Evidence of meeting #39 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Gary Anandasangaree  Minister of Public Safety
O'Gorman  President, Canada Border Services Agency
Deputy Commissioner Bryan Larkin  Royal Canadian Mounted Police
Pyke  Assistant Commissioner, Correctional Operations and Programs Sector, Correctional Service of Canada
Legault  Chief Financial Officer, Parole Board of Canada
Giles  Deputy Director, Policy, Canadian Security Intelligence Service
McCrorie  Vice-President, Intelligence and Enforcement, Canada Border Services Agency
Hazen  Chief Financial Officer, Royal Canadian Mounted Police
Bilodeau  Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness
Nashef  Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service
Superintendent Richard Burchill  Director General, Technical Investigation Services, Royal Canadian Mounted Police
Wong  Acting General Counsel, Policy Sector, Department of Justice
Hiegel  Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness
Gibner  Deputy Assistant Deputy Minister, Policy Sector, Department of Justice

6 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

My point though, sir, is this: It could happen.

What I'm getting at is that information that is meant to be encrypted and is itself encrypted could be compromised beyond end-to-end encryption. We're not just talking about end-to-end encryption because we were told that would introduce a systemic vulnerability if somebody had to disrupt that. I'm talking about data that is encrypted, but there is nonetheless a road map to it in the provider.

What I'm saying and what you're telling me that's of concern is that encryption that is not end-to-end that is provided by the service provider could then be subject to this bill. Do you get where I'm going with this?

6 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

I understand, yes.

6 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

Is that not accurate? Basically, what I'm asking is this: Isn't encrypted data still subject to this bill?

The Chair Liberal Jean-Yves Duclos

Give a quick reply, please.

6:05 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

If there were a judicially authorized warrant to access information, then it would depend on where the information lies, where the encryption is and also whether the regulations or orders apply.

It is case-by-case. It's hard for me to speculate on a hypothetical, because it would depend on the requirements set out in the regulations that we would be developing in consultation, and in the context of ministerial orders, with the provider—because it's a part of the legislation that we need to consult with them.

I would also say that in the context of the ministerial order, the provider could refuse to do it if it introduced a systemic vulnerability.

6:05 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

In this case—

The Chair Liberal Jean-Yves Duclos

Thank you for that. There will be other turns.

Next is MP Sodhi for six minutes, please.

Amandeep Sodhi Liberal Brampton Centre, ON

Thank you, Mr. Chair.

Thank you to all of our witnesses for being here today. My first set of questions will be directed to Mr. Nashef from CSIS.

To begin, to what extent do you believe Bill C-22 will bring CSIS's capabilities closer to matching those of our Five Eyes partners?

Ramzi Nashef Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Thanks for the question.

In fact, that's the exact objective of the bill from CSIS's perspective. As has been mentioned here many times today, we're the only Five Eyes country and one of the only like-minded countries—if we want to use that term—if we compare ourselves to the Europeans, that is absent a lawful access regime. For us, this would be a significant bound to put us in a position of equal footing with partners in terms of what we are able to get under judicial authorization.

Right now, to make a quick point of it, we rely on ad hoc arrangements with a range of different electronic service providers that give us an unpredictable and widely varying set of outcomes depending on which region of the country and which provider it is we're working with on any given warrant, let's say. For us, this is a significant step that will put us on much closer to even footing with key partners.

Amandeep Sodhi Liberal Brampton Centre, ON

Thank you for your answer.

We've had some people say that this bill will create some sort of a cybersecurity risk. What would be the cost to national security if we don't pass Bill C-22, particularly as encrypted communications become the default for threat actors?

May 28th, 2026 / 6:05 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Ramzi Nashef

That's another good question.

There were some questions earlier today around the risks of the bill. Something that has not necessarily been discussed today is the risk of not having a lawful access regime in this country. It's been a 30-year journey to get to the point of maturity of the current bill in front of you, and that has been with significant ups and downs.

The cost is increasing, to be frank with you. You can hear it from me, from CSIS and from counterparts on this panel. Don't necessarily take our word. There are other significant cross-partisan analyses, including the NSICOP report on going dark, that really get to the heart of the costs.

I would say that the slippage we are seeing, even when we have a federal court warrant for the information we are authorized to get but still cannot get, is increasing. That gap, for us, is an immediate and tangible one in terms of the safety of Canada and Canadians from what, for CSIS, for example, are the highest harm threats. We're talking about espionage, foreign interference and terrorism, primarily. That cost is here, and it's increasing. This bill is a significant proposal that would really modernize that set of tools for us.

Amandeep Sodhi Liberal Brampton Centre, ON

As you're aware, Peel Regional Police recently laid more than 100 criminal charges in what investigators described as one of the largest extortion cases in the region's history. It involved violent extortions targeting members of the South Asian community and their businesses.

How would lawful access tools improve CSIS's ability to investigate those networks more efficiently?

6:05 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Ramzi Nashef

I'll give a general answer and then pass it to my colleague Chief Superintendent Burchill.

For us, it's about being able to advance investigations and get better investigative outcomes in a quicker time frame. As I mentioned previously, we are only talking about the highest-harm threats. As such, it is of particular importance that we're able to improve the investigative outcomes because, as has been raised by the minister and many other speakers today, that erosion has been significant. It's been over decades, and we are really at an inflection point where a significant improvement and a modernization of those tools is required.

To speak specifically to the types of crime you mentioned, I'll pass it to Rick. Thanks.

Chief Superintendent Richard Burchill Director General, Technical Investigation Services, Royal Canadian Mounted Police

Thank you very much for the question.

From a law enforcement perspective, the Peel case represents the capability they had to get the evidence and bring charges, but with the number of extortion cases across the country, we have a national task force assisting police of jurisdiction, as well as RCMP where we're the police of jurisdiction, to try to have more better outcomes. The way that extortion cases unfold is particularly complex and difficult from a lawful access perspective, so having the tools that this legislation would provide would certainly enhance those investigations and provide better outcomes for law enforcement.

Amandeep Sodhi Liberal Brampton Centre, ON

I want to turn to the officials from the Department of Justice.

Apple recently testified that “anyone can walk through” a back door, but Bill C-22 requires that providers be capable of executing a lawfully issued warrant.

Can you clarify for the committee the legal distinction between a back door and a court-supervised lawful access mechanism?

Normand Wong Acting General Counsel, Policy Sector, Department of Justice

Thank you for the question.

A back door, the way that I understand it, is the systemic vulnerability that we've been talking about in relation to part 2.

Lawful authorizations, as our colleagues from CSIS and the RCMP have said, are obtained from the court. This is when police or national security is required to get a warrant. There are certain requirements to obtain that warrant in terms of evidence. The issue is that we have many of the tools already in the CSIS Act and the Criminal Code that allow our authorities to gain access. The problem is that when they go to the service provider, the service provider cannot allow them access.

Amandeep Sodhi Liberal Brampton Centre, ON

Thank you.

Thank you, Mr. Chair.

The Chair Liberal Jean-Yves Duclos

Thank you for that, MP Sodhi.

It is now over to Mrs. DeBellefeuille for six minutes.

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Thank you, Mr. Chair.

Thank you to the witnesses for being here.

Mr. Bilodeau, I'm going to tell you the feeling I have. In light of what the witnesses have told us, the sense I've gotten since the beginning is that they don't understand the bill. Their comments put all kinds of doubts in our minds. For your part, you're saying that isn't the purpose of the bill. When you say it enough times, it's almost like you're telling us we should trust you because that isn't really the bill's intent.

As I see it, things would be clearer if you spelled out in the bill everything people don't understand. That would make us feel better, especially about the whole issue of back doors. Basically, apart from the police services, hardly any of the organizations and companies we met with agree with some of the provisions in Bill C‑22. To my mind, one of your responsibilities is making sure that the committee has a clear understanding of the bill, so you need to stop saying that isn't the purpose of the bill and, instead, lay out exactly what the intent is right in the bill.

After hearing everyone's concerns, I'm very hopeful—I know the government would like to achieve somewhat of a consensus on Bill C‑22—that you'll have a chance to clarify things.

I wanted to say that at the start, because, as a parliamentarian, I don't have the expertise of a computer scientist. There are all kinds of things I don't know, so I'm relying on the experts, and all the experts are telling us that if Bill C‑22 is passed as is, privacy will be no more. I can name plenty of people who said so.

Do you think it's important to include clear definitions or perhaps even who the bill does not apply to? That's another suggestion we got, from Desjardins and Interac, who wondered whether they would eventually find out if the bill applied to them, since the definition will be established by regulation.

Are you working on anything or having any discussions that will provide us with the details we need regarding the government's intention? Those details are necessary to inform our consideration of Bill C‑22.

6:15 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

Thank you for your question.

I believe the minister said this yesterday when he spoke. We, too, have said a number of times that, if it's possible to provide clarity in the bill, as parliamentarians, you will have the opportunity to make amendments.

The government stated yesterday that it would do that and provide some clarity. With respect to end-to-end encryption, for instance, not being able to introduce systemic vulnerabilities is precisely the issue, in our view. The legislation does not allow end-to-end encryption. It is clearly excluded. The government said it wanted to clarify that.

Quickly, something worth considering is that the bill really creates a framework to specify who the legislation applies to. For example, in the case of core providers, there is a process to follow. It's a transparent process. Consultations will take place. The regulations will have to respect certain criteria throughout. The same goes for ministerial orders; the matter will have to be discussed with electronic service providers first.

Putting everything in the bill wouldn't necessarily allow the act or regulations to keep pace with technology. That's why the bill is drafted the way it is. Considering how technology is adopted—

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

I understand, Mr. Bilodeau. Essentially, in the regulatory part, you're suggesting we be more agile so we can adapt quickly to changes. The problem is that the police forces and the RCMP often tell us they've been waiting for this for 30 years.

In my view, the United States and the United Kingdom aren't good examples when it comes to privacy protection. When people tell me we should copy them, I become wary, because here in Quebec and Canada, we have a strong culture of privacy protection. We understand the needs of police forces, but before approving of this legislation, we want to be sure that everything is in place to meet police officers' needs while providing safeguards.

I understand the regulatory part, but could we proceed in stages? What I mean is this: We adopt the bill with certain clarifications, and then we'll revisit it in two years to refine and improve it based on how it has worked in practice.

Adopting Bill C‑22 represents a major cultural shift. Just because we're not like the others doesn't mean we're not good. Maybe we're the best at protecting privacy, and we don't want to imitate those we don't admire. That's what I'm after.

Do you think it would be possible to proceed in stages?

6:15 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

To answer your question, I'd say that it will have to comply with the Canadian Charter of Rights and Freedoms, whether it be the bill or the regulations.

We created a bill in response to information obtained by our allies, whether from the Five Eyes or from European countries, but we have drafted it in a Canadian context, in accordance with Canadian laws. We have a charter here in Canada. Laws must therefore comply with the charter. Our colleagues at the Department of Justice have submitted the required statement of compliance with the charter.

Whether at the level of the act or the regulations, it has to comply with the charter. There are also privacy requirements that must be considered in developing regulations and ministerial orders. We think we've struck the necessary balance by implementing ways to respond to the needs of police forces and the Canadian Security Intelligence Service's requests. In the end, these measures protect victims of crimes and national security threats, but they do so in a way that respects privacy and the Canadian Charter of Rights and Freedoms.

The Chair Liberal Jean-Yves Duclos

Thank you for your thoughts.

Ms. Kirkland, you have the floor for five minutes.

6:15 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Thank you, Chair.

My first questions will be directed to Mr. Nashef.

Thank you for being here today. I'm appreciative that you're here because I've found that any time I've asked questions of you in the past, whether it's in this committee or otherwise, you speak in a language that Canadians understand. Sometimes it is very hard for people to truly understand what's going on with technical pieces.

I have some important questions.

Would CSIS consider a government-mandated access point within an encrypted system to be a vulnerability from a cybersecurity standpoint, even if it's authorized and controlled?

6:15 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Ramzi Nashef

You might have jinxed me with the front end of your statement—