Evidence of meeting #44 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was reasonable.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Gilkes  Acting Officer-in-Charge, RCMP Lawful Access, Royal Canadian Mounted Police
Bilodeau  Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness
Hiegel  Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness
Superintendent Richard Burchill  Director General, Technical Investigation Services, Royal Canadian Mounted Police
Wong  Acting General Counsel, Policy Sector, Department of Justice
Gibner  Deputy Assistant Deputy Minister, Policy Sector, Department of Justice
Nashef  Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

The Chair Liberal Jean-Yves Duclos

Mr. Ramsay, go ahead on a point of order.

Jacques Ramsay Liberal La Prairie—Atateken, QC

Once again, the Conservatives are discussing the purpose of the bill. I would like to point out that we are currently discussing BQ‑5, which deals with line 27 on page 7.

I understand that Ms. Cody wants further explanations, but all she had to do was come forward when we did this work in extenso for several weeks.

The Chair Liberal Jean-Yves Duclos

Thank you, Mr. Ramsay. Your point of view has been noted.

Mr. Caputo, you have the floor.

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

I'd like to speak on the same point of order.

The Chair Liberal Jean-Yves Duclos

The floor is yours.

3:55 p.m.

Conservative

Frank Caputo Conservative Kamloops—Thompson—Nicola, BC

With all due respect, Mr. Chair, I don't think it's well noted. We are parliamentarians. We get to come here, and we get to ask questions. I will not allow anybody to get in the way of anybody asking a question, whether it be a Liberal member who has privilege or a Conservative member.

If Ms. Cody wants to ask a question about the bill, about the general nature of the bill and about how the general nature of the bill impacts line 27, or whatever it was, she has the right to do so. The fact that someone doesn't like it is irrelevant.

The Chair Liberal Jean-Yves Duclos

There is indeed a great deal of latitude in the questions that can be asked. Mr. Caputo's point has been duly noted. The same goes for Mr. Ramsay's point that it's preferable to ask relevant questions about the subjects discussed at the appropriate time. Right now, we are indeed discussing BQ‑5.

Ms. Cody, the floor is yours.

3:55 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

I want to know about the assurance, which carries a lot of weight here, so we can fairly look at anything else this bill claims to do. It would really help to know what the term actually means in law.

Does mandating interception capability in an encrypted system fall inside that definition, or outside of it?

3:55 p.m.

Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

I'm sorry. Can you repeat that question?

3:55 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

I'll read it again so that it's clearer.

We've been told that this bill would not create systemic vulnerabilities. What I'm asking is, does mandating interception capability in an encrypted system fall inside or outside of that definition?

3:55 p.m.

Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

When looking at the definition of “systemic vulnerability”.... There might be amendments that speak to this as we move along. The minister has spoken about this publicly. The term “systemic vulnerability” is understood to mean, from a government perspective.... It is not targeting end-to-end encryption. As such, the answer to your question will depend on a specific situation. If the regulation or a ministerial order mandates something, the core provider, person or company subject to the order would not have to do anything if it creates a vulnerability in their system.

That's how the legislation in part 2 is constructed. There's a process for developing regulation that everybody is familiar with. Ministerial orders have a very specific process that involves electronic service providers, law enforcement, the minister and the intelligence commissioner. There's a process there. At any point during that process, if an electronic service provider says to us—because they know their system best—that introducing a capability would create a systemic vulnerability, there's an opportunity to address this and make sure it doesn't.

4 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

A law describes what should happen and sets out consequences when things go wrong, but it does not physically prevent an attack from occurring. The assumption this bill seems to rest on is that if the rules are clear enough, the infrastructure will be safe. However, rules do not stop a breach. They describe what happens after one. The people targeting Canadian systems do not factor in what Parliament has passed. They look for a door. This bill would require that a door be built into every qualifying service provider.

What in this bill—not the rules around it but the technical reality—keeps that door from being found?

4 p.m.

Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

Taking a quick step back, the legislation would not apply to every single electronic service provider from day one. For an electronic service provider to be covered by the legislation, either it would have to be covered as a core provider through the regulation, or it would need to be identified through a ministerial order...to develop any capability that is mandated by the regulation or the ministerial order. The legislation is not intended to introduce vulnerabilities into systems. We don't refer to back doors. We don't believe it creates back doors. I think there's a letter from the CSE that was shared with the community on some of these points.

Whether or not it's in this legislation as it currently stands, it is the responsibility of companies to protect their cybersecurity. They do it every day. Attacks happen. We had testimony from my colleagues at the service: No system is 100% protected from cyber breaches. I think we all know this from what we see every day. Companies are well positioned to defend their systems.

This legislation has safeguards to prevent new vulnerabilities from being introduced into systems.

4 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

On that note, in 2024, Chinese state-sponsored hackers, specifically Salt Typhoon, got into lawful intercept infrastructure that had been built into American telecom systems. The access point that existed for authorized law enforcement became the way a foreign state got in. Bill C-22 asks Canadian providers to build that same type of architecture.

Did the Department of Public Safety do a threat assessment specifically on that scenario and, if it did, is there something we can see?

4 p.m.

Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

We're obviously aware of that information on Salt Typhoon. Without going into detail on that specific situation and breach, I can tell you that we always learn from past breaches in different situations.

This is obviously something we'd keep in mind with the implementation of this legislation, should it become law. We'd work with companies as the legislation gets implemented.

4 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

The term “electronic service provider” in SAAIA is extraordinarily broad. It could capture telecoms, messaging apps, cloud storage, AI platforms, email services and potentially much more beyond that, and many of those providers are not Canadian companies. They are headquartered in the United States, the European Union or elsewhere, and they operate under the laws of those jurisdictions.

Can this committee get a clear answer on exactly which categories of service are captured under that definition and which are not, and does that obligation apply equally to providers headquartered outside Canada?

4 p.m.

Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

I'll start, and I might go to my colleague Shannon Hiegel, who's with us virtually today.

As I explained earlier, who the legislation will end up applying to specifically will be determined through regulation on core providers. We've talked a lot about telecommunication service providers probably being one of the most important electronic service providers that might be subjected to part 2. Then, in ministerial orders, they will be able to identify electronic service providers after that. There's a process for decision-making in terms of who it gets applied to in regulation, and the same thing goes for ministerial orders.

As for differences in applications, whether or not they're domestic or international firms, maybe I can ask my colleague Shannon to elaborate on that.

Shannon Hiegel Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness

I would be quite specific in pointing out that “electronic service provider” in the act refers to, in proposed paragraph (a), providing the service to a person in Canada or, in proposed paragraph (b), carrying out all or part of its business activities in Canada.

What we're trying to ensure is that Canadians can have the certitude that we are covering any type of electronic service provider that services and operates within the jurisdiction of Canada. I think that's certainly an important definition and explanation to give you related to your question.

4:05 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

Thank you.

Anyone who has worked inside a data system knows that security gaps do not only come from outside attackers. Every time a service provider adds a third-party program, every time two systems get connected and every time a new software link gets built in to meet a requirement like the one this bill creates, a potential gap opens. The interception architecture, SAAIA, will not be built once and left alone. It will be patched, updated and connected to other systems by providers of very different technical capacity, and each of those moments is an opportunity for a gap to open that nobody anticipated.

Does this bill require any ongoing security testing of the interception infrastructure after it is built, or does the obligation end at construction?

4:05 p.m.

Assistant Deputy Minister, National and Cyber Security Branch, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

This legislation is part of an ensemble of legislation, but I would point out to you that companies already take a number of steps to protect their systems. They do so in collaboration with their own service providers, with third parties and with the Canadian centre for cybersecurity, which is a good partner of the private sector specifically on critical infrastructure.

I would also point out that Bill C-8, which received royal assent late yesterday, imposes a number of obligations on federal critical infrastructure owners, including cybersecurity and in relation to third parties. I think we need to look at it in totality in terms of what is done in the private sector and the obligations they have in regard to other pieces of legislation, but also, it is their responsibility.

We know that companies do this. They want to protect their systems because it's good for them and it's good for their customers. They are all constantly patching whether or not this legislation exists. As this legislation gets implemented and there are discussions with the government in terms of the regulations and ministerial orders, again, the legislation allows ESPs to say, “I can't do that because it introduces a systemic vulnerability.”

There are a number of safeguards in the legislation but also in totality in terms of obligations that apply to a number of providers.

4:05 p.m.

Conservative

Connie Cody Conservative Cambridge, ON

Thank you.

You're saying that there's going to be a lot of security being looked at with the bill, but in August 2025, hackers got into the House of Commons by exploiting a Microsoft vulnerability and pulled employee names, job titles, office locations, email addresses and device information belonging to members and staff. Canada's own cyber—

Sima Acan Liberal Oakville West, ON

I have a point of order, Mr. Chair.

The last three questions and this one are irrelevant to the topic we are studying on the clause. If our Conservative colleagues are willing to be productive, I suggest to them to get back to the topic and questions on the clause, please.

4:05 p.m.

Conservative

Andrew Lawton Conservative Elgin—St. Thomas—London South, ON

I'll speak on the same point of order.

The Chair Liberal Jean-Yves Duclos

Go ahead, MP Lawton.

4:05 p.m.

Conservative

Andrew Lawton Conservative Elgin—St. Thomas—London South, ON

Thank you very much, Mr. Chair.

I would note that this morning, the Liberal government House leader put on notice a motion to silence debate and shut down this committee's work. For members like Ms. Cody and me, who have taken a keen interest in this bill and others, today may be our only opportunity because of what the Liberals are doing to shut down this committee's work. For them to try to use their points of order to silence very legitimate questions on this bill even further is shameful.