Evidence of meeting #39 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Gary Anandasangaree  Minister of Public Safety
O'Gorman  President, Canada Border Services Agency
Deputy Commissioner Bryan Larkin  Royal Canadian Mounted Police
Pyke  Assistant Commissioner, Correctional Operations and Programs Sector, Correctional Service of Canada
Legault  Chief Financial Officer, Parole Board of Canada
Giles  Deputy Director, Policy, Canadian Security Intelligence Service
McCrorie  Vice-President, Intelligence and Enforcement, Canada Border Services Agency
Hazen  Chief Financial Officer, Royal Canadian Mounted Police
Bilodeau  Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness
Nashef  Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service
Superintendent Richard Burchill  Director General, Technical Investigation Services, Royal Canadian Mounted Police
Wong  Acting General Counsel, Policy Sector, Department of Justice
Hiegel  Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness
Gibner  Deputy Assistant Deputy Minister, Policy Sector, Department of Justice

The Chair Liberal Jean-Yves Duclos

Thank you very much. That was all very clear and quite useful, I'm sure.

Mrs. DeBellefeuille, you have the floor for two and a half minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Mr. Chair, I'm pretty impressed. As you can see, all parliamentarians across all parties want to understand the issue in order to adopt the best possible bill. The questions are coming from all parties, even the governing party. We want to adopt an important bill, which we know will bring about a cultural shift in Quebec and Canada. We want to make sure we improve it.

I find Mr. Housefather's questions relevant, because we're looking for the right words. We want to make sure we use the right word to reflect the government's intent or that of Public Safety Canada.

Mr. Bilodeau, I'd like to talk about metadata, because all of the witnesses have brought up the risks associated with such long retention periods. We've had discussions about this.

While studying the bill, I had an idea. In the regulatory section, we could say that the data will be kept for up to a year. That doesn't mean that all of the data for every Quebecker and every Canadian would be kept for a year. This may be something you wish to address in the regulatory section. However, not mentioning it and not putting it in writing creates confusion or insecurity and, I'd even say, a lack of trust.

I think that if you don't intend to keep 100% of Canadians' data, this should be stated explicitly in the bill in order to reassure people. As it stands, this is what it says. It doesn't say “up to”, “depending on the category” or “depending on the type of data”. Do you think there's room in the bill for us to clarify this?

Don't ask me to draft an amendment, because I wouldn't be able to do so. I'm asking whether there is somewhere this clarification could be added.

6:30 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

It is certainly true that clarifications can always be made to a bill. I will leave it to parliamentarians to propose such amendments.

As we have said on several occasions in different forums—and I believe we have discussed this with you as well—we are really looking to extract and define the metadata that will be useful for investigations, as well as a retention period for that data. That could be up to a year or less, depending on the type of data. You are absolutely right.

If you'd like, we can discuss the need for certain types of metadata. My colleague from the RCMP can explain why retaining metadata for up to a year may be relevant in the context of an investigation. Often, investigations do not develop in such a way that, from day one, a decision is made to obtain all the metadata relating to a person suspected of having committed a crime. This retention period is therefore necessary.

We are really seeking to address the current gap, where some providers do not retain metadata for longer than a week, while other electronic or telecommunications service providers retain it for much longer than a week. There is already data in the system that is retained for longer periods.

The Chair Liberal Jean-Yves Duclos

Thank you very much.

Mr. Caputo, you have the floor for five minutes.

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

Thank you, Mr. Chair.

I want to pick up on what Mr. Housefather was talking about. I wasn't planning on going into this, but he makes a very good point.

If I understand his point correctly, and maybe I don't, what I understand is a general concern. Who says “substantial likelihood” or whatever it is? What about a “possibility” or “plausibility”? If I could make one suggestion or one thought, it's that business hates uncertainty. The uncertainty in this bill is what's driving business to come out so clearly.... Even if it's a possibility, then what a business.... If I'm a business owner or if I'm advising shareholders or whatever and I have uncertainty, and it's “possibility” and they say, “Well, the recourse is that you have judicial review”, well, somebody might disagree with you.

What I want to underscore to the officials is that uncertainty is so pronounced here. When you are advising the government, please recognize that. Even with metadata, we don't know what classes of metadata will be preserved for up to a year. A point that's been made here is that we don't need to preserve anything for a full year. Which is it? I get that you want to put it in regulation and I get that it changes, but the act is silent on those things.

I'll open it up for comments, and then I have a question on what I had to say. Does anybody have any comments on that?

6:35 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

You mentioned regulation. For the first class of core providers, there's always going to be a first in the regulation. It will be clearly set out in the regulations what metadata needs to be retained and for how long.

6:35 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

I'm aware of that, but that's precisely my point. We around this table don't know what that's going to look like. I get that's how regulation works, but the uncertainty.... Again, we come back to that word “uncertainty”, because it's for up to a year. We don't know what type of metadata is going to take priority. We don't know whether location services are going to be there for up to a year.

A year is a long time. I understand that the argument has been made that we need this, but no one has asked, “Why a year?” That's another point. We have asked about industry standards. Australia has two years. Sweden has 10 months. There are also nuances there, but there's that uncertainty again.

Another reason for uncertainty is in proposed section 14, and that is the duty to assist. If I was a business owner, I think that I could rightfully fear this. Does proposed section 14 not conceivably require an electronic service provider to create hardware or software to bring it up to government standards, so to speak, so that the data can be retained? I hope that question is clear.

6:35 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

I'll ask my colleague Ms. Hiegel to respond.

Shannon Hiegel Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Absolutely. The expectation is that we are setting a standard across the current practices that is ad hoc. It is based on individual agreements.

Take the telecommunications class, as we call it. They are not all the same. When law enforcement goes to one provider over another one within the telecommunications world, they don't know if they're going to get the same information. If you're running an investigation and you're six months into something, it's probably taken you six months just to figure out which telecommunications provider it is. You're going to get a different set of information from different telcos. That is fundamental within setting a regulation. It's more than an expectation. You know what you get—

6:35 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

You want uniformity there. When we need information, we want to know it's there. I get that, but when I read this, if you're a small ESP, it might cost a million bucks to get up to that level. How do we, as parliamentarians around this table, say, “I get why you want uniformity”, but when we are sitting around this table, how do we address that for a small ESP?

A million dollars might be the smallest amount they have to pay, but that could cripple a company of that size. How do we respond to that?

6:35 p.m.

Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

Shannon Hiegel

One of the key elements.... Again, I am going to use the word “regulation”. In deciding who a core provider is, one of those factors is going to be how big your client base is. Are you national? Are you regional? How regional are you? How small are you? What is the service that you provide? There needs to be a very detailed conversation with these companies, so we can make a well-oiled regulation.

6:35 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

Therein is the issue. It is the uncertainty right there. Yes, we're going to factor these things in, but even factoring them in, you and I can't decide what that would look like. That uncertainty, I think, is what is driving a number of the questions here.

The Chair Liberal Jean-Yves Duclos

Your point is really well made in a short amount of time. Thank you.

Mr. Ramsay, you have the floor for five minutes.

Jacques Ramsay Liberal La Prairie—Atateken, QC

I will leave the floor to Mr. Housefather for the next question.

Anthony Housefather Liberal Mount Royal, QC

Thank you very much, Mr. Ramsay.

I'm going to come to the exact same point that Frank and Claude elaborated on.

If I was to say that, instead of “substantial” risk, it's a “credible” risk based on objective professional standards—so we now have assessed what the level of risk is and what it's based on—can the people from justice please tell me if that would be inconsistent with wording that we have in other legislation?

Kimberly Gibner Deputy Assistant Deputy Minister, Policy Sector, Department of Justice

Thank you for the question.

I think you've posited something really important to think about. We haven't thought about it and we're certainly open to what you—

Anthony Housefather Liberal Mount Royal, QC

Would you be willing to exchange with the committee on that?

I think I'm going to prepare something on that level and I'd be very interested to hear from you.

Thank you very much.

I'll hand the floor back to Mr. Ramsay.

Jacques Ramsay Liberal La Prairie—Atateken, QC

Is anyone among the witnesses familiar with the brief submitted by the Privacy Commissioner and the recommendations it contains?

The committee hasn't had much time to review these recommendations. I would like to hear your views on them, particularly the fifth recommendation, which deals with the powers of the Governor in Council and the minister, and suggests that the obligations imposed be necessary and proportionate.

6:40 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

Thank you for that question.

We've taken note of the Privacy Commissioner's brief. A good portion of the criteria and language proposed by Mr. Dufresne would form part of the regulatory analysis, since privacy protection must be taken into account as a factor in the drafting of regulations and ministerial orders.

So that would form part of the regulatory analysis.

Jacques Ramsay Liberal La Prairie—Atateken, QC

So we have to take your word that it will be considered at a later stage.

6:40 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

It's a criterion that is currently set out in the legislation.

Jacques Ramsay Liberal La Prairie—Atateken, QC

Let's talk about the sixth recommendation.

We are well aware that a provider has the ability to invoke a systemic vulnerability. The sixth recommendation calls for the government or the minister to be unable to require anything that would introduce a systemic vulnerability. That is a request which, I believe, is at a higher level.

6:40 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

The intent of the sixth recommendation is to place the burden on the government to determine whether a systemic vulnerability exists.

In the analysis we conducted while drafting the bill, we concluded that this analysis would be better carried out by electronic service providers, because they know their systems better than anyone—certainly better than the government—since they are the ones who developed and operate them. It's therefore up to them to tell us whether what we're asking them to do could create a systemic vulnerability. We would then hold discussions and decide, based on this information, whether the ministerial order should be issued in the form considered initially.

We will use the information provided by the providers to make informed decisions. We truly intend to consult with electronic service providers, and this is not merely an intention; it is a requirement under the legislation.

Jacques Ramsay Liberal La Prairie—Atateken, QC

Under clause 12, it states that a provider subject to an order is required to comply with it. In the event of judicial review, is there a way to stay this order, or must the provider proceed regardless?

If the provider must proceed regardless, the commissioner's recommendation would make sense.

6:40 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

My understanding of clause 12 is that it does not override the obligation not to introduce a systemic vulnerability. Therefore, clause 12 cannot require providers to do something if there is a systemic vulnerability.