SAAIA does not rely on judicial authorization, despite authorizing powers that frequently rival their Criminal Code counterparts in breadth. For example, if police want to force a company to keep a specific customer's metadata for 90 days, they need a court order, but to force the same company to keep the same metadata on every single customer for up to one year, the government need only impose an obligation through SAAIA. Judicial review is available and even required in some instances, but judicial review is highly deferential to government decision-making and no substitute for independent authorization, de novo review or full appeal rights. This is particularly the case when many of the obligations are imposed in secret, as is the case under SAAIA.
In sum, SAAIA poses a significant threat to privacy and cybersecurity. It's unclear how SAAIA's many overlapping flaws can be remedied through the highly attenuated legislative study it's receiving. Australia's technical capability regime was amended 173 times during a detailed committee study. Despite these changes, they were still held to be likely incompatible with human rights and a mandatory assessment of the legislation.
We therefore urge you to recommend that the government advance Bill C-22 without part 2. This legislation will be in place for years to come, and it's critically important that we get it right. The stakes are simply too high.
Thank you. Those are my opening comments, and I invite your questions.
