That's a good question. I might ask my colleagues from the Department of Justice to weigh in. I'll give them an opportunity to think about it.
At the end of the day, substantial risk was used to strike that balance between providing a framework for lawful access and making sure we're not creating those systemic vulnerabilities. The last thing we want this legislation to be used for is to weaken this. As one of the previous witnesses said, we don't want to harm Canadian security writ large, whether it's through this or cybersecurity.
That's why I would add to Mr. Nashef's answer earlier that a lot of data is being retained now. Companies are used to doing this. They take a lot of precautions. Some of the firms have very good cybersecurity hygiene and take really important steps to protect that. We would expect that to continue under this lawful access regime, because some of the data might still be kept.
