House of Commons photo

Crucial Fact

  • Her favourite word was data.

Last in Parliament October 2015, as NDP MP for Terrebonne—Blainville (Québec)

Lost her last election, in 2015, with 26% of the vote.

Statements in the House

Request for Emergency Debate June 13th, 2013

Mr. Speaker, following the letter that was sent to your office dated yesterday and pursuant to Standing Order 52, I am requesting that an emergency debate on the Communications Security Establishment Canada's metadata collection program be held as soon as possible.

An emergency debate is needed so that parliamentarians can take an in-depth look at the extent to which Canadians' personal information, metadata and other information are collected by the police, law enforcement agencies and national security agencies. This debate is also needed so that we can look at measures that will lead to appropriate parliamentary oversight and ways to balance public and national security interests with Canadians' privacy rights.

On Monday, it was announced that the Communications Security Establishment Canada was potentially collecting metadata on Canadians. Since then, Canadians have been very concerned. They want to ensure that a parliamentary oversight system is in place.

We know that, right now, just one judge, with the help of a small team, is responsible for examining this office's operations. He has testified in committee only three times since he has been in office. I think it is our duty to reassure Canadians by holding a debate here.

I can also say that, since that announcement was made, there have been online campaigns and petitions signed by tens of thousands of Canadians. They are very concerned about this news and about the possibility that their privacy is being violated. Canadians are not alone in this campaign. They have been joined by Amnesty International, Alternative Québec, the Canadian Civil Liberties Association, the Council of Canadians and 10 other civil society groups. OpenMedia is also playing an important role in this situation. Thank you for taking the time to carefully consider my request.

I hope that we can work together as parliamentarians to respond to Canadians' questions in this regard.

Privacy June 7th, 2013

Mr. Speaker, it is clear that Conservatives do not take the privacy of Canadians seriously. The commissioner herself has raised concerns about Bill C-12. To paraphrase the Privacy Commissioner, the Conservatives are taking a soft approach when it comes to protecting Canadians' privacy online.

The commissioner made it clear. The present lack of oversight for online snooping is putting Canadians' privacy at risk.

When will the Conservative government agree that we need a tougher law, better oversight, and reporting mechanisms? When will the Conservatives start protecting Canadians' privacy online?

Privacy June 7th, 2013

Mr. Speaker, in her report released yesterday, the Privacy Commissioner was clear: Canada has fallen behind when it comes to privacy matters.

The law is quite simply archaic, because it was designed before Internet fraud, cyberbullying and the theft of personal information, which now dominate the headlines.

The NDP introduced Bill C-475, which seeks to bring the Privacy Act into the digital age.

Why not support these practical solutions?

Petitions May 30th, 2013

Mr. Speaker, today I am presenting a petition from people in my riding who support my bill, Bill C-475, which is designed to better protect the personal information that Canadians put online.

Those who signed the petition lament the fact that the laws protecting our personal information online have not been updated since the first-generation iPod was released. They would like to see my bill passed in the House.

Personal Information Protection and Electronic Documents Act May 23rd, 2013

Mr. Speaker, I would like to thank my colleague who also works very hard on the protection of personal information.

As I pointed out in my speech, the bill introduced by the government dates back to 2007. It is no longer pertinent or practical and does not address the risks that are present today, in the digital age, in 2013. The threshold proposed by the Conservatives is very subjective. It would allow organizations to carry out their own assessment of the situation and the risk present even though these organizations are often not in the best position to carry out such assessments.

I am proposing that, when there is a risk, all organizations report it to the commissioner. It will then be up to the commissioner to examine the risk and the loss of data and to decide whether the risk of harm is serious or not. That is what we must implement.

I invite all members of the House to bring our privacy protection laws into the digital age to ensure that they address clear and present risks.

Personal Information Protection and Electronic Documents Act May 23rd, 2013

Mr. Speaker, I thank my colleague who also worked very hard. He studied social networks and privacy with us in committee.

With respect to his first question, I would say that it is a private member's bill and therefore cannot incur costs or expenditures. That is a short answer to an interesting question.

In response to his second question, the Privacy Commissioner released a report today indicating the changes she would like to see in the law protecting privacy. She has some excellent suggestions, which correspond exactly to what I am proposing in my bill.

There is real consensus among experts on the protection of privacy and the Office of the Privacy Commissioner. These measures have the support of a substantial portion of the population. We must move forward with these measures.

Personal Information Protection and Electronic Documents Act May 23rd, 2013

moved that bill C-475, An Act to amend the Personal Information Protection and Electronic Documents Act (order-making power), be read the second time and referred to a committee.

Mr. Speaker, it is with deep conviction that I initiate the first hour of debate on my Bill C-475, the purpose of which is to bring the Personal Information Protection and Electronic Documents Act into the digital age.

I would like to begin by reading from a statement by the Privacy Commissioner, Jennifer Stoddart, released this morning:

“PIPEDA is not up to the task of meeting the challenges of today--and certainly not those of tomorrow”.

It is therefore no surprise that she should have said this, because this legislation has not been updated since the arrival of the first-generation iPod. Matters evolve very quickly in the digital age, and the law is no longer relevant.

Millions of Canadians have never known a world without smart devices. It is an eternity in a modern society undergoing constant change, as ours is.

The Internet is central to our lives, because we use it daily. It is not surprising, therefore, to learn that Quebeckers and Canadians will spend about 45 hours a week online in 2013, that over 70% of Canadians use the Internet daily, and that our fellow citizens have more than 18 million Facebook accounts.

Canada as a country is firmly plugged in. For a few years now, laptops and devices like tablets have been used both recreationally and as working tools. They occupy an increasingly crucial place in our lives. We are moving more and more towards digital management of our lives. This major change means that new rules must be put in place and that they must reflect the new risks associated with these developments in the digital world.

Since the beginning of this year alone, we have witnessed serious losses of data, including data on 52,000 Canadian investors in February and more than 50 million clients of LivingSocial in April.

The Privacy Commissioner of Canada recently stated that breaches of personal data have been steadily increasing in recent years. In that connection, a study by Telus and the Rotman School of Management at the University of Toronto, published in 2011, showed that each public company experienced an average of 18 data breaches a year.

Unfortunately, the current legislation designed to protect Canadians’ privacy has not been updated to address these risks and put appropriate measures in place to protect society. The current legislation does not provide for Canadians to be notified of a breach of their personal information. Organizations are not in fact required to notify them, regardless of the seriousness of the breach. This means that our fellow citizens cannot take appropriate action to protect their identity or their credit in order to reduce any harm they might suffer.

I am referring in particular to our passwords, social insurance numbers, personal emails or even the bank account numbers needed to make online purchases. The sharing of personal information with third parties, without consent, is a major problem in Canada.

In September 2011, the Privacy Commissioner noted that a quarter of the most-visited websites in Canada do not comply with Canadian law; they disclose our data without our consent. This bothers me a great deal, particularly when I think of children, the elderly and people who have not had the good fortune to learn how the Internet works and what the risks are. What is much worse is that companies that decide to do this do not currently suffer any consequences.

For more than 10 years, Canadians have been waiting for a better regulatory framework. They are rightly expecting results along those lines, and it is in that spirit that I decided to introduce Bill C-475. The bill proposes two simple and effective mechanisms to improve protection of Canadians’ personal information.

First, it requires that the commissioner be notified by any organization having personal information under its control when there is a possible risk of harm to users.

Experts in the commissioner’s office will assess the seriousness of the situation against a criterion for harm that sets a high standard. They will also recommend whether or not the organization should notify the users affected.

This mechanism allows for an objective analysis of the risk and better management of the risk through an expectation of a high level of security, rather than a subjective analysis based on the interests of the organization, which may differ from the interests of users.

The process will restore to Canadians the power to take steps to protect themselves much more quickly, in addition to reducing the harm done to them.

The second mechanism provided for in Bill C-475 is based on the Alberta model. It is designed to give the Privacy Commissioner order-making power when an organization fails to obey the law. The Federal Court would have legislated authority to penalize organizations that fail to carry out an order issued by the commissioner.

These mechanisms are straightforward and clarify the commissioner’s powers. In short, the Office of the Commissioner will now have the power to enforce the law, which unfortunately is not now the case.

By providing better oversight of organizations and the use of personal information to which they have access, Bill C-475 gives Canadians an assurance of acceptable risk management and the right to protection of their information. This bill was drafted to address the concerns of Canadians, people in the digital industry, civil liberties organizations, Internet experts and specialists in the protection of privacy.

I had the opportunity to hear a great deal of evidence from experts during a study the Standing Committee on Access to Information, Privacy and Ethics conducted on social media and privacy from May to December 2012.

Bill C-475 is a direct response to requests from the community to adapt the law to suit our digital age by providing some flexibility for people in the industry and clarifying the ombudsman’s role of the Office of the Commissioner.

Moreover, during many consultations specifically discussing the bill, the same conclusions emerged. The bill therefore takes a very balanced approach. It is balanced with regard to Canadians, since objective risk analysis will ensure that they are not bombarded with notifications of data breaches that do not affect them at all or present a minimal risk. The bill is also balanced with regard to companies, since clear roles and processes enable them to plan their policies and response.

It will be clear for organizations that they are required to report a breach to the Office of the Commissioner, but they will not be responsible for deciding what the ultimate risk is. Companies that are law-abiding will no longer have to compete with companies that are not.

Lastly, the bill makes it possible to bring our privacy protection legislation up to the same level as countries like Germany, Great Britain, Australia and France, or indeed to the level of provinces such as Quebec and Alberta.

As a world leader in technology, Canada should be adopting international standards.

Bill C-475 offers a different vision from that proposed by my colleagues opposite, who in 2007 introduced Bill C-12, which is no longer supported by the Privacy Commissioner. They will probably tell me they have already introduced a bill to modernize the Privacy Act, but I would like to remind them that it dates from 2007 and is absolutely not representative of our day and age, particularly when you consider that technology changes extremely quickly.

Bill C-12 was introduced in the House, but there has been no debate for six years, and its content has therefore become outdated. It certainly no longer represents a serious attempt by the government to modernize the legislation in order to better protect the public. Moreover, a problem with the mechanisms proposed in Bill C-12 to deal with a breach shows that it is completely inadequate.

The risk threshold for notifying the Office of the Commissioner is very low and subjective. This poses two major problems. The first is that because the threshold is low, users and the Office of the Commissioner will be notified less often in the event of a breach.

Organizations could avoid notifying those concerned, which poses a major problem with regard to their security. Nor will they have the power to protect themselves and reduce the potential harm to which they are exposed.

The second problem is that experts testifying before the Standing Committee on Access to Information, Privacy and Ethics explained the need to obtain better data in order to gain a better understanding of the cybersecurity risks Canadians face every day. A low, subjective threshold reduces the data to which they will have access, which makes them less able to advise the government and companies on the risks associated with their practices.

My bill establishes an objective threshold, and the Office of the Privacy Commissioner will be mandated to assess the risk associated with a breach. The interests of Canadians, which we in this House have the responsibility to protect, will be paramount.

Quebeckers and Canadians support the measures and principles in my bill. In April the Office of the Privacy Commissioner published a cross-Canada survey showing that 97% of Canadians would want to be notified by an organization if their personal information was compromised. Note that this is the overwhelming majority. In addition, 80% of respondents would also grant more powers to the Office of the Privacy Commissioner. Again, a large majority of Canadians supported these measures.

My bill has garnered support from all classes of stakeholders affected by these changes, including industry representatives, civil liberties organizations, consumer protection agencies and academics specializing in law, communications, cybercrime and political science. I could go on, but there are too many to name them all.

The Union des consommateurs has stated that:

[it] believes that the implementation of the principles proposed by the NDP, through their private member’s bill amending the Personal Information Protection and Electronic Documents Act, constitutes a real advancement to better protect the privacy of consumers.

Michael Geist, chair of Internet and e-commerce law at the University of Ottawa and renowned public affairs pundit, has said about my bill that:

Bill C-475 is a far better proposal.... Those provisions would do far to ensure a greater respect for Canadian privacy law and give Canadians the assurance of notifications in the event of security breaches.

Steve Anderson, executive director at OpenMedia.ca, stated that:

We welcome...[this] online privacy bill because we think it's a tool that can later be applied to protect our privacy against reckless warrantless access to our private information by government authorities. This bill is a useful stepping stone to safeguard our privacy.

Canadians trust us to act in their best interests. They clearly want us to give them better protection. By voting for Bill C-475, my hon. colleagues will be giving them the reassurance of stronger support for their rights and the power to protect their privacy.

Economic Action Plan 2013 Act, No. 1 May 7th, 2013

Mr. Speaker, I congratulate my hon. colleague on his excellent speech, which contained a great deal of information and was very well thought out, written and delivered.

The Conservative member who spoke before him said that NDP members are always so negative, that we think there is absolutely nothing good about this budget, that we cannot find any good measures in it. From my perspective, and that of my constituents, this budget is very hard to support. It amends nearly 50 pieces of legislation, and unfortunately, we are under a gag order and will have only five committee meetings to examine this budget implementation bill. The Conservatives' way of doing things is extremely problematic.

I would like to hear my colleague's comments on this, as well as what his constituents think of these measures.

Privacy April 24th, 2013

Mr. Speaker, the minister's answer is cold comfort to the farmers, students, veterans and unemployed whose privacy was compromised. These are privacy problems on a massive scale and now we also learn that the tracking system for dealing with these problems has also failed.

A million Canadians had their privacy compromised on 3,000 separate occasions, yet the Conservatives failed to put a system in place to track this serious problem. Why is no one tracking these breaches of personal data?

Privacy April 24th, 2013

Mr. Speaker, more than a million Canadians have been affected by data and privacy breaches, and that is the government's response? Canadians deserve better. The information about these data breaches was made public because the NDP pushed for it. There have been more than 3,000 privacy breaches, yet only 13% of those cases were reported to the privacy commissioner.

Why did the Conservatives not feel it was necessary to report these breaches to the commissioner?