Thank you very much, Mr. Chair.
I think this is a good opportunity for us because we have to prepare amendments to the bill. One amendment that I think is very important is the one that Ms. Kirkland was just talking about. It's with respect to encryption and bringing this into line with the U.S. statute to say that no company that doesn't have a key to the encryption has to create one or could be ordered to create one, under an order. I think that's very important, but another element that is important to look at in this bill is the systemic vulnerability issue, the definition of systemic vulnerability and its interplay with the orders.
I think it will be relatively simple to craft amendments to say, for example, that you can't be forced in an order to create a systemic vulnerability. I think we can create amendments to do this that would be very agreeable.
I have an issue with the definition of “systemic vulnerability”. This is what it says right now:
systemic vulnerability means a vulnerability in the electronic protections of an electronic service that creates a substantial risk that secure information could be accessed by a person who does not have any right or authority to do so.
A substantial risk is very high. It means it's not just any risk. It's not a plausible risk. It's not just a risk. It's not a material risk. It's not a real risk. It's not a credible risk. That's a lower threshold. It basically means that if somebody says, “I think there's a plausible risk that by doing this we will create a systemic vulnerability”, they could still be forced to do it.
I'm not satisfied with “substantial” risk. I understand that there may be a reason to not just remove the word “substantial” and put in “a” risk, because that would be any risk, irrespective of how immaterial it is. What word should I propose, or do you recommend that I propose, as an amendment?
For example, if I were to use “plausible” risk, what, then, do you believe would be the legal interpretation? How would that be viewed? What would be the effect?
