:
I call this meeting to order.
I want to thank everyone for joining us.
First of all, I apologize for all the emotions you may have gone through over the past few hours. I'm thinking in particular of the clerk. There were changes in schedules, votes, assigned seats, unassigned seats, reassigned seats and so on. I thank you all for your kindness and indulgence.
Welcome to meeting number 36 of the Standing Committee on Public Safety and National Security.
We're meeting today as part of our study on Bill , an act respecting lawful access.
First, I'd like to welcome the witnesses, who are all senior officials. The ministers will be joining us in about an hour.
We have with us, from the Canadian Security Intelligence Service, Ramzi Nashef, director general; from the Department of Justice, Kimberley Gibner, Normand Wong and Anne‑Marie LeBel; from the Department of Public Safety and Emergency Preparedness, Shannon Hiegel, Mike McGuire and Fenton Ho; and from the Royal Canadian Mounted Police, Richard Burchill.
Mr. McGuire, we'll start with you, please. You have the floor for five minutes.
:
Thank you, Mr. Chair and honourable members of the committee, for having us here today.
My name is Mike McGuire. I'm the director general of international and border policy at Public Safety Canada. I'm pleased to be here with colleagues, as was just mentioned, from the Department of Justice, the Department of Public Safety, the RCMP and CSIS to answer technical questions on Bill , an act respecting lawful access.
Lawful access is a familiar issue that has been studied by Parliament in the past, most recently by the National Security and Intelligence Committee of Parliamentarians, which issued a special report last year calling for lawful access legislative reform.
[Translation]
Bill C‑22 seeks to address fundamental and well-documented gaps in Canada's lawful access framework. The online environment has facilitated, if not fostered, the communication, coordination and concealment of criminal activities and those of threat actors. The widespread use of mobile devices, Internet-based communications, messaging platforms and other emerging technologies has fundamentally transformed how crimes and threats to national security are planned, executed and investigated.
At the same time, Canadian police services and CSIS face increasing challenges in obtaining information critical to investigations in a timely manner. Bill C‑22 seeks to address these challenges while maintaining strong safeguards, including respect for the Canadian Charter of Rights and Freedoms and the protection of Canadians' privacy.
[English]
The provisions in Bill are grouped under two key themes. First, part 1 of the bill modernizes Canada's legal authorities to support police and CSIS in obtaining timely and lawful access to digital information needed for investigations, with each tool carefully designed to take into account the type of information that will be collected and the privacy interest it engages.
This includes the creation of a new confirmation of service demand, which would allow police to confirm whether a telecommunications service provider offers or has offered service in relation to a specific identifier, for example a specific telephone number or IP address. The scope of this tool has been deliberately limited to a yes-or-no confirmation, and it pertains only to telecommunications service providers.
Part 1 would also create a new production order from narrowly defined subscriber information, such as name, address and basic information about the services provided, and update existing search warrant powers to better reflect computer searches.
In addition, it would establish new authorities to facilitate lawful requests from Canadian law enforcement to foreign electronic service providers and enhance international co-operation in criminal matters involving electronic data.
These measures are intended to ensure that where lawfully authorized, investigators are able to act in a timely and effective manner, bearing in mind that delays can result in serious and ongoing harm to victims in particular cases and circumstances.
[Translation]
Part 2 of the bill establishes a clear and modern legislative framework to ensure electronic service providers have the technical capacity to effectively respond to lawful access requests, meaning access already approved under existing legislation, such as the Criminal Code or the Canadian Security Intelligence Service Act.
Canada is the only western democracy without a comprehensive legal framework requiring electronic service providers to develop and maintain such technical capabilities. With the exception of an antiquated licensing regime dating back to the 1990s, collaboration in this area remains largely voluntary and uneven.
Part 2 of Bill C‑22 sets for core providers minimum technical capability requirements aligned with international standards and provides the Minister of Public Safety with the authority to issue targeted and flexible ministerial orders when specific capabilities are required to meet operational needs.
[English]
Safeguards related to this new framework are embedded in the bill. For example, ministerial orders would be subject to approval by the intelligence commissioner and would be proactively reported to NSIRA. Privacy and cybersecurity considerations are explicitly included in the legislation. Data retention obligations are restricted, and public annual reporting is required.
This part does not create new powers for law enforcement or CSIS to intercept communications or obtain information, nor does it allow direct government access to electronic service providers' systems. It also explicitly prohibits the creation of systemic vulnerabilities, to ensure that a regulation or ministerial order does not weaken encryption or create back doors.
Finally, part 2 establishes tools to promote compliance, including inspections and administrative monetary penalties.
[Translation]
Together, these mechanisms aim to ensure Canadian law enforcement and intelligence agencies have the tools they need to do their important work while maintaining strong accountability and transparency.
Mr. Chair and members of the committee, my colleagues and I would be happy to answer your questions.
:
Thank you very much, Chair.
Thank you to all of our witnesses. It's so great to have so many people here around the table for such a complex issue. We're going to get to know each other very well in the coming two parliamentary weeks.
I never know who to direct my questions to, because there is a lot of expertise here. Whoever is best to answer this, please let me know.
I've looked at the definitions. I've looked at the definitions of “systemic vulnerability”, at how it incorporates the definition of encrypted data to some degree, and at the provision, in part 2, that says a service provider does not have to do anything that would create a systemic vulnerability. I'm going to ask a very direct question. Will this bill cover encrypted data? Secondly, is it intended to be that way? I assume that would be yes. Will this bill cover encrypted data? Could somebody please help me with that?
:
Thank you very much, Mr. Chair.
Mr. McGuire and Ms. Hiegel, my questions will be on the technical side, so I believe you will be answering.
As we examine the evolving landscape of public safety and national security, it's essential to clearly understand the role of metadata. Metadata is often described as data about data that does not capture the content of communications but rather provides contextual information such as time, location, duration, origin or destination of digital interactions.
While it differs from content data, metadata can, in specific circumstances, support analytical insights and help identify patterns that are relevant to operational needs. This makes metadata a valuable operational tool for law enforcement and intelligence agencies, and it plays a critical role in enabling threat detection, risk assessment and investigative efficiency, particularly in an era when digital activity is deeply embedded in our daily lives.
Please correct me if I was wrong about or missed anything regarding metadata, but given this context, could you please clarify the scope of the information that law enforcement would be authorized to access under the legislation, and specifically confirm how metadata is distinguished from the content of communications in practice?
:
I'll start off and, if you don't mind, I'll turn it over to my colleague, Fenton. Then, if you'll give me a few minutes, I'll turn to the RCMP and maybe CSIS to explain how important metadata can be in their operations.
As you can see within the bill as it currently stands, we have not given a lot of specificity to what elements of metadata we plan on regulating. That's because we need to take the time to assess that with our investigative bodies and speak with industry about the ability to retain various types and for how long. We certainly do not assume.... Where we note that it's up to a period of one year, the expectation is not that all metadata points will be kept for up to one year. That's why there's a time period.
We've looked at international comparisons on this front, and we've come in about the middle. Australia holds its metadata for two years, and the U.K. holds it for about a year. There's always a bit of small print there, but generally that's what it is.
Through that process, we expect to narrow down what very specific types of metadata are the most important for investigations and then apply a timeline to that within the regulatory process. We will do our charter challenge at that point.
Fenton, is there anything you might like to add?
:
However, you didn't consult the current chair of the agency.
I'm going to ask a question I've asked the Department of Justice team many times in the House. I'm not a lawyer, so I'd like to understand why you chose the lowest threshold for obtaining information.
I think reasonable grounds to “suspect” something seems like a very, very low threshold for obtaining information. Reasonable grounds to “believe” something would be a higher threshold. I don't understand why you chose this one.
Could you give us some examples of what reasonable grounds to suspect something might be? I have a hard time imagining what wouldn't be acceptable. I think any reason to suspect something can be reasonable. That part of the bill worries me. Could you give us tangible examples of what might be reasonable grounds to suspect something?
I would need that. I'm not a lawyer, and I'd like to get a better understanding, if I could.
I'd like to use the time I have left to understand something else. In part 1 of the bill, it says that “telecommunications service provider has the same meaning as in subsection 2(1) of the Telecommunications Act”, whereas part 2 of the bill talks about an electronic service provider and a core provider. However, there is no definition in the schedule.
I want to understand why this very broad regulatory power is being given in definitions. People are wondering whether they'll be affected. Can you explain why there's no definition, why there's nothing in the schedule and why everything will be decided by regulation?
Thank you to the witnesses for being here today.
I'm going to start with Mr. McGuire.
Something I find contradictory in this bill—maybe you can explain how it's not contradictory—is that you're requiring electronic service providers and telecoms to create the systems to enable the interception of communications within their networks, yet later you say that nothing in this bill seeks to undermine the integrity of encryption networks. That seems very contradictory to me.
In light of the Salt Typhoon hack we saw in the United States.... It was later found that it was exactly the vulnerabilities created by the requirements under U.S. law to create these encryption back doors that allowed hackers to access this information.
Can you explain what this contradiction appears to be?
It's been helpful to have the officials. One thing I will say at the outset is that I feel like we need three hours with you. I don't say this in jest. This is a highly technical bill. We can't rush this. I have a list of about eight things I want to ask you about.
I'm looking up case law further to Madame DeBellefeuille's earlier point about the threshold of “reasonable grounds to suspect” versus “reasonable grounds to believe”. I haven't studied reasonable grounds to suspect in years. With regard to reasonable grounds to believe, I'm familiar with the Storrey decision that a person must subjectively believe that what they're doing is reasonable and that it must be objectively reasonable.
That probably means nothing to a lot of people, but these are difficult things to comprehend. When we're wrapping our heads around this, I think having you here for only one hour prior to clause-by-clause consideration is inadequate. I think we need you here a whole lot more, to be very candid. I'll leave that with you and with the chair and with my Liberal colleagues, because we have lots of questions, and I know I've just burned a minute here.
This is an important question that comes to the requirement for an electronic service provider to retain data for one year. Is that a de facto seizure that runs contrary to section 8? I understand that a search warrant is required, and that would be the search aspect. Normally there's the search and then the seizure. Is the compulsion to retain data a seizure in itself?
[English]
It's always fascinating to listen to my colleague Mr. Caputo.
First of all, let me start by saying thank you so much for being here.
Obviously, I'm strongly in favour of this bill. As I said in the House, I think we need a modern access regime. I think we need to deal with Bykovets and Spencer and have proper legislation that allows us to deal with things like that.
I also had a couple of questions, if that's okay, with respect to the way systemic vulnerabilities interplay in this bill, in proposed subsections 5(5) and 7(5) of the bill versus proposed sections 12 and 13. Basically, what I understand from proposed subsections 5(5) and 7(5) of the bill is that a provider is not required to comply if a systemic vulnerability would be created. I think I have that right. However, proposed section 12 says, “An electronic service provider that is subject to an order made under subsection 7(1) must comply with it.” Then proposed section 13 specifies that orders take primacy over the regulations that will be made.
I don't really understand, personally, the interplay here, where we're saying that somebody is not required to comply if it creates a systemic vulnerability, but then if there's an order, they're required to comply with it, and then the order supersedes regulations.
Can you talk me through this so that I understand how 5(5) and 7(5) actually work?
I'm sorry, MP Caputo. We have run over the time.
We are going to suspend now, since, as we have seen, the has entered the room.
Thank you, officials. Many of you will stay.
[Translation]
We will resume the meeting in a few minutes. The meeting is suspended.
:
I call the meeting back to order. Thank you, everyone, for coming back.
I'd like to welcome the two ministers and the officials accompanying them, starting with Minister Gary Anandasangaree, MP and Minister of Public Safety. I would also like to welcome Minister Sean Fraser, MP and Minister of Justice.
Welcome to both of you, ministers. We'll begin with an opening statement from the Minister of Public Safety, followed by the Minister of Justice.
Mr. Anandasangaree, you have the floor.
[English]
I would like to start by acknowledging that we're meeting on the traditional and unceded territory of the Algonquin Anishinabe people.
[Translation]
Thank you for inviting me to appear today to speak about the proposed Bill .
[English]
I also want to acknowledge my colleague, the , as we've been working on this bill for a number of months, and also the officials who are here to support us.
As Minister of Public Safety, my top priority is to ensure that every Canadian remains safe and secure. Since my appointment, I've heard clearly from law enforcement at all levels—municipal police services and the RCMP—as well as victims groups such as the Canadian Centre for Child Protection. They've all said that Canada needs modern tools to take on the wide array of illicit activities that are facilitated by the global digital environment.
Technology has fundamentally changed the nature of crime and threats globally. Criminals are continuously exploiting the digital space we all use, in order to facilitate a wide array of offences. This includes extortion, childhood exploitation, auto theft, terrorism and human trafficking. Furthermore, this environment is being used to facilitate foreign interference and violent extremism.
Our laws have simply not kept pace with our digitally driven world. This has created a significant gap between today's crimes and threats and what our current laws can meaningfully address.
[Translation]
We have a duty to Canadians to address these new threats.
[English]
This is what Bill aims to do.
It's worth taking this opportunity to highlight that Bill does not aim to regulate the Internet, police activity on the Internet or require Internet service providers to become agents of the government, as some of the debate in the House has suggested.
As our officials have confirmed, Bill is encryption-neutral. It is simply to address gaps in our legal framework that present challenges to timely access to information and intelligence that are vital to conducting investigations. It will give our officers the tools they need to keep Canadians safe in the 21st century, while ensuring we continue to uphold Canadians' charter and privacy rights.
[Translation]
We listened to the concerns of stakeholders and other parliamentarians after the tabling of Bill .
[English]
Part 1 of Bill includes important safeguards, such as limiting the scope of confirmation of service demand to telecommunication service providers; a narrow definition of subscriber information; and strong judicial oversight. Police will still require court approval to obtain personal details like names, addresses and phone numbers.
Under part 2 of the bill, we'll ensure that electronic service providers can fulfill lawful access requests. Let's be clear: This part does not create new authorities for law enforcement agencies and CSIS to intercept communications or obtain information. Its focus is to ensure that electronic service providers are able to comply with existing legal orders, which are found in the Criminal Code and the Canadian Security Intelligence Service Act. Key elements include a new compliance framework that will require core providers to have the technical capability to comply with legal authorization to obtain information, such as warrants and production orders.
It would also give new ministerial order powers to the Minister of Public Safety. Only with approval from the intelligence commissioner, the minister could order an electronic service provider to develop specific technical capabilities: for example, to address new technologies that are developed but not captured in the regulations.
Finally, it introduces regulatory enforcement tools, such as administrative monetary penalties for any provider that does not comply.
Once again, I wish to underscore the safeguards that would be in place under this part of the bill. As I mentioned, all ministerial orders will require prior approval from the intelligence commissioner to ensure they are reasonable.
This part also includes an explicit safeguard to prevent the introduction of systemic vulnerabilities in electronic protections. Our government does not support the creation of back doors.
We want Canadians to see exactly how these powers are being created and used to ensure that their implementation is subject to the highest levels of democratic scrutiny. Under our current laws, our police and intelligence officers are trying to fight tech-savvy criminals and state actors with tools that are decades old. Bill would bridge that gap, while upholding the charter rights and the privacy of all Canadians.
[Translation]
Thank you. I look forward to your questions.
Before I begin my opening statement, I'd like to thank everyone for being here to take part in this very important debate.
I think it's important to understand the context of this bill. To improve public safety, we have a strategy built on three pillars. The first is to strengthen criminal laws, particularly with Bill , Bill and Bill .
That said, we recognize it's not enough just to make changes to criminal laws. We also need to support those working on the ground in our communities, such as community organizations and police officers. It's not enough to increase the number of people working in the communities. We also have to give them the tools they need so they can meet the expectations we have for the officers on the ground.
We also need to invest to prevent crime and violence in the long term. That includes making investments in affordable housing, making investments so people with mental health issues can have medication and making investments to support young people who have issues in their lives.
[English]
This bill is focused on that second pillar, supporting those who are on the front lines trying to make Canada safer every day. We can't expect people to address modern challenges with outdated technologies. That's where this bill comes in.
When we compare Canada with other partners around the world, we are significantly behind when it comes to addressing modern challenges, particularly in a digital context. Technology has changed. The world has changed. Crime has changed. It is faster-moving. It crosses borders. It is digital on an increasing basis. We've seen that other jurisdictions have embraced what we are discussing and calling “lawful access”. Very simply put, it's the ability of law enforcement to get access to the evidence they need that may be digital in nature, the same way we would allow them to get access to evidence that exists in the physical world. You can't arrest an IP address or a phone number.
We need to give tools to ensure that law enforcement has the ability to figure out, where there is a criminal investigation going on, who is the person behind it and how they can advance that investigation. When I look at the actual process we've laid out, I think it's important that we demonstrate to Canadians that we have put significant thought into ensuring that privacy rights are protected, in the same way that we embrace the recommendations of law enforcement to make it easier for them to do their jobs.
In particular, to start off, what we're allowing under this legislation is for law enforcement, when they have an investigation involving a phone number or an IP address, to make a simple request of a service provider: “Is this on your network?” If the network comes back and says it is, that would allow us to move forward with a process, which would be approved by a judge, to say, yes, there is a person with a name and an address attached to this. Currently, this process can take months. When we're dealing with people who are involved in criminal organizations—engaging in child sexual exploitation, engaging in drug trafficking and human trafficking, organizing home invasions and auto theft rings—you can appreciate the need to move quickly. It is essential if we're going to reduce the ultimate consequences of crime to Canadian communities.
This bill, in my view, provides the appropriate framework that empowers law enforcement to have the tools they need to keep Canadians safe, but it puts protections in place to ensure that, where appropriate, judicial authorization remains essential, and we put a system in place so that service providers actually do hold the information that will help facilitate these investigations.
Let me perhaps sum it up simply: We are not going to solve Netflix problems with Blockbuster technology. We have to join the advanced economies in the world that have been working to solve these problems for many years. With the support of different parties at this committee, I think we have the potential to send a strong signal to Canadians that when it comes to public safety, we will make absolutely sure that law enforcement has the tools they need to keep Canadians safe.
[Translation]
Thank you, Mr. Chair.
Thank you to the ministers and officials.
I'll note that we have two Kamloopsians at the table today. That's always wonderful.
Minister Anandasangaree, you're off the hook today. We won't be asking you about visas and who gave people from the IRGC a visa. We'll stick to Bill here.
I want to go into something you mentioned, Minister. You talked about this being encryption-neutral. One of the greatest concerns I'm hearing about is encryption. Please don't defer to the analysts. I want to hear your perspective on this. This bill could threaten encrypted communications, based on the way it is written or the way some people are reading it.
Can you confirm that the purpose of this bill is not to go after end-to-end encryption, as in party A is using a program to deal with party B that is encrypted and there's no way to decrypt it? Can you confirm that this is neither in this bill nor the intent of this bill?
:
I'll be blunt, Minister. The Liberal government now has a majority. There is a concern that, if there is room there, it won't be addressed.
That's why I'm asking you, on the record, if there's a chance that encrypted communications can be targeted by this bill. If that's not the intent of the bill—that's what you said—I don't think it's too much to say, “Yes, Mr. Caputo, I would support an amendment to ensure that our intent is clear.” For instance, that could be an amendment that includes a definition of encrypted data in part 2 or an amendment that says that “systemic vulnerability” includes a key to encrypted data and the creation thereof.
With all due respect, Minister, I don't think it's difficult to say, “Yes, that's our intent.” Do you not agree?
:
The difference with Bill , though, Minister.... If you want to get into Bill C-8, that is exactly my cautionary tale. The Liberals voted against just about every amendment that was of consequence. It was the Conservatives and the Bloc that voted for those amendments, that swayed those amendments, with the government often voting against them. Now things have changed. With all due respect, Bill C-8 is not a great example to use. That's why I'm trying to get it on the record.
I think I've made my point. You've made your point. Let's move on.
The ministerial order is one of the biggest things. One of them, as I said, is encryption; another major issue is the degree to which enforcement and definitions are left to regulation. That's one of the primary criticisms of this bill.
I look at proposed section 5, for instance. This is sweeping powers. Proposed paragraph 5(2)(b) says, “the installation, use, operation, management, assessment, testing and maintenance of any device”. Proposed paragraph 5(2)(d) says, “the retention of categories of metadata”. Minister, I get why the government wants things to be broad; it's because then you can account for things. However, should we not be defining things where we can define them? I'm pretty sure we're going to have experts who say, “Do you know what? We can define categories of metadata.” I'm sure we can define categories of metadata. Those don't change every day.
Would you be open to an amendment that says that when we're looking at taking information from people over which there's a high expectation of privacy...? I trust you would support an amendment that would define those types of things.
Thank you to our ministers for attending today.
Minister Anandasangaree, in Brampton, we have seen a concerning rise in crime of any and all types, from car thefts to robbery, breaking and entering, murders and shootings in broad daylight. I'm worried about the safety of my constituents and all residents of Brampton, and they are as well. Our mayor, Patrick Brown, and Peel Regional Police chiefs have been calling for legislation like Bill and have welcomed this bill's introduction.
With that local context in mind, can you describe the specific threats this bill is designed to respond to and the real-world operational gaps facing law enforcement and CSIS today that Bill would close?
:
Let me acknowledge the work of Peel Regional Police in informing us on the development of this bill. It's been quite critical. I've had conversations with Chief Nishan Duraiappah on a number of occasions.
This is the number one priority as indicated by police leaders, not just in Peel, but across Canada at every level, whether it is Commissioner Carrique in Ontario with the OPP or Commissioner Duheme at the RCMP, as well as regional police services. This is of critical importance.
In a granular sense, the technology we have today is inadequate to deal with the types of issues we're dealing with. Primarily, telephones, the Internet, emails and electronic devices are used on a day-to-day basis for the execution of crime. Extortion, for example, is oftentimes done by way of a phone call or a text, or sometimes by email. Over the years, all of this has meant a great deal of delay for law enforcement to be able to get production orders. Oftentimes, they have to wait weeks, sometimes months, to get the information that will enable them to go to the next step.
Essentially, what we're doing here.... I'll use the example of a phone directory or Bower's reverse lookup, which can be found at a local library. If you have a phone number, you can go to the Bower's directory, put the phone number in and get the address of the individual who owns the phone number. Right now, these are often anonymous, which means that we need to go to the service provider. If it is a telco, we need to go to the telco and ask if this particular telephone number is associated with their service. It takes weeks, sometimes months, to get that information.
Bill would, as a starting point, enable law enforcement to get what's called confirmation of service. That will say whether this phone number is attached to the service the telco provides. Once that information is obtained.... It's a yes-or-no answer. If it's a no, the matter stops there. If it's a yes, then a production order, a warrant, will need to be prepared, seeking subscriber information on the individual whose phone number may be associated with the telephone company. Based on the warrant, we will get basic subscriber information, which would be their name, email address and so on.
Beyond that, any additional information that is required will go back to what we do right now, which is go back to court, all under judicial authorization, to be able to get the type of information that's required for that investigation to continue. Essentially, an investigation that takes months could take weeks, based on the additional provisions that are provided within this bill.
:
I would say that we've had a number of engagements. The Honourable Murray Rankin engaged in some mediation sessions and advised us on near consensus. I wouldn't say there was consensus, but there were civil liberties organizations and industry representatives present. We had law enforcement, as well as community advocates in different conversations.
What we have here is an area where I think there is a great deal of understanding and acceptance. It is not perfect. Not everyone is 100% behind this. There are concerns that people continue to express, but, by and large, this reflects.... Even with law enforcement, we have had to curtail.... You will see some significant changes in Bill from Bill , for example narrowing and defining certain aspects of what is included.
We have done an enormous amount of work to build what we think is as close to a consensus as we can get. We won't get full consensus. I think the work we need to do is make sure that all the safeguards are in place. We are fully confident that both privacy and charter rights concerns are addressed in this bill. Some would like us to go further. Some would like us not to have a bill whatsoever, but that is not an option for us.
Thank you very much, ministers.
Mr. Fraser, I don't really have any questions for you, but I honestly want to congratulate you on your French, which has greatly improved.
Mr. Anandasangaree, the Support for Authorized Access to Information Act, enacted by part 2 of the bill, provides for a limited role for the National Security and Intelligence Review Agency, the NSIRA. However, we've noticed that there are comparable legal access mechanisms among our Five Eyes partners that come with a more formal independent oversight role. Australia is an example, where the Telecommunications and Other Legislation Amendment (Assistance and Access) Act of 2018 mandates the NSIRA's counterpart be notified of the issuance of technical assistance orders within a specified period of time.
According to Bill , a year later, you have to provide the agency with an unredacted report, and, if I'm not mistaken, you have 90 days to do so. This means you're handing this report to the review agency about a year and a half after the fact or after the decisions were issued.
You've drawn inspiration from the Five Eyes for your bill, so why don't you want to give the agency a role as important as the one given by Australia to their oversight body?
:
I'm sorry to interrupt, but I've already read that. I came prepared.
I find the Canadian agency is somewhat sidelined and I'd like to understand why. I know the intelligence commissioner has a role, but why isn't the agency notified in real time? It's hard to conduct an investigation into whether the agencies involved, such as the RCMP or the Canadian Security Intelligence Service, are complying with the law when you get the facts almost a year and a half later.
I'm letting you know I'll be proposing an amendment so the review agency is notified in real time, similar to the Australian model, because I think that's our guarantee. It's a bit like entrusting the government by ensuring the review agency, whose primary mission is to conduct oversight, is notified in real time, like the intelligence commissioner.
I was also surprised to learn from your team that the various consultation groups organized to study Bill C-22 didn’t consult Ms. Deschamps, the current agency chair. That doesn’t make sense to me, honestly. We look to our Five Eyes partners for best practices, yet we fail to include an important role for the agency in Bill C-22. Would you be willing to discuss the idea of notifying the agency in real time?
Ministers, I appreciate your being here.
I appreciate what you say about supporting our frontline officers. Lawful access has been called for over many years. I do think, though, that we have to be careful not to rush something through. We need to get it right. We need to balance, as parliamentarians, our duty of care that we are protecting the privacy of Canadians. My questions will be based on that. I think we have to be careful not to race to royal assent. We have to do this right.
More than a decade ago—I don't know if you're aware of this—your party warned against a bill very similar to this. It was a lawful access bill. They said it risked turning Canada into a surveillance state. Today you are advancing similar powers, but actually in a more expansive form, with Bill . In fact, , our current Speaker of the House, was at the time the Liberal public safety critic. He warned that similar lawful access legislation, in his words, risked “creating an Orwellian service state”.
My question for you is this: Was he wrong?
:
Thank you very much, Mr. Chair.
I was in Parliament the day went after Vic Toews with respect to the lawful access legislation at the time, and I distinctly remember Minister Toews saying that either you're with the government or you're with the child pornographers. I remember the proliferation of the hashtag “TellVicEverything”, because there was a widespread perception at the time that the legislation was an overreach. Right across the country, there were people who were providing Minister Toews with information about spilling soup on their tie, because they felt that perhaps Vic was interested in everything, with the measures he was taking to trample privacy and the over-the-top rhetoric that was being used at the time to support it.
I'd like to bring Minister Fraser into the conversation.
Minister, in your opening remarks, you talked about the protection of privacy and compliance with the charter in that regard. Can you talk a bit more about the protection of privacy and the compliance with the charter and the efforts that have been made in this legislation on the two?
:
Look, to help us get there, I want to provide a bit of context.
Ms. Kirkland, when she led her questions, talked about this debate going on for a few years. It hasn't been going on for just a few years; it's been going on for 30 years.
I invite everybody to watch the video of Commissioner Carrique's summary of the importance of this bill upon the legislation being tabled. You can hear the frustration coming out of law enforcement. I think there is consensus among law enforcement to move forward, because they are very tired of the criminal organizations responsible for human trafficking, auto thefts and drug trafficking. They know this activity is going on, and they are trying to do their jobs with one hand tied behind their backs. When they receive tips from foreign governments, in particular, on something as sensitive as child sexual exploitation, they want to move. They do not want to invade people's privacy along the way.
Thankfully, there have been several evolutions in Canada and around the world that demonstrate how we can better protect privacy. There's been some discussion at this committee about the differences between the approaches of our Five Eyes partners and Canada's. Of our Five Eyes partners—or France, Germany, Finland or Spain, for that matter—none require judicial authorization to get subscriber information. We're talking about information that used to be in the phone book. We would still require that a court approve access to that information. This would streamline access without compromising privacy in any significant way.
If you want to go beyond that, even in exigent circumstances.... The one exception would be when an emergency is playing out and the crime can be stopped, or if evidence is going to be destroyed. There would even be opportunity on the back end to.... The test would still have to be met, but the harm could be undone, so to speak, by a court excluding evidence, should they need to—if, in fact, there was a privacy breach committed.
We've improved this, by the way, through a consultation process with different MPs from different parties, and with experts who said, “You know, you might want to ring-fence what subscriber information you're looking for”, so we excluded medical information and legal advice. This is about finding out who is behind a phone number or an IP address when we suspect they are tied to a criminal activity of one kind or another.
At every step of the way, we've tried to give law enforcement the tools they need to combat modern crime. At every step of the way, we've said, “How are we going to do this in a manner that respects the reasonable expectation of privacy protected by the Canadian Charter of Rights and Freedoms?” I'm convinced that we found the right balance, after many years of debate and many months of discussion among parliamentarians of different parties. This strikes a balance that will allow us to defend the interests of Canadians, keep our communities safe and respect the privacy rights of Canadians at the same time.
:
Thank you very much, Mr. Chair.
Minister, you told Mr. Caputo the intent behind Bill isn't to create back doors in encryption systems, now or in the future. You've confirmed that.
The possible weakening of encryption was also a concern for us when we studied Bill . At the time, Minister told us that even if the bill expressed a certain intention, she would agree to add a clause clearly stating that encryption will not be weakened.
Honestly, the weakening of encryption is really a widespread fear. Perhaps you could reassure the public by making it clear in the bill that you will not undermine encryption systems.
Do you think there's room in the bill to further clarify your intention, since you told the previous speaker it wasn't your intention to weaken encryption?
I want to share some technical considerations regarding metadata for my colleagues to consider before proposing amendments that could significantly impact the effectiveness of this bill.
Modern criminal investigations, especially those involving child exploitation, human trafficking, extortion, organized crime and cybercrime, rely heavily on digital metadata to reconstruct events, identify suspects and map complex networks. These cases are often reported long after they occur, making historical data essential for establishing timelines and connections that are not immediately obvious.
It is therefore potentially risky to narrow the types of data retained. Different metadata types serve different investigative and IT functions: attribution, communication mapping and cross-platform activity reconstruction. If key categories are excluded, it can break the chain of evidence and limit the ability to link activity across systems and jurisdictions. From an investigative and digital forensic perspective, missing metadata reduces the ability to conduct pattern and network analysis, which is central to modern intelligence-led policing and cyber investigations. It can also weaken evidentiary completeness in court. Many serious crimes are reported long after they occur. If certain metadata categories were never stored in the first place, they cannot be recovered later, even with a warrant or a court order.
Mr. Chair, I ask my colleagues to please refer to this transcript of my remarks when considering any amendments related to narrowing the types of metadata or limiting the retention periods, as these changes could significantly weaken the effectiveness of lawful access.
My colleague Mr. Caputo raised concerns regarding not only the types of metadata but also the 12-month data retention framework outlined in part 2.
During my meetings with law enforcement officials, they clarified the general parameters. There remains a practical challenge when it comes to complex investigations. Many serious cases, such as child exploitation, human trafficking, organized crime and extortion, are inherently time-intensive and often extend well beyond six or even nine months due to their cross-jurisdictional and digital nature.
Could CSIS or the RCMP elaborate on the operational importance of data retention in supporting these types of complex investigations? Also, significantly, how does the availability and duration of retained data impact the ability of law enforcement to conduct timely and effective investigations in the digital context?
Thank you.
:
The ministers are gesturing to me, so I'll take that as my cue.
I can give two examples, perhaps. One example could be that CSIS is trying to determine the movements of a terrorist group, and we've received a warrant to track a person of interest's cellphone. The electronic service provider did not have the necessary capabilities to track the device, so we're out of luck if there are not the capabilities to track the device. That is one of the key capabilities that would be provided under part 2, because it would require ESPs to develop and maintain location tracking capabilities, which are, quite frankly, standard in Five Eyes and European countries.
Another example could be that we receive information from a foreign partner who is carrying out an investigation outside of Canada where a few of the subjects of the investigation are associated with a Canadian phone number, and the foreign partner has further highlighted that the threat looks like it's about to move into Canada. We're able to confirm that the phone numbers were obtained through a reseller, but the reseller, quite frequently, neither maintains records of its sales nor tracks its clients' activities. Part 2 would bring that into play by having the resellers brought into the process, which would allow us to respond to those types of requests.