:
I call this meeting to order.
First of all, it is a pleasure and an honour to be here as your vice-chair chairing this meeting. Thank you all so much.
Welcome to meeting 37 of the House of Commons Standing Committee on Public Safety and National Security. Pursuant to the order of reference of the House of April 20, 2026, and the motion adopted by the committee on April 30, 2026, the committee is resuming its study of Bill , an act respecting lawful access.
Welcome to our witnesses.
We have Professor Leah West as an individual. We have the chief of police for Thunder Bay, Chief Fleury, and we have chief of police for the Toronto Police Service, Chief Demkiw.
Welcome to you all.
You all have five minutes to make an opening statement. For those in person, I will endeavour to get your attention when you're at one minute left and then when we're coming down to the end of your time. Hopefully I can do that as well for the people who are by video link.
With that, I invite Professor West to make an opening statement.
Thank you.
:
Chair and members of the committee, thank you for the opportunity to appear today.
By my count, Bill represents Canada's ninth attempt to enact lawful access legislation. That alone should give us pause. For over a decade, successive governments have recognized the same problem. Our laws have not kept pace with the realities of modern criminal and national security threats or the tools required to address them. The result is a growing gap between Canada's lawful access framework and the central role that electronic data plays in investigating and prosecuting crime.
At the same time, the Supreme Court of Canada has been clear that even basic identifiers can reveal deeply personal information and are therefore protected under section 8 of the charter. As the court recently reaffirmed, an IP address is often the first digital bread crumb that can lead the state on the trail of an individual's Internet activity.
The government and this committee have a difficult task to address the existing operational gap in a way that is consistent with the charter. Bill is a meaningful improvement over past efforts at reform. It reflects the hard work done by officials at Public Safety Canada to engage with stakeholders and revise earlier proposals. It is more carefully structured and, in my view, capable of getting us to a workable, lawful access regime, but it is not there yet.
Let me briefly highlight three areas where targeted amendments would significantly strengthen the bill.
First is the subscriber information production order. The bill introduces a new tool that allows police to obtain subscriber information on a reasonable suspicion standard. In my opinion, that standard is constitutionally defensible, but the bill as drafted goes too far in another respect. It requires service providers to produce all subscriber information, as defined, tied to an identifier, regardless of whether each category of data is relevant to the investigation.
This new power applies to anyone who provides services, not just telephone service providers, creating a risk of overcollection of private information that does not meet the legal threshold set out in the bill. The fix is straightforward: Amend the provision to give police the discretion to request and judges the discretion to authorize only specific types of subscriber information for which the standard has been met. If the standard for a production order is going to be suspicion, then the scope of what is authorized must be narrowly targeted.
Second is risk to individuals in foreign jurisdictions. The bill allows Canadian authorities to request data directly from foreign service providers. This power is important, but it carries risk. There is currently no requirement for a judge to consider whether such a request could expose the target to mistreatment in another country, and that is a gap. I recommend adding a clear obligation for judges to assess whether there is a substantial risk of mistreatment and to refuse the order where such a risk exists. This would align the regime with Canada's broader human rights commitments and what is already obligated for RCMP officers under the Avoiding Complicity in Mistreatment by Foreign Entities Act.
Third and most critically is part 2, or the SAAIA, which is what I'm going to call it. Requiring companies to build interception capabilities and retain data that they would not otherwise keep inevitably creates cybersecurity risks. Every additional access point and every new repository of data are potential targets. The question is not whether the bill creates new risks. It does. The question is whether the bill adequately mitigates those risks and strikes the correct balance between the risks and the public safety imperative. As currently drafted, I don't think that it does.
Three changes are essential.
First, strengthen the definition of “systemic vulnerability” and prohibit the GIC from weakening that definition through regulation.
Second, prohibit blanket data retention. I believe that the current authority engages the right to privacy, is overly broad and creates a significant cybersecurity risk. The current one-year framework departs significantly from existing 90-day preservation limits, and I've yet to hear a compelling argument for the need for a blanket retention obligation not tied to any specific collection authority or subset of offences such as serious crime. Any retention regime must be necessary for investigative purposes and must be reasonable and proportionate to the offence or threat under investigation.
Third, make explicit that law enforcement and CSIS cannot directly collect or intercept personal information or private information from service providers' systems. Control over access to providers' data and systems must remain with providers. They alone should flip the switch. This is critical for privacy, security and legal clarity.
In conclusion, I believe deeply that Canada needs lawful access reform, but the task is not simply to expand access. It is to ensure that any expansion is necessary, reasonable and proportionate, and that it does not undermine constitutional protections or create undue security risks for Canadians.
Bill is a meaningful improvement, but targeted amendments are still required to get this right.
Thank you.
:
Thank you, Chair and members of the committee, for the opportunity to speak with you today about Bill , an act respecting lawful access, and why policing leaders across Canada strongly support its passage.
Policing in Canada has changed dramatically over the past decade. Crime is no longer confined to physical spaces or geographical borders. Today, organized crime networks appear across jurisdictions using encrypted applications, anonymous accounts and digital platforms to coordinate activities such as drug trafficking, human trafficking, firearms smuggling and cybercrime, yet the laws that govern how police access critical information were largely designed before the digital reality existed.
Bill is about closing that gap. It proposes practical, measured updates that would allow investigators to access certain information more efficiently, always with lawful authority, judicial oversight and a full respect for the charter and the privacy protections Canadians expect.
This is not about expanding unchecked powers. It is about ensuring that when police have lawful grounds to act—
:
No, that's good. Thank you.
This is not about expanding unchecked powers. It is about ensuring that when police have lawful grounds to act, they can do so in a timely way, especially when lives are at risk.
We are experts in this area. Last year alone, the Thunder Bay Police Service investigated 184 cyber-related cases. This involved more than 140 production orders, 80 search warrants, and over 1,370 devices being seized for examination. These efforts led to 20 victims being identified, and more than 240 charges laid. This is impressive for a five-person unit.
However, this is not about statistics. It's about protecting people. Bill will help services like ours, facing increasing demands with limited resources, reach victims more quickly. Let me illustrate this in a more realistic scenario.
Imagine a missing 14-year-old girl: Shawna. Her parents report that she has been communicating online with someone they believe is exploiting her. Investigators identify a username linked to a messaging platform. Time is critical. Under the current framework, confirming which service provider holds that account information and obtaining the basic subscriber data needed to proceed can take valuable hours or even days due to fragmented processes and outdated legal pathways.
Meanwhile, evidence suggests the suspect may be attempting to move Shawna across provincial or international borders. Every hour matters. Under Bill , investigators could more quickly confirm the service provider tied to the account and proceed with the appropriate judicial authorization to obtain further evidence. In urgent circumstances, they could request limited emergency access to data to prevent imminent harm, while remaining fully accountable to strict legal thresholds and oversight. That time saved could mean locating Shawna before she is moved, before further harm occurs and before critical evidence disappears.
This is the reality police services face every day. We have multiple examples in Thunder Bay where we have youth as young as 14 being exploited and coming to our community from southern Ontario. The Canadian Association of Chiefs of Police has endorsed Bill because it strikes the right balance. It streamlines access to essential information, improves emergency data sharing and clarifies voluntary disclosures, while maintaining strong judicial and privacy safeguards. The Ontario Association of Chiefs of Police has also consistently called for modernizing lawful access tools.
Our members see first-hand how individuals and organized crime group networks have exploited legislative gaps. These actors are sophisticated and constantly evolving.
To keep communities safe, policing must evolve as well. Lawful access tools are not about surveillance overreach. They're about public protection. They allow investigators to understand criminal networks, prevent violence and rescue victims. Whether it's locating a missing youth, disrupting fentanyl trafficking, dismantling human-trafficking networks or combatting online exploitation, clear legal frameworks and modern tools are essential.
Bill represents an important step forward. It acknowledges that modern crime requires modern solutions. It ensures police can act quickly in urgent situations, while remaining firmly grounded in judicial authorizations, privacy laws and the Charter of Rights and Freedoms. At its core, the legislation is about protecting Canadians, especially the most vulnerable among us.
I urge you to support the timely passage of Bill .
Thank you.
:
Thank you, members of the Standing Committee on Public Safety and National Security, for the invitation to join you today.
The Toronto Police Service, along with the broader policing community in Canada, has long advocated for reforms that put public safety first, including reforms related to lawful access. We believe that Bill , an act respecting lawful access, is a step in the right direction. It would provide additional tools for our officers to move investigations forward more quickly, hold offenders accountable and prevent harm.
Preventing harm often requires the ability to intervene early, including in cases involving violent extremism.
The Toronto Police Service is the biggest municipal police service in Canada. Policing in Toronto is extremely complex. In addition to all the unique aspects of the city, we often see trends here before they begin to appear in other areas. We see the ripple effects of geopolitics and a rise in hate crimes. We see frontline situations rooted in the complexity of mental health, addiction and unmet social needs.
Toronto is home to the majority of consular offices in Ontario. The city is host to many major international events. We are seeing more young people becoming involved in violence and often communicating anonymously about potential targets through digital platforms.
Addressing these issues requires support and collaboration across the broader justice system, including through legislative reform. In many ways, new technology and communication enhancements have made our lives easier, but they have also made it easier for criminals to plan their activities and avoid justice. We are seeing bad actors use digital tools for all kinds of crime, including drug trafficking, extortion, child pornography, hate crimes, extremism and other serious offences.
Our role is to prevent these offences, bring offenders to justice and provide a voice for victims who have experienced some of the most difficult of circumstances. However, because technology has evolved so quickly in recent years, we are encountering roadblocks in some of these investigations.
Take, for example, the issue of confirming which telecommunication service provider has information that will assist in an investigation. Presently, this process is time-consuming and potentially leads to loss of evidence. Bill would streamline our processes and allow police to advance investigations in a timely manner.
As the criminal world evolves, law enforcement and the justice system must keep pace. It is important to note that some of these tools are already available in other Five Eyes countries. The Toronto Police Service strongly believes that lawful access would reduce delays in accessing critical information and, in doing so, enhance public safety.
Thank you. We look forward to continuing our work with all levels of government to ensure the justice system upholds accountability and protects our communities.
:
Thank you, Chief Demkiw.
With that, we will get to our first round of questions. I will exercise my prerogative as chair to take six minutes for questions. This is something that I've spoken about with the honourable and my colleague from the Bloc.
Thanks to all of you for being here. This is an area in which you all have a lot of expertise.
I thank the two police chiefs for their service.
Professor West, it will probably be no surprise that I'm going to start with you. I wanted to ask you about encryption. This seems to be, for some people, a really big issue.
What can you say about encryption when it comes to this bill? Is it sufficiently defined? Is it not sufficiently defined? Where, in your legal opinion, would you land, given what we see in the bill on the definition of “encryption”?
My question is for the two law enforcement representatives. One important thing to keep in mind here is that Bill aims to give law enforcement the means to act in a timely manner.
Chief Demkiw, you said that the process was time-consuming and that this could lead to the loss of evidence.
Also, in your opinion, in cases of online fraud, cybercrime, extortion and vehicle theft, am I correct in thinking that acting quickly helps reduce the number of victims?
If an investigation takes a year or 18 months, there could be hundreds of victims rather than just a few or a few dozen cases. In cases of cybercrime or sextortion, there can be many victims.
That's what I would like clarification on. There's a big difference between having one victim or 200, between having one case of cybercrime or 12.
This is where Bill needs to make a difference.
What are your thoughts on this?
Given the example of fraud-related offences that you used, let's take an example of a Ponzi scheme. In a Ponzi scheme situation, if we've identified one, two or three victims and we're able to get into that material or that information early on, there's a really strong possibility that our quick access to that information will stop further victimization or prevent other people from becoming victims before we finish up the investigation.
I have seen that happen in the past when time was of the essence. We're talking about people who are very motivated to do their crime, and they will victimize multiple people very quickly. If we have the ability to get in there, we might be able to interrupt some of their activity while we're forming grounds to lay charges and go forward with court proceedings. I think it's really important to have that early access in those types of scenarios.
:
If I may start, the short answer is, yes, I believe it is.
We know from practical experience that the use of digital technology by the criminal element has expanded dramatically, and our ability to gather timely evidence, preserve evidence and prevent the escalation of offences is hampered by the inability to access key digital bits of evidence. Bill will assist us in that regard.
By way of a simple example, when we have a phone number tied to a particular set of criminality, no matter how serious the alleged crime, we have to establish who the service provider is, and that in and of itself is a cumbersome task today. Bill will streamline that task, allowing us to move more quickly and gather essential evidence that may disappear and be lost while we wait for different service providers to advance our investigations under the current legislative framework.
Bill is calibrated well to assist us in making timely access to key digital technology more readily possible.
:
I think there are two issues.
The first is on changes to the MLAT, which would allow foreign entities to serve orders in Canada. There would be a process where the minister approves the request, it goes through a judge, the judge agrees that the criteria made out in the Criminal Code are met, and then they collect that data back.
There is no requirement that the law under investigation also be a crime in Canada, so there is the possibility of seeing foreign governments seeking to enforce repressive laws or politically motivated investigations through this process. There is no real safeguard against that, except for the actions of the minister executing things at his discretion. In this case, especially because there isn't necessarily a judge involved in the foreign jurisdiction, it can be an administrative order. The minister has to commit to exercising his discretion to not authorize a process where the crimes being investigated are potentially repressive or politically motivated. There is no safeguard in the law.
There could be by adding the fact that the law would similarly have to be a crime in Canada. Then we wouldn't have that problem. That's one way to make it broader. However, right now, it would be at the minister's discretion.
I'm very concerned about this. So if you could suggest a specific amendment to Bill that might reassure people, that would be very helpful. We have until May 27 to introduce amendments.
I'd like to ask you another question. In the letter you published in The Globe and Mail, you emphasize the importance of the work being done in committee and of reaching a consensus around Bill . I think everyone here would agree that this bill is necessary, but that it could be improved.
Do you think it would be reasonable to include the National Security and Intelligence Review Agency, so that it is notified in real time when a ministerial order is issued, and so that it can investigate and ensure that the powers conferred by Bill are not abused?
You have said publicly that the government should show its homework. I appreciated that, especially the focus on this committee, which is part of making this legislation go through this process.
We know that in consultation with Murray Rankin, who produced a report that informed Bill .... The told the committee that the report was used specifically to inform the government's decision-making on Bill C-22. I know you participated directly in that consultation.
In your professional opinion, is there any legitimate national security solicitor-client privilege or operational reason preventing the report from being released to Parliament or to the Canadian public?
I'll focus primarily on the operational side of policing and ways to support the work that the investigators do when it comes to organized crime, extremism, child sexual exploitation and other complex crimes.
Chiefs, Bill creates a confirmation of service demand, which simplifies the process by which law enforcement identifies the proper recipient of a production order. Would you say that this helps in the context of a time-sensitive investigation dealing with organized crime, extremism, hate or child exploitation? How does this provide the main operational benefits to you?
I think the practical reality is that we often have a phone number or another clue that requires us to then pursue the digital footprint, the digital evidence, that the phone number or other information provides.
In the present regime, there is no provision for us to make a demand for service providers. We have to do production orders multiple times to simply identify that this is a service provided by a particular telco, for example. There's an incredible amount of time spent doing this. Just by way of example, numbers-wise, over a 20-month period, our detective operations alone in Toronto did 1,900 production orders.
Something that would help us very much is to have the ability to understand which service provider to focus our investigative efforts on and to then pursue that through a judicially reviewed process: production orders or warrants. That saving of time is very real and will impact our ability to succeed.
As was asked in the previous question, the type of evidence that can get lost while we determine who the service provider may be—video evidence, forensic evidence—may involve greater victimization or ongoing victimization that proceeds for a longer period of time while we, in the present regime, determine who the service providers are. The ability to know where to focus our investigative energy quickly and then to go through the process of gathering evidence through production orders, which are scrutinized by a justice, is something that we very much welcome.
In this context, Bill has metadata retention requirements where metadata is to be held for up to 12 months. Yesterday, we heard from officials that in Australia they keep it for two years. In the U.K., they keep it for one year.
Would you say that requiring core providers to retain metadata for 12 months is a reasonable time frame, given the fact of how quickly providers may otherwise delete the data? Sometimes it's 30 days. Sometimes it's three months.
This is still remaining flexible for providers and supportive of investigators, especially when complex cases can go beyond three to six months or even over a year.
:
I certainly understand from the law enforcement perspective why they would want all the data they need to be available for as long as necessary, but in terms of charter protections, my opinion is informed by what I've read of European jurisprudence on this issue.
Also, it's not just that it's one year. It's one year for any type of data for any purpose: for mischief or for investigating jaywalking, for example. I'm not saying that's what they would do, but it's the fact that it's for any purpose, for any type of data, that creates a chill in people that they could be under surveillance when all of their data is being held for this long period of time.
Right now, there's nothing that constrains the retention. It's any type of data for a year, for any purpose, and I think that's what needs to be amended to make sure that it's more narrowly tailored to the type of data, the requirement and the investigative imperative.
:
I'm told it's not necessary.
[English]
Darcy, it's good to see you out there, even though you're on a screen. I've gotten to know Darcy pretty well over the last few years. I have to say he's a wonderful chief in Thunder Bay. I'm really glad you're here.
You gave one concrete example of a 14-year-old girl. Maybe you can tell me, after I finish posing this rather lengthy question, whether that was a real case. I wonder about other cases you've encountered—you may want to disguise sufficiently whom you're talking about—where lawful access would have been helpful to you. I would think in terms of child pornography....
Especially in a place like Thunder Bay, there seems to be a real issue with trafficking people. There's also, as we both know, a big issue with gangs from Toronto and Ottawa coming up to Canada...well, not Canada. I guess it's Canada down here in Toronto and Ottawa as well. They're coming up to Thunder Bay and committing crimes there. There must be communications between the gangs going back and forth between Toronto, for example, and Thunder Bay.
Can you give other examples of how lawful access would help you in doing your job and addressing these problems?
:
The real case is of those youth who are coming up to us from down south. We see them on a regular basis. Some are as young as 14 years old. Of course, we have concerned parents who are reaching out and asking for some support. They go originally to the Toronto police and then come to us. They're asking for some support to locate these kids.
Really, when we're talking about the exploitation of these youth, they're getting involved in all kinds of different crimes and gang activities. Having in the legislation more immediate access would be a real benefit to us. When we start to see the chains and the links between some of the groups down south and these kids who are coming up here, it would be really beneficial to us to get ahead of it, especially when we're looking for these youth. We have real-life cases of families who have come up and asked us to go out and help search for their youth. Quite often, we find them involved in drug activities or the gang-related work that's being done in this community.
That happens on a regular basis. On average right now, I'd say we've probably gone from 60% to 50% of the people involved in that type of activity coming from southern Ontario. Again, they are very young people who are involved and exploited. We are looking at some of those cases. Are they being human-trafficked? They are coming into our flophouses, and then they end up doing all kinds of activities.
This is a real concern for us. I think if we had the ability to access a bit sooner, it would be a definite benefit to us to enforce some of the acts that we do.
:
Thank you, all, for being here again for the second hour.
We have two witnesses here in person and one appearing by video conference. I understand that Mr. Fraser, who is on video, has been sound checked.
Thank you for appearing.
We also have Dr. Robert Diab from Thompson Rivers University.
Lastly, we have Dr. Michael Geist from the University of Ottawa.
Professor Diab, could you please go ahead with your five-minute opening statement?
:
Several of the powers in the bill have been more appropriately tailored to the needs of law enforcement and to the privacy interests at stake, but I would like to highlight and briefly walk the committee through what I believe are three significant weaknesses with the bill that remain.
The first is the new production orders for subscriber information to be added to the Criminal Code. The government's charter statement defends this power on the basis that subscriber info is not particularly sensitive, since it reveals only the name and address of a person obtaining a service from an entity like Rogers, but the power as drafted would disclose much more than this. Police can obtain not only a name and address tied to an account, but also the types of services a person subscribes to, the tiers or channels associated with those services and the identifiers of every device associated with the account.
It also applies to any person who provides a service, not just companies like Rogers. All of this certainly allows for capturing sensitive information like, for example, what cable packages a person subscribes to or what medical services they receive. A power to obtain this shouldn't rest on reasonable suspicion alone. The scope of the power should be narrowed. As it stands, I think it would likely be struck down under section 8.
A second concern I would like to raise is the definition of “systemic vulnerability”. I understand that Professor West dealt with this earlier, but I'll try to target my remarks here. There is a definition, and that's good, but it remains too narrow in two ways.
The test for what constitutes a vulnerability here is defined to be one “that creates a substantial risk that secure information could be accessed by a person” without authorization. That's too high a threshold. Developments with AI in recent weeks reveal its far greater power for hacking, so even a remote or theoretical vulnerability now could be readily exploited.
The definition also applies only to vulnerabilities in the electronic protections of an electronic service. It may not extend the definition to the operating systems of devices, so a ministerial order could, in principle, require Apple or Google to build extraction capabilities into an operating system without engaging the safeguard, even if the practical effect would be to undermine end-to-end encryption.
The third concern with the bill is, in my view, the most serious, which is the metadata preservation power that the committee spent time on a few minutes ago. This would require core providers to retain transmission data for every communication for up to a year. That's when and where we used our phones and the coordinates of who we were in touch with, when and where.
The charter statement doesn't address this at all. Its position appears to be that compelling a provider to preserve metadata is not itself an interference with privacy, because police still need a warrant or other authority to access the data. It implies that it is not a seizure and does not engage section 8, but this is not so.
We know from ample case law that metadata is private, and under these provisions, when the compels Shaw or Telus to preserve our metadata, the company is doing so on behalf of the state and for a law enforcement purpose. Those are the basic elements of a seizure under section 8.
It's worth noting that Parliament assumed precisely this 12 years ago when it added to the Criminal Code the power to make a preservation demand or order, which requires individualized suspicion, reasonable suspicion or a warrant, depending on the case. This is key: It makes it a criminal offence to hold data, if you're Shaw or Telus, etc., beyond whatever the period at issue is. Why would Parliament have assumed authority was needed to preserve data if it didn't engage section 8?
Nothing here changes, in my view, in light of the fact that police are saying they won't look at it unless they go get a warrant. That's also true right now. In order to see the things they demand to be preserved, they need a warrant, but even preserving it is—
:
Good afternoon, everyone. Thank you for the invitation.
My name, as you heard, is Michael Geist. I'm a law professor at the University of Ottawa, where I hold the Canada research chair in Internet and e-commerce law. I appear in a personal capacity, representing only my own views.
In preparation for today's hearing, I looked back at the history of my engagement with lawful access policy. I found that I wrote my first op-ed on the issue more than 20 years ago, and first began appearing before committees, about various bills, a few years after that.
As I'm sure you know, lawful access has been the subject of legislative debate in Canada for decades, under both Liberal and Conservative governments. The technologies change and the governments may change, but the challenge has always been the same: to give law enforcement and security agencies the tools they need to address serious crime while respecting Canadians' privacy rights and the constitutional framework the Supreme Court has built around privacy in decisions such as Spencer and Bykovets.
Bill is what happens when the balance is not well struck, as its warrantless information demand power envisioned compelling disclosure of subscriber information, of any provider of a service in Canada, without court oversight. The decision to drop that power was the right one, and replacing it with a confirmation of service demand is a meaningful change. Bill , nevertheless, contains some serious problems, and I'll focus on three. They're going to echo what we just heard from Professor Diab.
First, I'm going to focus on the mandatory metadata retention regime, which would require providers to retain metadata for up to a year on every subscriber, regardless of suspicion. On a mobile network, that data includes cell towers each phone connects to. When retained at scale, the aggregate amounts to a comprehensive surveillance map of virtually every Canadian, where and when they go, and who they interact with. This is the kind of bulk data retention regime that the Court of Justice of the European Union struck down in the Digital Rights Ireland case, and in the Tele2 Sverige case extended to mandated private sector retention of traffic and location data. Germany's Federal Constitutional Court has reached similar conclusions, yet, remarkably, the charter statement about Bill fails to address the regime, despite the obvious charter implications.
The committee is being asked to entrench a surveillance architecture and accept the security risks that come with it. The obvious approach is to remove this entirely, as it is disproportionate and, I believe, likely to be struck down in its current form by the Supreme Court. Alternatively, perhaps a 30-day cap on metadata retention would suffice in terms of meeting the immediate investigative needs, while allowing for a court order if a longer period is required.
The second concern involves systemic vulnerability safeguards in the technical capability provisions. Proposed sections 5 and 7 of the SAAIA—that's part 2—say providers are not required to comply with an order if doing so would create a “systemic vulnerability”. Proposed sections 12 and 13 make compliance unconditional and provide that orders prevail over inconsistent regulations. That leaves a safeguard that exists in name only, largely cloaked in secrecy, with the burden of invoking it falling on the providers. The consequence is a backdoor capability mandate that could weaken encryption, place user data at risk and lead companies to remove privacy-enhancing services from Canada.
This needs a fix, which should include amending proposed section 12 to make compliance subject to the provisions of proposed sections 5 and 7. Further, the definition of “systemic vulnerability” should be expanded by the statute, clarifying that there will be no requirement to weaken or break encryption or to introduce any security weakness.
The third concern is the production order threshold for subscriber information. Bill sets the standard at “reasonable grounds to suspect” rather than the current “reasonable grounds to believe”. The Spencer and Bykovets decisions establish a high informational privacy interest in subscriber data, yet the charter statement nevertheless asserts that the “subscriber information sought does not, by itself, constitute particularly sensitive information”. I think that sentence is difficult to reconcile, both with Supreme Court jurisprudence and the technical reality of what subscriber information may reveal. Setting the bar lower invites further charter litigation, placing the provision on shaky legal ground.
Now, none of the changes that I've discussed here would be incompatible with effective law enforcement tools. Rather, they're about ensuring a framework that can withstand charter scrutiny, respect Canadians' privacy rights, avoid creating a surveillance infrastructure and sustain public interest and confidence.
I look forward to your questions.
:
Mr. Chairman and honourable members, thank you very much for the kind invitation to share my views on Bill .
I'm a partner at the law firm McInnes Cooper in Halifax, where, among other things, I advise clients who are on the receiving end of orders for customer information. I also teach at the Dalhousie law school. I'm appearing in my personal capacity with my own views, and I'm not speaking on behalf of any of my clients.
I have to commend the government for its comprehensive consultation with stakeholders since Bill , to which I contributed, but I still have a number of concerns and recommendations. I'll note that, in particular, part 2 of Bill is very problematic. I can't cover all my concerns in five minutes, so I look forward to the rest of our discussion.
First, I agree with my colleagues. We need to narrow the scope of subscriber information production orders or raise the bar up to reasonable belief. The bill lowers the threshold for police to obtain a production order for subscriber information—which they can get today—from “reasonable grounds to believe” to merely “reasonable grounds to suspect”.
The organizations that could be on the receiving end of these orders are any that provide services to the public, which include banks, hospitals, grocery stores and hotels. We're well beyond telcos here. Even though the definition is narrowed from ones in previous bills, police could still demand all the subscriber information that a service provider holds. This would go beyond name and address, as my colleagues pointed out. It would include the types of services provided and device identifiers, like the serial number of the CPAP machine from your doctor's office. It would compel Apple to hand over the digital IDs of every single device you have, including your AirTags and iPads. That's too much. I suggest narrowing the scope of these orders or raising the bar to reasonable belief. Otherwise, it will ultimately be found to have violated the charter.
I'll move on to part 2, the supporting authorized access to information act.
Nobody has made a compelling case for anything in part 2. The government has had 20-plus years to build its case, but, as NSICOP observed, it has only anecdotes. We should not be undermining the privacy and safety of every single Canadian based on anecdotes.
Part 2 of the bill targets electronic service providers, but the definition is so broad that it would likely include most businesses in Canada. Everybody deals with digital information. If it proceeds, the bill should include necessary guardrails. Under no circumstances should the government be allowed to require—particularly with a secret order—an electronic service provider to make changes to products or services it provides in the ordinary course, to collect and retain any data beyond what the business requires for its own purposes or to make any changes that would affect functionality, including adding additional functionality for any products or services offered by the business. As the bill is written, the Minister of Public Safety could issue a secret order to turn your Amazon Alexa into a listening device, as in an example given by the previous panel. CSIS has explicitly said, in connection with this bill, that it wants to be able to track every single cell phone in Canada in real time, and that telcos would have to change their services to make every cell phone trackable. That would be disproportionate and, in my view, absurd.
Now, the government says that it doesn't plan to undermine encryption and that there would be no back doors, but you just have to read the words in the bill to see that there's nothing to prevent this. Government officials said at this committee—I think it was on Tuesday—that the bill is “encryption-neutral”, but Canadians are not encryption-neutral. The words of the bill would clearly permit, and certainly would not prohibit, back doors and mandatory decryption. That would be in secret, with no transparency to Canadians and with very little accountability. What the government intends is not relevant. What is relevant is what words end up in the statutes.
Under part 2, the Minister of Public Safety could issue these secret orders to electronic service providers—very broadly defined—that come with mandatory permanent secrecy. Currently, the police and CSIS can apply to a judge for something called an assistance order. This orders a service provider to provide all reasonable assistance to give effect to a judicial warrant. It can be accompanied by a gag order if it's appropriate. That is judicial control. Nobody from law enforcement has offered evidence that assistance orders are inadequate or should be replaced by these secret ministerial orders. The U.K. equivalent of a ministerial order was used by the U.K. government to secretly order Apple to remove encryption on iCloud, globally. Part 2 of Bill does not contain any guardrails that would prevent such overreach in Canada. Secret ministerial orders have to go.
We also have the issue of metadata retention, which my colleagues already spoke about. This would include your location history. The government could require everyone's cell phone to become a retrospective tracking device going back a full year, without any suspicion of wrongdoing. This will almost certainly be found to have violated the charter. Collected metadata would be sought by Canadian and non-Canadian authorities based on mere suspicion. That would be a record of everyone who sought reproductive health care in Canada, which might be of interest to law enforcement in a Five Eyes partner.
Finally, as legions of cybersecurity experts—
:
As chair, I will be leading off this round for six minutes.
I want to thank all of the witnesses. We have a very academic panel this time. I'm very humbled by the three of you coming to spend your time with us today, and what do you know? We're all lawyers here. That's wonderful.
Professor Diab, it's particularly great to have you here as a colleague with whom I dealt at the bar in British Columbia in my time as a prosecutor and also in my time teaching advanced criminal law and sentencing at Thompson Rivers University. I know that everybody's very proud to have you here, so thank you for being here.
With that, I want to expand a little on the question of engagement in section 8 when it comes to the requirement of a third party to retain data. Is there a specific case you're relying on there, Professor?
:
No, I'm just relying on the broad propositions under section 8. Section 8 is engaged whenever a state actor interferes with something over which we have a reasonable privacy interest, so I gather that the question you're asking is about a mere demand by a state agent of a third party to hold on to the private data that belongs to the person over there. Is that an interference with their privacy? Again, 12 years ago, Parliament assumed that, if a court were to look at that, they would find that it would be an interference with their privacy.
In other words, I can't think of a body of case law where police told third parties to preserve data and then it was challenged in courts. I can't think of that. The story for me begins with the power, the preservation power, and when that was added to the code, it was added, I'm assuming, on the premise that requiring a third party to do this for the state for a law enforcement purpose is an interference that engages section 8.
Once again, stand back and ask yourself how you would feel if you were told that Telus, Rogers, etc. are preserving a record of all your movements and the people to whom you sent emails, not the content but those details? How would you feel? They're preserving it for up to a year for the purpose of potentially prosecuting you if necessary.
Maybe one answer is that it's absolutely fine, but I think most Canadians and, I think, courts are likely to say no. They would think that the mere fact that I was visiting this person on this day or talked to this person is private. That should be private. There should be no record kept of it, and that is, I think, the best explanation I can give you as to why.
I would like to ask the two professors who are here in person about the reasonable grounds to suspect versus reasonable grounds to believe. It's been a while since I dealt with reasonable grounds to suspect, but my recollection of reasonable grounds to believe is that there has to be a subjective belief, as in you have to personally believe that an offence has been committed, and that belief must be objectively reasonable. That's my recollection. In other words, a reasonable person would say, “Yes, you have a reasonable belief.”
It's below balance of probabilities, so it's not ultrahigh. It's less than 50%, but above the suspect, which is more than a hunch but less than that.
What would you say to the proposition that this is asking for very narrow data and, therefore, we don't have to worry as much that this could be saved under section 1?
Would you agree with that, Professor Geist?
:
No, I wouldn't, and I wouldn't in two respects.
First, the consistent claim that this data is of low privacy value, I think, is simply inaccurate. We just heard examples from Professor Diab and, perhaps, over the course of the next little bit, we'll have a chance to walk through some of those kinds of examples, but it seems to me that, even with the question that came up towards the very end of your last panel about whether or not someone might know that you asked Siri something, the question isn't the content. The fact is that you raised it and engaged with people. The fact is that members of the public engage with you, and a record would exist of who you communicate with. The fact that there might be orders to have that kind of thing disclosed raises, from my perspective, significant issues.
This may have significant privacy import, so lowering the standard for this information, when there is scant evidence that the higher standard that we've had in place for many years now has posed a problem, seems to me unwarranted.
To Mr. Fraser online, I mentioned at the last meeting, when I wasn't the chair, that this is a highly technical bill. We had only one hour with the officials.
I wanted to address one thing you brought up to this committee. You talked about CSIS wanting to have real-time access. I think the committee may want to ask CSIS about that.
For our reference and for our analysts, can you tell us where you got that point, please, in 25 seconds or less?
:
Again, thank you all for being here.
I think we have a general tension in this law, as you've rightly pointed out, between the goal to be as safe as possible and the goal to respect privacy rights. We have to find the middle, where most people are comfortable. I don't think we'll ever find a situation where everybody agrees on the details of the bill, but I think we have to try to find that reasonable point.
We start from a premise that the bill is laudable in that it deals with some of the flaws in Bill . The bill is really needed, in terms of law enforcement having access to information that technologically isn't dealt with under current law, but as everybody here said, there are concerns you have expressed.
I've noted a real discomfort with the idea of regulations. I would point out that there's a suspicion as to what's going to be in the regulations, and then we're hearing hypotheticals of what might be in the regulations or how orders might be used. Some people will trust the government and say that it will act reasonably, that the charter still applies and that there's still judicial oversight. Other people say that they won't trust it unless it's written in the bill. I get all that.
I also expressed concern about the interplay between systemic vulnerabilities and the orders. The way I read the bill, the company is exempt from having to do it if it creates a systemic vulnerability. I understand that we might need to look at the definition of systemic vulnerability. However, in an order, the company's obliged to carry out the order.
Mr. Geist, you talked about that issue. Could you express the way you would amend the bill to deal with that?
:
I would highlight a couple of things.
First, it is essential that we get greater specificity around this issue, with more clarity around that definition. Many have expressed concern about what this could mean and the implications. This is serious in terms of what it means for our cybersecurity and for people's privacy, so I think we owe it to everyone to ensure that it becomes clearer.
Respectfully, I think there is good reason for people to listen to the debate and think that, in fact, some of those concerns are warranted. For example, during the House debate, I heard the talk about this being a first step. I walked into the hearing just before that, and the police officers were talking about wanting metadata for two or three years. Is that the next step—beginning to expand this into multiple years? I don't know, but there are real concerns.
In answer to your question, we need far more specificity around the definition to make very clear that this is not touching encryption and that there will be no orders that will create systemic weaknesses. That's a clear starting point.
:
That one, I'm very sympathetic to.
I want to mention something, because I have less agreement with raising the grounds to “reasonable belief” from “reasonable grounds to suspect”. I wanted to point out that the “Conditions for making [the] demand” say:
(2) The peace officer or public officer may make the demand only if they have reasonable grounds to suspect that
(a) an offence has been or will be committed under this Act or any other Act of Parliament; and
(b) the confirmation that is demanded will assist in the investigation of the offence.
I think the combination there does create a situation where there is a reasonable burden, determined by the totality of the circumstances, that makes that threshold to be relatively reasonable in this context.
I understand, though, the idea of limiting what the production order could deal with, but should we do that, should it be, for example, this person's name and this person's address—all the stuff you used to be able to read in the telephone book—and not necessarily every particular service a person had, for example? Would you then agree that was a reasonable threshold? Yes?
That's for you, Professor Diab. I've already asked Mr. Geist this question.
:
Thank you for the question.
I think there are two parts to this.
First of all, on the language you cited at the opening, the preamble, that's standard language. When it's challenged and courts are assessing whether it's a reasonable law under proposed section 8, they are going to be looking at the scope of it in addition to the grounds. One part of the whole question is this: Is “reasonable” suspicion too low even for just the name and address of the subscriber? That's one question left open in the wake of Spencer.
To reiterate a point that Professor Geist made just a couple of minutes ago, in Spencer the court said that we have a “high” privacy interest in the name attached to our subscriber information, because it ties us to a whole search history. It's a high interest. The court didn't say this. It was intimating that probably nothing less than a warrant on probable grounds would be reasonable, but it wasn't asked that question and it didn't have to answer—
:
Yes. That was what I was suggesting.
In a sense, what I was trying to put forward is that there is always the ability for law enforcement, if it needs this information as part of an ongoing lengthy investigation, to seek the necessary order to have it preserved. The issue that law enforcement I think has identified in this context is that you don't know what you don't know in some circumstances, so you don't know that you might need it. There is this desire to build this giant haystack of information, because maybe you will need the needle at one point in time.
It seems to me that, of course, the haystack is comprised of people who have done no wrong. They're suspicionless. It raises for them real privacy-related concerns. Is there some kind of mechanism that we can find, in the spirit of trying to address law enforcement's concerns, that will allow, on a rolling basis, some of this information to be retained but quickly discarded after an appropriate period?
I heard in the last panel, I think, one of the members of law enforcement who was asked for a use case and talked about a missing person. Wouldn't it be good to be able to get that information? Respectfully, you don't need to retain everybody's metadata for a year for someone who's gone missing. I would think, frankly, that 30 days is more than enough to realize that the person is missing. Then, if there is a need to try to obtain other metadata, you can get the order to get it.
:
Thank you for your answer, Dr. Geist. That's pretty clear.
You know that Bill is important to us here. We all made a commitment to collaborate and, above all, to improve it. So if you have an amendment to propose or specific feedback to offer to improve it, I invite you to share it with us. All your suggestions are welcome, especially if you provide them in both official languages. They will be promptly forwarded to committee members.
Now, I'll ask you my other question.
Unless I misunderstood, I've learned that in Europe, data retention is limited to cases of serious crime, and that Europe is much more cautious when it comes to protecting privacy. In the United States, it's also not very clear whether metadata is retained for a very long period.
Do you consider that, in Bill C‑22, Canada is more intrusive than its Five Eyes partners when it comes to retaining metadata?
Mr. Fraser, I appreciate your being here today. My questions will start with you.
Let me start with the difference between what's intended and what's allowable. I think most Canadians would not argue with the intention of this bill. Many times when we ask questions of the department, of both Justice and Public Safety, they rely on the statement, “Well, that's not the intention of this bill.” My concern is more about this: What does it allow versus what does the bill intend?
Yesterday, Public Safety Canada, on the social media platform X, posted this: “Fact or Fiction? Bill will require electronic service providers to create backdoors to their systems.
“Fiction! C-22 would not require backdoors.”
You responded on X, saying this: “Fact: There is nothing in Bill that would prevent the ordering of backdoors given the enormous powers granted under s. 5 and s. 7.”
Could you elaborate on that concern for the committee?
:
Absolutely, and I think that's one of the big issues with this bill.
With regard to the intentions of the bill, the bill is in two parts, and they do two very different things. One is about authorities, and the other is about capabilities.
If you look at clause 5 and the list of things that the Governor in Council can make regulations about, or clause 7 and ministerial orders, you see that they are written extremely broadly.
First, I would call your attention to the regulations that the Governor in Council may make. They include all the things in paragraphs 5(2)(a) through 5(2)(d), which means more than implicit granting of authority. Paragraph 5(2)(a) could include back doors, and paragraph 5(2)(b) could include back doors, because they can require the installation of devices on ESPs' infrastructure. There is nothing else in the bill that prevents that from happening, other than the goodwill of the minister and the goodwill of the intelligence commissioner, and that's that.
I am particularly very concerned about these secret orders, because the minister has the power to do any of the things that could be in a public regulation to any telco or any electronic service provider. At least the regulations are going to be published and will go through a process, and people can see them. However, secret orders can include back doors, because that certainly isn't precluded in the definition of “systemic vulnerability”, and it doesn't protect encryption in any meaningful sort of way.
If you take those two things together, the guardrails simply are not there. The only guardrail is the Charter of Rights and Freedoms, for which we'll have to have litigation in order to.... I'm afraid the government are setting themselves up for failure if they pass a bill that goes too far, a bill that violates the charter and that is going to be found to be unconstitutional. It's better to get it right.
Thank you to the witnesses for being here today on this important legislation.
I want to start with Professor Geist.
You were answering a question from a fellow parliamentarian, Madame DeBellefeuille, around privacy and how other Five Eyes and European countries handle that issue.
I'm also curious about judicial oversight and how Five Eyes and European countries approach judicial oversight with respect to a comparative analysis on Bill .
:
I could start, and perhaps others can proceed.
I have concerns, concerns that we've expressed. We do run the risk of undermining the trust—I referenced that towards the end of my remarks—between the public, their providers and, frankly, law enforcement itself.
When you talk about communities where some of that trust may have been, even now, strained, the notion that we are creating frameworks that lessen the safeguards that exist in terms of the standard to be able to obtain information, and even the base knowledge that, as people become more aware of the implications of some of these provisions, who they speak with on their devices, where they go and how they engage, all of that information being collected and retained for a year, I don't think knowing that their providers have this information increases the level of trust that people have with their providers. You're also then layering on top of that the fact that providers have been compelled to collect that information and then enveloping with secrecy what might take place with some of that kind of data. I think all of this undermines the trust that exists between the public and the various kinds of authorities whom we want to enhance the level of trust with.
:
Sure. The basic notion between a quick freeze, which is, by and large, what takes place today, is.... We should probably just back up to note that there is no commercially viable reason for providers to retain metadata for long periods of time. There are risks. We've talked about those risks. Create that big haystack, so to speak, and you create a ripe target for hackers or others who might seek to gain access to it. It's a treasure trove, potentially, of information, but beyond that, it's expensive, which may render some providers less competitive, thereby increasing prices that Canadians face for their communications services, so by and large they don't do it.
What they do, though, is create a scenario whereby they will respond to orders requiring them to retain this information while an investigation is ongoing.
What I had suggested was this: Can't we find a way of marrying that system, which does allow us on that ongoing basis to retain that data, with a system that, for a very short period of time, if needed, allows for that retention and then gets quickly flushed? You can have it that in that very small minority of situations where you need that metadata retained for a long period of time, it's retained, but it's retained only where you have an active investigation, not against all Canadians.
:
Yes. Mr. Fraser, I know, spoke to that, and he could perhaps elaborate around why that very broad definition encapsulates far more than I think most people would realize, given just how broadly it's defined.
I did want to return to your question that I didn't have the chance to fully respond to, where you asked, why go so broad? I do think—and I say this with respect—that as I look back on the many years of lawful access debate, it is invariably the case that law enforcement seeks as many powers as possible, and one can understand why. They would like to ensure that they can do their job as effectively as possible. However, just because you can demand that very broad approach doesn't mean that the government of the day ought to acquiesce, and certainly Parliament should not, once it's had the opportunity to study the implications and the trade-offs that exist when that happens.
We saw it, frankly, in Bill , where there was clear overreach with respect to warrantless access to information from anybody providing a service in Canada. People said, hold on a second, that goes too far. Thankfully, the government listened on that issue, but we still have other issues where I think we need to recognize that it does go too far and we need to scale back, recognizing that we'll still address many of law enforcement's concerns and needs.
:
I also understand that you're a prominent speaker on technology and Internet issues. I came across one of your YouTube videos on this law that we're studying now, Bill , on lawful access, and I'd like to provide the committee a quick transcript of your remarks:
“If Bill C-22, the lawful access act, 2026, becomes the law, the Government of Canada will be able to secretly order Apple to build in a capability into its infrastructure to allow Canadian law enforcement and national security folks to track every iPhone, every iPad, every Apple Watch, every Apple AirPod and every AirTag in real time. Then they'll be able to require Apple to confirm whether they provide you any services.
“Then [law enforcement] can go to a justice of the peace and get an order, without actually believing that a crime has been or will be committed, requiring Apple to hand over every device identifier for every device that you use with their services. That's the digital ID for your iPhone, iPad, Apple Watch, AirPod, Apple TV, AirTag. With that information, they can go back to the judge and get an order, again without actually believing that a crime has been or will be committed, requiring—
Certainly, I have very few concerns with the judicial oversight. The threshold is obviously important.
However, if you take a look at all of these pieces as they go together, part 2 can require an electronic service provider—undeniably, Apple is an electronic service provider—subject to a secret order, to preserve metadata, location information, all that sort of stuff, and even build in new capabilities to their devices. That's under proposed paragraphs (2)(a) and (b) in clause 7.
Once that information exists, you can go to a judge and get an order on reasonable suspicion related to confirmation of service, then reasonable suspicion related to basic subscriber information, then reasonable suspicion in order to get the metadata and transaction information that they've been required to save.
This is potentially an entire package that we need to look at holistically and in detail.
:
This is without actually believing that a crime has been committed, without swearing an affidavit saying, “I believe that a crime has been committed, and therefore, Your Honour, I get a court order.”
I would like to dispose of some of the legal arguments that the Liberals make. I'd like to get specific, if I may, with Mr. Diab.
One of the arguments that is made on section 8, which is the arbitrary seizure.... What the government is proposing to do is to seize metadata, all of it, and order that it be held for 365 days, without knowing or suggesting that any offence has been committed. However, there's some jurisprudence on section 8—arbitrary search and seizure—that suggests that “seizure” requires a production. Here, we have no production.
How do you respond to that?
:
The seizure is the fact that information is being held. The fact that it's not held by the cops but held on behalf of the cops by order of government is what makes it seizure, because you have government compelling the private sector to hold on to the information.
On to Professor Geist, it's very nice to see you in your non-Twitter persona.
Professor Geist, I have a major concern, specifically with the language of who can be bound by these orders. Specifically, it's the electronic service providers that can be compelled by a minister to design a system, a back door, etc. I looked at the definition of “service provider”—it's in section 2, “Definitions”—and it's basically anyone who provides electronic services to persons in Canada and does business in Canada. Then I went and I looked to see the definition of “electronic service”, and it means anything “that involves the creation, recording, storage, processing, transmission, reception [or] emission” of electronic communication.
Well, it sounds to me like any law firm would be sending emails or receiving emails through its server, any bank would and any doctor's office would. We hear from the Liberal officials that only Internet companies are subject to this, but that's not what this legislation says.
:
I think it's way too hyped, at this stage.
Voices: Oh, oh!
I was going to say this: You asked a question with a long list related to Apple and the notion of, “Well, what's the problem?” The problem is, of course, all the data that might ultimately be retained and potentially accessed.
There is another problem here. Layering in some of these rules will mean that these companies may well either remove some of the services that protect Canadians—we've seen this with Apple in the U.K.—or choose to exit the market altogether if they are unable to meet the kinds of standards they expect of themselves and that their customers expect in terms of the privacy they provide. When you layer a very broad definition of “electronic service provider” in with very broad demands that may be inconsistent with where a company is at, you create an environment in which Canada may well be an outlier. Companies may stop providing particular kinds of protections or stop providing services altogether.
:
Thank you very much, Professor Geist. I apologize.
I want to exercise my prerogative as the chair, because there's one thing I think we're going to hear about in the next round that I think is very important. I'll ask you for a very brief, 15-second response.
You mentioned that 30 days for metadata would be appropriate. Oftentimes, there's not even an investigator assigned to an Internet luring case in 30 days. Bearing that in mind, what would you think about 90 days, given those types of crimes, to address those types of crimes or the metadata that would allow us to address those types of crimes?
:
We are now into our third panel.
I want to welcome our next panel of witnesses here to speak. We have, from the Canadian Centre for Child Protection, Monique St. Germain; from the Canadian Chamber of Commerce, David Pierce; and from the Peel Children's Aid Society, Mary Beth Moellenkamp.
Thank you, witnesses. You have five minutes each for an opening statement.
Ms. St. Germain, we will hear from you first, please. Thank you.
:
Thank you very much, Mr. Chair and committee, for inviting us to participate in this study.
My name is Monique St. Germain. I am general counsel for the Canadian Centre for Child Protection, a national charity that works domestically and globally to reduce the incidence of missing and sexually exploited children.
We also operate Cybertip.ca, Canada's tip line for reporting the online sexual exploitation of children. In 2025 alone, we received 28,000 reports.
We also operate Project Arachnid, a platform that prioritizes the removal of harmful child sexual abuse and exploitation material. As of this month, Project Arachnid has issued 141 million notices requesting CSAM removal.
On a daily basis, our agency directly witnesses egregious privacy violations on children whose child sexual abuse material is circulating online for the world to view. We hear directly from children and families impacted by online crimes like CSAM, online luring and extortion. We welcome the measures in Bill , particularly the confirmation of service demand and the subscriber information production order.
It's been over a decade since the Spencer decision left it open for Parliament to enact a reasonable law. We hope this time we can finally get there. In the intervening years, we have witnessed a number of growing threats to children, including an exponential increase in CSAM online. StatsCan figures show that CSAM incidents have quadrupled from 2014 to 2024. Then there's online luring. Reports to Cybertip.ca surged 344% between 2020 and 2025. StatsCan has this crime going up 65% in 2024 over 2023. Sextortion is another big issue. Cybertip.ca has received over 14,000 reports since 2020.
Even though crimes against children are through the roof, StatsCan data reveals that, in 2024, charges were laid or recommended in just 24% of all sexual offences against children online and in only 6% of CSAM incidents. We have to ask ourselves why.
This is obviously complex, but it has to be acknowledged that offenders are increasingly using sophisticated tools like burner phones, bulletproof hosts and VPNs, and networks like Tor that hide IP addresses. Some apps are blatantly and intentionally designed for anonymity. Offenders are able to rapidly change their digital identities through fake accounts. It's very common for offenders to use multiple apps, devices and accounts. Unravelling that web is incredibly complicated. On top of that, some of these investigations involve multiple jurisdictions and service providers. Record-keeping and co-operation amongst these providers varies widely. This has to be having an impact.
At our agency, we are now at the point where nearly one-third of contacts to Cybertip.ca or our support services come from children seeking help. These are just the children who come to us—often only when they are in crisis and, in some cases, suicidal. By the time these children feel able to reach out for help, the evidence that might help police identify their offenders could be gone. Even a single offender left unchecked can inflict an enormous amount of harm. Here is just one example: An Alberta offender posing as a female teenager was able to lure 92 children.
We wish to address one specific area of the bill that we would like to see changed. We believe the confirmation of service demand should include basic jurisdiction information, such as province and municipality. Having this information is critical, especially at the outset of an investigation when the available information is limited. Knowing the jurisdiction will help ensure that the right policing agencies are involved and that production orders are brought forward to the right court, and this can help police be much more effective in their investigation.
In closing, Canadian children have been forced to pay a very steep price as this debate rages on. Past failed efforts at lawful access reform are a powerful reminder of how long children and families have been waiting for action. We want police to be able to act. We need them to have the tools to do so.
Thank you.
:
Thank you very much for the opportunity to be here today on Bill and lawful access.
I am here as the Canadian Chamber of Commerce on behalf of our 400 network chamber partners and boards of trade across the country, our 200,000 combined members and more than 100 industry associations. I'm also here as a father. I can share that many representatives from Canada's digital companies also have families. We all want to ensure that law enforcement has the tools it needs to pursue criminals, especially online.
I'd like to express our appreciation to the , the and their teams for the extensive back-and-forth over the past year. The amendments made to Bill in part 1 addressed many industry concerns, and we thank the government for acting, but when you compare Bill 's part 15 and Bill C-22's part 2, it's clear that the government doesn't share the same concerns as the vast majority of our members at the Canadian Chamber of Commerce.
I’ve worked in and around cybersecurity for years. I don't understand why we treat cybersecurity differently from other crimes. If a business is hacked, the business CEO must apologize. The liability is on the business, even if the hackers are state-sponsored, yet our discussions here today are not about how we can support business to further protect their systems and our data. Instead, we’re talking about obliging them to install devices, open their digital doors and give access to information to “authorized persons” essentially on demand.
:
Absolutely, Chair, I'm happy to.
Let's imagine that this law is on the books. In a year or two, imagine hundreds and maybe thousands of investigations across multiple national law enforcement agencies and federal departments on all of our digital systems. Who's managing all those secure keys? Who's accountable for patching and updating those systems to make sure they are secure?
If I leave you with one message today, it's this. The business community supports production orders and we support urgent 24-hour production orders in exigent circumstances, but we are very concerned at the prospect of unfettered access by a government-authorized person to pull information from encrypted, secured systems.
What's also puzzling about this debate is that I've had the privilege of working with some of the most talented lawyers in the country, and there is a debate right now about whether or not Bill in part 2 requires a warrant. It is critical that the powers in Bill 's part 2 be amended to clarify this important point, especially in proposed subsections 5, 7, 14 and 20.
On the discussion of metadata, this will impose significant costs—millions of dollars—on businesses, and not just on the infrastructure to retain the data, but to manage it, to manage it securely and to have it in a usable format for law enforcement. As soon as you store large volumes of sensitive data, it becomes a cyber-target. As soon as data is retained, it's a target.
We recognize the importance of non-disclosure orders, but these should be limited to court-authorized actions tied to national security risks and active investigations.
Bill could also penalize successful Canadian companies that operate here in Canada but also have operations in the United States and Europe. If you are an electronic service provider based in Canada today, with customers in the United States and Europe, complying with parts of part 2 could put you offside with law enforcement and regulators in those jurisdictions. At a time when businesses are already facing tax competitiveness pressures, tariff uncertainty and the broader economic risk that we're all facing, adding another layer of regulatory burden on Canadian companies at this particular time may incentivize them to relocate.
Finally, with regard to the definition of “core provider”, without an amendment to this section, it potentially captures the vast majority of Canadian businesses that communicate or provide an electronic service.
In closing, the business community very clearly has signalled that they're concerned about Bill and part 2 especially. I think we all trust that the current , the and the will use the measures in this law in a way that's appropriate and as they've said. I'm sure the public servants who were at the committee on Tuesday would do the same. They seemed to be very honest and reputable—
:
Mr. Chair and members of the committee, thank you for the opportunity to appear. My name is Mary Beth Moellenkamp, and I'm the chief executive officer of the Peel Children's Aid Society.
Peel Children's Aid is a mandated child protection agency for Peel Region, including child protection responses connected to Toronto Pearson Airport. We also lead, alongside our partners, nCourage, Peel's anti-human sex trafficking integrated service hub, and CWICE, the Child Welfare Immigration Centre of Excellence.
Through this work, we see how trafficking, immigration, housing instability and cross-border movement intersect with child safety and reflect broader provincial and national trends. That experience gives us a particular perspective on Bill .
Bill responds to a real challenge: whether lawful systems can move quickly enough to protect children in a fast-moving, digitally enabled environment. Children can be groomed, isolated, threatened, moved and controlled through digital tools faster than systems can identify risk and respond. Timely, lawful access to digital evidence can help find a child, identify the adult causing harm, prevent further exploitation and support coordinated intervention.
At the same time, safeguards are essential. The use of these tools must remain grounded in lawful authority, appropriate oversight, clear thresholds, privacy protections and respect for children's rights and dignity.
The child welfare system holds a difficult but necessary tension. We are responsible for protecting children from harm while also protecting their privacy, voice and civil liberties; and both matter.
Children and youth involved with child welfare often already experience high levels of system involvement. They are disproportionately represented among victims of sexual exploitation and trafficking. Many have experienced trauma, abuse, neglect, instability and disrupted relationships.
Traffickers exploit these vulnerabilities. What begins as connection can quickly become coercion and control. Some youth are drawn into other forms of criminal exploitation, including auto theft, fraud, drug movement or recruiting other youth. These children are often being manipulated, threatened and isolated.
In Ontario, as in other jurisdictions, human trafficking is recognized as a child protection concern. We have a clear role in assessing safety, supporting caregivers, collaborating with police and community partners, and protecting children from ongoing harm. Increasingly, our efforts focus on identifying traffickers and exploiters as the individuals causing harm rather than viewing parents and caregivers as failing to protect.
Traffickers exploit gaps between systems and jurisdictions. They exploit delays and digital platforms that move faster than our legal and service responses. The average age of recruitment into sex trafficking is estimated to be 13 years old.
At Peel CAS, we have supported children as young as nine years old. Last year, our agency identified more than 200 cases where a child or youth was suspected of involvement in trafficking for sexual exploitation, and yet we know that this is significantly under-reported. Often a child may only know a trafficker through a phone number, social media handle, app, vehicle, hotel or email address. Those fragments matter. They may be the difference between not knowing where to look for a child and locating a child.
The value of Bill for child welfare is indirect, but it's important. It may help our police partners obtain lawful digital leads that child welfare agencies, trafficking hubs, survivor services and community organizations can translate into safety planning, protection and survivor-centred support. Exploited youth must be treated as victims and survivors, not as offenders.
Digital information alone will not make children safe. Safety requires coordinated systems, including child welfare, police, survivor-led supports, indigenous and culturally specific services, immigration expertise, housing and mental health supports. Used lawfully and with safeguards, Bill may help partners locate children sooner, disrupt exploiters faster and strengthen collective efforts to protect children and youth.
Thank you.
:
Thank you very much, Ms. Moellenkamp.
I want to thank this panel of witnesses.
I will begin the first round of six minutes now.
Ms. St. Germain, you probably don't remember me, but I consulted you when I was writing the bill to change the name from child pornography to child sexual abuse and exploitation material. I first became acquainted with your work when we both attended the same B.C. ICE provincial strategy conference. For those who don't know, the RCMP in Vancouver has a specific unit that investigates Internet and child exploitation. People from all sorts of agencies gathered at the conference. I really appreciated your interventions there.
One thing we were talking about in the prior round was how long it takes for an investigation to kick off. I have prosecuted an Internet luring case. A lot of people don't realize this, but the software for a service provider, let's say, Facebook, could pick up an attempt to lure a child. Then, that goes to Washington, D.C., as I recall—it used to anyway—to the National Center for Missing & Exploited Children. I believe it would then go to the national headquarters for the RCMP, and then it would go to the province. Is that somewhat accurate?
:
Yes, I understand what you're asking. I'm not sure that I'm the person you should be asking. We're not police. The role we play is very distinct and separate from police. We get tips from different places and pass things on to police, but then the investigative process they follow is within their knowledge.
We know, from where we sit in the continuum, oftentimes when the tips are coming in to us from Canadian children and families, that they can't be acted upon. By the time the information gets through to police, there may not be sufficient information for them. There certainly have been delays, in terms of getting subscriber information, to link the information they have to an actual location so that they can start to investigate someone.
For an example, an IP address may lead to an individual house, but within that house, there may be four individuals living there. There's a whole process. Every step in the process helps narrow down and get closer to the actual person.
On the issue of metadata, what I understand from the bill is that this is being left to regulation to go through what metadata is being captured, being saved and being saved for how long. That is an important process in order to clarify what pieces of information are going to be helpful. Certainly, from what we see in the courts, that information is critical in terms of linking an offender to a particular piece of activity on the Internet.
:
Mr. Pierce, as it happens, you are in the company of two people who deal with cybercrime, among other things.
Among other things, you have heard about a defendant who made 92 children aged 9 to 13 his victims. We're talking about over 200 calls per year. Law enforcement urgently needs the powers required to be effective. The rapid-fire approach doesn't work in this case. As you've heard, reports are often made several months after the offence has taken place.
Given that, how do you reconcile your requests with the needs, taking all that into account?
We're talking about child sexual abuse, but we could also be talking about extortion targeting businesses. Recently, there have been repeated incidents in Surrey and Brampton. So it's urgent that complete information be provided in a timely manner. I'd like you to tell me how you reconcile that with your requests.
:
I will start from a cybersecurity perspective.
I don't think it makes anybody safer if our systems are compromised. That's a fundamental point. All of your data, my data and our families' data.... It's about financials, pictures or whatever the case may be, including location data indicating when you're not home so your house can be broken into. Our whole world is digital. If we lose encryption on these major systems, it will be a fundamental risk to the Canadian economy. It will be a fundamental risk to businesses being successful in our country. It would put us out of step internationally with countries where the systems of large providers that provide these services would be at risk.
From a business perspective, I think it's critical to remember the context we're in right now. These are not smooth economic times. In the case of large providers, you're talking about adding millions of dollars of additional expenses to their balance sheet. What about the smaller businesses and electronic service providers across the country that fill gaps the large ones do not fill? They don't have the capacity to pivot and finance large operations to essentially support law enforcement coming in and attaching a device to the back of their system, and to work with them over a long period of time to facilitate this.
I'll go back to my opening comment, if I can.
We all want law enforcement to have tools that are effective. We all want law enforcement to be able to pursue the criminals and protect our kids and families—all of us. It's really important that the measures this bill would provide are balanced between protections for our data and privacy with, above all else, protections for our encrypted systems.
:
I'll give you an example. I watched the testimony on Tuesday. One of the officials made a comment that in many of these systems there are two keys, so we can just have the providers issue a third key or another key that we can use.
Cybersecurity is not just technology. Cybersecurity is equal parts technology and humans. The human interaction with technology...I'm sure everybody knows someone who opened an email that let some virus into your system. The question is, who's managing those keys? Who's protecting those keys? How are those keys protected? Who has access to them? Keys change. Who's updating those keys? Who's doing the patches on those systems?
Look at FINTRAC. Look at some of these large Salt Typhoon hacks, in which these are very sophisticated actors. It's funny: I go back to my opening comment, when I expressed a bit of frustration, just because cybersecurity is looked at differently from every other crime. The real hackers of today are not in a basement in one of our major cities. They're foreign adversaries. They're state-sponsored. These are sophisticated operations. If you'd just add a new door to the back of the system, they will have been there on Monday. If the door appears on Tuesday, they're going to say, “Hmm, that looks different. It doesn't look like the other doors.” They'll start to probe it, and that immediately becomes a target.
Again, I go back to the point that the whole concern from the business community is, one, about encryption and making sure these systems are protected; but, two, about ensuring that we have the ability to conduct commerce and that we can have trust that our systems and our information is safe. If the measures in Bill , part 2, are implemented as written, the language does not preclude the concerns I've just outlined.
:
Absolutely. I'll share, quite honestly, the discussion in industry when this law was first introduced. Many thought that they were excluded, simply by the fact that they weren't defined as electronic service providers. However, when you really look into that definition, it's providing an electronic service. What do you use today that doesn't use some form of electronic communication? My car does that. We have so many different devices and pieces of equipment. It's not typical to just narrowcast it to one small subset with the language that's in the law.
Our suggestion is that there be a primary function test, applied to the definition of a core provider, that narrows it down to companies that are specifically in the business of communication, which is ultimately what I believe law enforcement is after. However, if it is left as it is right now.... As we were going through this with our members across the country, initially the industries thought they were excluded. Then they went back, looked at it and said, “Well, geez, you're right. This could capture us.” That ambiguity really should be closed in this process, we hope.
:
Do you think Quebec and Canadian companies are ready to meet the requirements of Bill ?
Are any of your members saying they're ready? Honestly, Mr. Pierce, I believe the bill will likely be passed, even though we hope it will be improved.
Do you consider it will take an enormous effort to prepare to meet the expectations imposed by Bill C‑22? Is it costly?
You told us that this has economic consequences. Have you quantified them?
Have you assessed what it will cost to comply with the expectations and requirements of the bill?
:
I'll start with the cost piece and then I'll work backwards from there.
For large providers, the cost is in the millions to set up the infrastructure to comply with this, and then millions more in operational costs. It's very important to remember that metadata is not something you can just go in and read. It has to be in a usable format that law enforcement would find useful and helpful.
The bill is in two parts. I believe the clerk will be distributing an English and French letter from the chamber of commerce to members in which we've identified areas where we think both part 1 and part 2 need to be improved. We understand the Spencer decision. On part 1, with the changes that were made and the changes we've recommended in our letter, perhaps there's an opportunity to split the bill so that part 1 can move forward and deal with some of the concerns that I know my other two colleagues on the panel spoke to so eloquently earlier, and we can study part 2 a bit more.
From my perspective, when you look at authorities in proposed sections 5, 7, 14 and 20... The number of lawyers I've talked to over the past year who said they cannot rule out whether or not a warrant is required says, to me, this might need some more study and it might need some more work. I would hate for it to be passed in order to resolve what part 1 is after and then create a host of trade and business issues for the economy as well.
:
Thank you, Mrs. DeBellefeuille.
[English]
For the benefit of the committee, we have been running a bit late. It's not because we have not been efficient, but because we have had more opening statements than we are used to.
What I would propose, to ensure that we give our next panel the appropriate amount of time, is to now have a four-minute round for the Conservative Party and a four-minute round for the Liberal Party, and then move on to the next panel so that we can finish on time. I hope that is okay.
We will move to Mr. Lloyd for four minutes, please.
I will continue my questions with CCCP and the Peel CAS.
I have volunteered countless hours over many years, supporting organizations like SAVIS of Halton. SAVIS serves as a leading agency in my region of Oakville. It's a backbone organization for the Halton Collaborative Against Human Trafficking, which brings together community organizations and partners to create a coordinated regional response to combat human trafficking. It's an organization such as yours.
Organizations like yours play a critical role in protecting vulnerable individuals and in strengthening community awareness and prevention efforts. Unfortunately, traffickers have frequently used Oakville and Burlington as transit hubs because of their proximity to major highways, moving victims between hotels along these corridors in an effort to avoid detection.
We are fortunate to have the dedicated members of our Halton Regional Police Service. I want to sincerely acknowledge and thank them for their continued work in combatting these horrific crimes.
Over the past year, I have spoken with many officials from different levels of law enforcement, and they have consistently emphasized that the child exploitation investigations are extremely complex and time-intensive. These cases can often take more than six months to resolve, particularly due to criminals' use of phones, computers, cloud services and storage devices to conceal illicit material.
From your perspective, how would Bill improve law enforcement's ability to investigate and combat child exploitation and human trafficking offences?
:
Bill would help law enforcement access this information more quickly. We sometimes have minutes or hours when we're looking at an investigation and trying to protect a child.
I want to speak from a Pearson airport perspective.
Sometimes we have children and youth coming through the airport who have been identified. Being able to access that information and look at that digital footprint is important because, once they go through, we may have no other opportunity to see that child again, and we may not know where they end up.
You rightly said that, within the GTA, there are many different transportation routes from the highways to the airports. This creates some challenges. Accessing that quickly is extremely important because time is of the essence in those cases.
I apologize if that was a bit aggressive. I want to thank all panellists today. They are excellent, and we have a very distinguished panel. I really don't want to lose any time with them.
I want to introduce them.
We have, from Meta Platforms Inc., Rachel Curran and Robyn Greene. From NSIRA, we have the Honourable Marie Deschamps, Craig Forcese and Lawrence Mangano. Finally, we have the Honourable Simon Noël and Justin Dubois.
We will now have opening statements.
I have to vacate the chair for about three minutes. If anything comes up, Madame DeBellefeuille will deal with it. I will hopefully be back in three or four minutes. If not, please go on to the next opening statement. Thank you.
We will start with the opening statement from Meta.
Good evening, and thank you for the opportunity to appear before the committee today. My name is Rachel Curran. I'm head of public policy for Canada at Meta. Joining me is my colleague Robyn Greene, who is an expert in the subject matter under consideration. Please direct your technical questions to her.
Meta is deeply committed to keeping our Canadian users safe online and off-line. We routinely engage with Canadian law enforcement agencies at all levels of government, including by proactively reporting threats we identify or by responding to valid legal demands and emergency requests from Canadian authorities.
We commend the government for addressing many of the concerns that were raised about part 14 of Bill . With narrowly tailored amendments, we think the current part 1 of Bill would provide law enforcement with an effective legal framework for obtaining the necessary data in a timely manner. However, part 2 is a different story and could ultimately make Canadians less safe, not more.
First, the technical assistance obligations in part 2 could conscript private companies into service as an arm of the government’s surveillance apparatus. As drafted, the bill could require companies like Meta to build or maintain capabilities that break or undermine encryption and force providers to install government spyware directly on their systems.
The bill purports to protect against risks to encryption by allowing providers to challenge demands that would introduce a “systemic vulnerability”. However the definition of “systemic vulnerability” is unclear. Essential terms like “encryption” are left to be defined in regulation, while ministerial orders can override those same regulations. Moreover, the bill contains no process for challenging a problematic order, or liability protections for companies while a challenge is pending.
The technical community's consensus on this is clear. It is not possible to build back doors to encrypted systems for law enforcement without creating vulnerabilities that will be—not could be, but will be—exploited by malicious actors. Weakening encryption does not just affect the target of an investigation. It affects every Canadian who depends on secure private communications to do banking, access health care, run a business or simply talk to their family.
This is not a hypothetical risk. Governments around the world are still dealing with a fallout from China's state-sponsored Salt Typhoon cyber-attacks, which exploited the U.S.'s far narrower technical assistance laws. Canada's own security agencies understand this and issued guidance that specifically advised adopting encryption to defend against these kinds of cyber-attacks.
Part 2 of Bill would move Canada in the opposite direction and out of step with our closest allies. Last year, France and Sweden both abandoned similar proposals, and the EU guaranteed robust encryption protections in its agreement on online safety. The U.K.'s use of a similar authority ordering Apple to break its encrypted cloud service drew condemnation from the U.S. government and 200 global civil society organizations, and ultimately resulted in Apple withdrawing its advanced data protection service.
Imposing these obligations would also chill domestic innovation and investment and harm Canadian competitiveness abroad.
In addition, overly broad non-disclosure orders in part 2 risk undermining public trust and transparency. The bill's data retention provisions would create a framework to capture the private information of ordinary Canadians with no connection to any crime, and also grant warrantees the authority to search company premises and seize data.
In light of these significant challenges, we urge policy-makers to separate part 2 from Bill so that these critically important issues receive the time and attention they deserve.
To avoid the worst privacy and security outcomes, required changes include removing obligations for companies to add government or third party surveillance tools or other software to their systems, and strengthening the definition of “systemic vulnerability” to explicitly rule out any requirement that would weaken or break encryption, and codify the process for companies to challenge requests.
Thank you, Mr. Chair.
:
Mr. Chair, members of the committee, good evening.
Thank you for inviting us to participate in your work.
I am chair of the National Security and Intelligence Review Agency, or NSIRA. I am joined by our vice-chair, Craig Forcese, and our secretariat acting executive director, Lawrence Mangano.
[English]
I'm going to use this time to make two points.
Given the scope of the new powers being proposed in this bill, timely and effective independent review is essential.
[Translation]
That's my first point.
[English]
Second, this bill, in its current form, falls short of supporting that review.
[Translation]
NSIRA has two core responsibilities. First, it reviews national security and intelligence activities to assess whether they are lawful, reasonable and necessary. This should not be confused with the authorization granted by my colleague Mr. Noël, which he will tell you about a little later.
Second, NSIRA investigates public complaints related to national security and intelligence.
[English]
In doing so, we provide independent assurance to Canadians that those activities comply with the law, including with the charter. Bill introduces significant new powers through the proposed supporting authorized access to information act. Given the breadth of these new powers, NSIRA anticipated a review role that would provide timely and direct visibility into how these authorities are used.
[Translation]
However, as drafted, Bill only provides NSIRA with the minister's public annual report. In practice, this could mean delays of more than a year before NSIRA becomes aware of how these authorities are used.
[English]
While NSIRA has broad access rights, there is a real benefit in legislation that requires information to be provided proactively to NSIRA in a timely manner. In the context of constrained resources, early awareness would provide a meaningful baseline of what activities are taking place and allow NSIRA to plan and target its reviews more efficiently.
[Translation]
We do welcome the requirement for intelligence commissioner approval of ministerial orders. However, the absence of provisions granting NSIRA access to those orders, or information about how they are implemented, limits our ability to assess their use in practice.
To address this, we recommend two targeted amendments.
[English]
The first is to amend proposed section 9 to ensure NSIRA is proactively provided access to classified ministerial orders issued to service providers as well as to information provided to the intelligence commissioner in support of those orders.
The second is to amend proposed section 27 to ensure NSIRA is informed when compliance orders are issued, including information relevant to potential non-compliance. These changes would enable more timely, targeted and effective reviews.
[Translation]
Furthermore, these amendments are consistent with existing Canadian legislation, where NSIRA receives proactive information related to activities conducted under ministerial authorization, and with international practices.
Australia also has provisions of this nature. You can ask questions about that.
[English]
In closing, independent review is a cornerstone of public trust in Canada's national security framework. Ensuring that NSIRA has timely access to relevant information will strengthen accountability and support Parliament's intent in establishing these authorities.
[Translation]
Thank you for your attention.
We would be pleased to answer your questions.
:
Thank you, Mr. Chair and members, for the invitation.
I am accompanied today by Justin Dubois, executive director and general counsel at my office.
Bill gives my office a new and significant function. I want to explain how this function would fit into my existing duties.
[English]
My quasi-judicial function as intelligence commissioner, or IC, is to approve or not approve certain national security and intelligence activities proposed by CSE and CSIS, and authorized, respectively, by the and the .
My independent approval is necessary because the activities that the ministers authorize may be contrary to the law or breach the reasonable expectation of privacy of all Canadians. I have 30 days to render my decisions, but I adapt to much shorter timelines when urgency calls for it. Only with my approval can the activities be conducted.
When I approve a ministerial authorization, I assess whether the minister's conclusions are reasonable in light of the factors the legislation requires the minister to consider, including the impact on privacy interests and cybersecurity. For most of my decisions, my primary concern is how the proposed activities impact the privacy of Canadians. I apply the legal principles of proportionality and reasonableness, and I ensure compliance with the charter, including section 1.
[Translation]
In this regard, when I look at the factors the minister must consider when issuing an order under this bill, I am confident that these orders are similar to the ministerial decisions I currently oversee, and raise legal issues my office is well versed in.
In my experience as intelligence commissioner, I understand how certain orders could only be effective if they are confidential. Although I operate in a classified environment, my oversight role calls for me to be as transparent as possible with Canadians. I share my decisions with the National Security and Intelligence Review Agency, presided over by Ms. Deschamps, for post-facto review purposes. I publish redacted versions of my decisions on my office’s website. Decisions rendered under this bill would likewise be published.
My annual report, which was tabled in Parliament last Friday, also provides information on the impact of the activities that I oversee and on the significant legal issues at stake.
[English]
Would my office require additional resources for this new function? I have no control over the number of ministerial orders that I would review, nor how complex or voluminous each file might be. Another consideration is the potential effect of judicial reviews. These considerations could impact the resources my office needs. My role is on a part-time basis, and I adapt my work and my life accordingly. My expectation is that if my office requires additional funding, this will be provided in a timely manner. I would certainly appreciate a firm commitment from the minister to that effect.
One element I would raise for your consideration relates to the minister's extending, or not, the validity period of an order. Currently, there's no limit to the validity period or to the length of any extension. Under my existing jurisdiction, maximum validity periods are specified, and renewals require a new approval by the IC. I suggest a similar approach in this bill.
[Translation]
I will be happy to answer your questions.
:
Thank you so much for putting this question forward.
As drafted, the bill has a blanket secrecy provision that would essentially prevent us from being able to explain to our users that these changes were made and, if discovered, why they were made. This latter part is really important because, ultimately, our services are available around the world. This means there are security researchers, technical experts and journalists around the world who regularly decompile and reverse-engineer our products. Sometimes it's because they're trying to look for vulnerabilities and help us shore up our systems through bug bounty programs. Sometimes it's because they're trying to see if they can get any information on what our next product or feature releases will be. This happens with all companies like ours.
Ultimately, these kinds of changes will be discovered. It's not a question of “if”. As Rachel was saying, when it comes to the exploitation of a vulnerability, discoverability is a question of “when”. Providers would then be in a really significant conflict because users would completely lose trust in the security and privacy protections of our products.
:
I thank the witnesses for being here.
[English]
I'm so happy to see you in front of us today. I have a lot of respect for the work that you have done throughout your careers.
I will start with you, Mr. Noël. Over the years, I have come across your work with respect to security certificates and many other pieces of national security legislation, and I have a lot of respect for this.
You stated earlier that one of your key functions involves privacy, looking at privacy with respect to this legislation. Would you suggest that it would be at all helpful for the Privacy Commissioner to be involved in this legislation and this process?
:
It's hard to guess what will be in the future. With the new era we're in, gone are the days of the telephone book that police organizations could go and consult. The Meta groups and the others control all of that information. The government is put in a position of trying to improve the system of investigation across Canada.
[Translation]
He is trying to establish a framework, an architecture to be able to do so.
[English]
I would suggest to you, sir, that Canadians, when they hear about pedophile issues and bank fraud, expect the system to adapt to the new era. Measures have to be undertaken. This is one proposal. Some people don't like part 2, but somebody at some point will have to decide how the data banks, essential to police organizations, will be used, and that's one example.
:
Thank you very much, Mr. Chair.
I’m very glad to hear from you, Ms. Deschamps and Mr. Noël. I think you are the only francophones to have spoken in the four hours since the meeting began. So, that’s music to my ears. I wanted to tell you that.
Ms. Deschamps, it’s fair to say that the National Security and Intelligence Review Agency is a young organization. I think it’s been around for about six years. I feel like I’m the member encouraging my colleagues to learn more about the agency, because it’s still pretty unknown. By attending your briefings, I’ve come to realize just how important it is in terms of protection and oversight.
Regarding Bill , the minister does not seem to understand what you are asking for and what I am about to ask for, namely that the agency be notified. This is not a request for you to be involved in the decision-making process. We know that, under the bill, this is the job of the intelligence commissioner.
Could you explain to us why, in Australia or other countries, they have chosen to allow agencies equivalent to yours to provide superior protection and surveillance by granting them access to real-time information?
:
Ms. Deschamps, I’m sorry to interrupt you, but, as you know, I only have five minutes.
We understood that perfectly well when you gave your speech. What I want to understand, and what I want you to explain to people, is the fact that some countries have made a different choice than the one the government made in Bill . These countries notify their oversight body in real time of decisions made, for example, by an intelligence commissioner.
Canadians and Quebeckers would benefit from knowing that the agency is informed in real time, as this would reassure them. If the agency is informed a year after the fact, it requires a significant investigative effort. Furthermore, it does not necessarily have a large team that would allow it to quickly determine if the actions taken were not in compliance with the rules.
Did I understand that correctly?
For example, in Australia, the turnaround time is only a few days. This saves the agencies that oversee intelligence activities from having to request information.
When you are forced to request information, it is not efficient for anyone. You have to do it on a case-by-case basis, with each of the agencies involved. It takes time for the body requesting the information, and it takes time for the agencies receiving the request. So, all we're looking for is greater efficiency. If we receive the information automatically, it avoids this entire process.
:
Thank you, Ms. Kirkland.
We just have three asks—three recommendations for this bill. Remove obligations for companies to add government or third party surveillance tools or other software to their systems. That would include our company. Strengthen the definition of “systemic vulnerability” to explicitly rule out any requirement that would weaken or break encryption, mandate client-side scanning or otherwise introduce a security weakness. Codify the process for companies to challenge problematic requests. I think we heard that after-the-fact protections are really no protection at all. Those are our recommendations for dealing with part 2.
For what it's worth, we think part 1 responds to the criticisms that were made about part 14 of the previous bill, Bill . It is a good framework, subject to a couple of tweaks, to provide law enforcement with the information it needs to conduct investigations. Part 2 is really the problem with this bill. We are recommending some pretty significant, fundamental changes to that part.
:
Of course, we do not control all the information.
One thing that's critically important about the services we offer is this: People use our services for different things. That is why we are proud to be, really, the largest service provider of end-to-end encrypted communications services in the world. At the end of the day, people are extremely dependent on having secure and private mechanisms for communications, whether for friends and family, for running their business or for engaging in day-to-day life. The reality is that governments rely on end-to-end encryption, as well, to conduct government business and represent the interests of constituents.
The idea that technology is changing so quickly is one of the most important things for us to think about. Encryption is one technology that is changing very quickly but not in the way many people expect. One of the new waves of development in encryption technology is the implementation of post-quantum cryptography. One of the greatest threats we're facing over the course of the next several years is this: As we see advances in quantum computing, there need to be similar advances in post-quantum cryptography because that's the only type of cryptography that's going to be resistant to the ability to decrypt previously encrypted information.
One thing we're concerned about with this bill is that there are insufficient safeguards to ensure that encryption won't be undermined or that a mandate to break encryption won't be imposed. This will become significantly more dangerous in the future when you're looking at trying to build secure exceptional access—which is really a paradox in itself. It's not something that's possible to do. It will be much more difficult in a future state with post-quantum cryptography.
[Translation]
Ms. Deschamps, I believe you have already expressed your point very clearly. You sent a letter to the committee chair, Mr. Jean‑Yves Duclos, on April 16, 2026. That letter contained two proposed amendments.
If these two amendments were adopted by the committee and, eventually, incorporated into the bill, would that be sufficient for you, with regard to the matters within your organization's purview?
:
All right. That's perfect.
Mr. Noël, thank you very much for being here.
You mentioned the need for additional resources. That's for sure. The bill provides for a very significant mandate for you.
Are there any changes we should make? If you tell me that's not your role, I'll understand.
However, do you have any suggestions for improving the bill, aside from increasing your resources?
[English]
Now let me come to Meta. Thank you, by the way, for coming all the way from D.C. It's very much appreciated.
Rachel, I know you didn't come from quite as far, but thank you also for being here.
I don't think it's feasible that we're just going to drop part 2, but I do understand the requirement. One thing that I'm very sympathetic to is the question of clarity—first of all, a clear definition of a systemic vulnerability; and second, a clarity that the order, should a section order be given, is still subject to...that an order can't require you to do something that creates a systemic vulnerability.
Would that largely assuage some of the concerns that you have?
I wanted to also note that, of course, a lot has come up about the terms and conditions of Meta. I would say that, having read the extremely long terms and conditions, it would be very easy to put in a caveat to say that one of the many exceptions to the privacy that you're guaranteeing to the user would be that Canadian law should, in the event that X and X happened....
Let me just come back. Since we have an expert from the States, can you just talk to us about the major differences between the two major pieces of U.S. law and this one, and where you see the distinctions?
:
I'm at page 37, on the top left. It says, “electronic service provider” means a person that, individually or as part of a group, provides an electronic service in Canada or carries out part of its business in Canada.
Then the question becomes what an electronic service is, and that is at the prior page. If you go to the earlier page, it says, “electronic service” means a service, or a feature of a service, that involves the creation, recording, storage, processing, transmission, reception or making available information in electronic form or other technological means.
That sounds to me like a law firm that has a server that runs emails of its clients. It sounds to me like a bank. It sounds to me like a doctor's office.
:
I can assure you that this would be a very important factor and that I would look into it seriously.
[English]
I would like to reassure Meta that in that case, you would present to me a document. If it's convincing, I would certainly look at it seriously and make up my mind down the road.
I do know what encryption is all about. I know how important it is. If something is trying to circumvent the encryption and open up the channels to other things, I still have common sense. I know what I'm doing. My intent, at the end, is to protect the privacy of Canadians, wherever they are.
:
Thank you very much, Mr. Chair.
Ms. Greene, Meta already complies with the U.S. CLOUD Act, which gives, as you mentioned, American authorities the power to compel U.S.-based technology companies to produce data under their possession, custody or control, regardless of whether the data is stored in the U.S., Canada or elsewhere abroad. Under the CLOUD Act, the U.S. authorities can obtain access to Canadians' data, through judicial orders served on companies like Meta, and Meta accepts those obligations as a part of operating in the United States.
Bill , similarly, requires lawful access based on Canadian legal authorization—