:
Good morning, everyone. This meeting is called to order.
Welcome to meeting number 38 of the House of Commons Standing Committee on Public Safety and National Security.
If I may, I would like to move right away that we adopt the three budgets that the clerk sent last week. There was one for the study of the main estimates, a second for the study on the management of the Canada-United States border, and a third for the study of Bill , which we are continuing today.
As you know, the amounts that have been provided to us are estimates. The committee could spend less than planned. Any unspent funds will be returned to the Liaison Committee.
If you have any questions, the clerk will be happy to answer them.
Is it the committee's pleasure to adopt the three budgets?
Some hon. members: Agreed.
We will now move on to the main topic of our meeting today.
Pursuant to the House of Commons order of reference of April 20, 2026, we are meeting today for consideration of Bill , An Act Respecting Lawful Access.
Today we are fortunate to have with us many distinguished witnesses, whom I would like to welcome.
From the Barreau du Québec, we welcome Marcel‑Olivier Nadeau, president of the Barreau du Québec, who is joining us by video conference; Nicolas Le Grand Alary, lawyer from the Secretariat of the Order and Legal Affairs, who is with us; and Michel Marchand, member of the Criminal Law Expert Group, who is joining us by video conference.
We also welcome Luc Lefebvre, chair and co-founder of Crypto Québec; as well as Philippe Dufresne and Marc Chénier, from the Offices of the Information and Privacy Commissioners of Canada.
I want to welcome each and every one of you back. You will each have the floor for five minutes for your presentations.
Mr. Marcel‑Olivier Nadeau, you have the floor.
Members of the committee, thank you for having us here today.
Allow me to introduce myself. My name is Marcel‑Olivier Nadeau, and I am the president of the Barreau du Québec. I am accompanied by Michel Marchand, a member of the Criminal Law Experts Group, and Nicolas Le Grand Alary, a lawyer with the Secretariat of the Order and Legal Affairs of the Barreau.
The Barreau du Québec thanks you for inviting us to take part in the consultations on Bill . Let us recall that the mission of the Barreau du Québec is to protect the public, to promote accessible justice and to defend the rule of law. It is in that capacity that we are speaking today.
To begin, I would like to remind you of a fundamental principle. The concept of the rule of law is at the heart of our democracy. It requires that state powers be exercised, particularly in criminal investigations, within a framework, predictably and subject to independent judicial review. It also requires that laws uphold the fundamental rights guaranteed by the Canadian Charter of Rights and Freedoms, including the right to privacy and protection against unreasonable search and seizure. This balance is not theoretical. It is essential to maintaining public trust in our institutions.
The Barreau du Québec recognizes the legitimate objective of the bill, which is to modernize investigative tools in an ever-changing digital environment. We are nonetheless concerned about several provisions that could undermine fundamental rights, particularly when it comes to privacy and constitutional guarantees. Our goal is therefore to improve the bill so that it achieves its objectives without compromising the principles central to the rule of law or provoking court challenges.
Our recommendations focus on four main points.
First, the definition of subscriber information is too broad. The bill provides a very broad definition that is likely to reveal sensitive personal information when combined with other data, such as a person's name, alias, address, phone number and email address. The Supreme Court has also reminded us that the reasonable expectation of privacy must be analyzed in the current social and technological context, in which a massive quantity of data is collected, cross-referenced and retained. As a result, even isolated information can reveal a great deal when combined with other information.
Furthermore, the lack of a clear definition of the term “person providing services to the public” increases the risks of the invasion of privacy, as it allows for broad interpretation and potentially abusive applications. In the absence of legislative safeguards, this generic wording is likely to apply to a wide range of entities. That includes not only Internet service providers, but also companies and organizations with sensitive personal information.
This wording also creates uncertainty for the entities concerned, which could be forced to pass on sensitive information without clearly knowing whether they are legally required to do so. We recommend clarifying and narrowing these definitions to avoid overbreadth.
Second, the bill sets out an insufficient legal threshold for obtaining production orders. Under the bill, certain orders could be authorized on the basis of “reasonable grounds to suspect”, which is a lower threshold than is generally required for infringements of fundamental rights.
Let us not forget that the Supreme Court has established that subscriber information has a high level of constitutional protection, warranting rigorous judicial oversight. In our opinion, by stipulating the lower standard of mere suspicion, which does not require probability but only a reasonable possibility that an offence has been or will be committed, the bill does not meet constitutional privacy requirements. We therefore propose that, as with other similar orders currently in the Criminal Code, the threshold of “reasonable grounds to believe” be considered.
Third, there is a lack of judicial oversight in certain situations. Indeed, in certain cases, the bill allows for voluntary disclosure of information without judicial authorization, which we consider a significant departure from traditional safeguards in criminal law.
Let us not forget that even information that is considered “basic”, such as a subscriber's contact information or IP address, can, when linked to other elements, provide a detailed profile of the person in question. In this regard, the courts have found that it is imperative that the disclosure of this information be accompanied by procedural safeguards, including the requirement for prior judicial authorization. We recommend removing these mechanisms or, at the very least, requiring prior judicial oversight in all cases.
Fourth, the protection of solicitor-client privilege and computer data is at risk. The bill makes useful changes for the review of computer data. We maintain, however, that there should be a requirement that the extraction of computer data must be carried out by a person whose only role in the investigation of the offence in question is precisely to extract that data. That would be an effective way to avoid contamination of the investigation and, at the same time, to preserve solicitor-client privilege, which is a principle of fundamental justice as defined in the Canadian Charter of Rights and Freedoms.
:
Mr. Chair, members of the committee, I appear before you today on behalf of Crypto Québec.
When I last appeared before this committee, as part of the consultations on Bill , I concluded by saying that the Quebec model increased overall security by harmonizing security and privacy protections, and that the government should draw inspiration from this approach, which has already proven to be effective.
[English]
However, today we find ourselves faced with a bill that many information security professionals in the country and abroad, as well as several technology organizations, consider fairly dangerous. These are organizations whose applications are used daily by a very large number of elected Canadian officials as well as law enforcement. I am notably thinking of Signal from the Signal Foundation, which is threatening to leave the country if this bill is passed, so as not to weaken the encryption of its application.
In our opinion, this bill should be withdrawn and completely rethought. The basic premise of this bill is flawed.
[Translation]
Bill is based on a premise that has never been rigorously publicly demonstrated, which is that encryption is the main threat to public safety in Canada today. There is no evidence of that.
We've heard anecdotes from certain police forces and intelligence agencies, but we've never seen any empirical, public evidence that encryption is the greatest threat to Canada's national security.
On the contrary, it has been shown that the more data that is collected, the greater the risk of data leaks, without any real improvement in security.
[English]
To that effect, in the U.S., just a few years ago, it was demonstrated by The Washington Post that the FBI had massively overestimated the number of investigations allegedly blocked by encryption. These figures were then used publicly to justify the expansion of surveillance powers. We should not repeat the same mistake in Canada.
While we're being told about encryption being the problem, the actual public reports from the Canadian intelligence agencies, such as those from NSICOP, primarily tell us about foreign interference, deficient resources and the opaque expansion of the national security apparatus. The problem is thereby pretty clear. There's a lack of human, technical and financial resources as well as an excessive increase in data collection powers without any real oversight capacity. Bill addresses none of that.
[Translation]
Encryption is not the heart of this crisis; it is the solution.
Despite this, Bill C‑22 proposes nothing less than the creation of a permanent digital monitoring infrastructure. It would be an infrastructure in which service providers could be forced to keep more data, maintain technical access capabilities, respond to secret orders, and participate in extraction processes, even though the word “oversight” appears exactly zero times in the text of the bill.
The bill also makes no specific reference to robust democratic checks and balances. This is extremely concerning. A healthy democracy is founded on privacy, freedom of association, confidentiality of communications, and spaces where citizens can discuss and criticize power without fear of permanent structural monitoring.
[English]
To Albertans and Quebeckers alike, I say this. No federal government should ever possess expanded structural surveillance capabilities in a context where major democratic and constitutional debates may one day oppose Ottawa and the provinces.
[Translation]
Canada's history reminds us that national security tools can sometimes extend beyond external threats and affect domestic political movements. That's precisely why stellar democratic guardrails are needed.
It is also important to note that if this bill passes in its current form, all the efforts made in terms of digital sovereignty in Quebec will become null and void.
[English]
Protecting democracy in Canada requires strong institutions that balance security and privacy with robust oversight, checks and balances. Bill , unfortunately, gives the impression that the main threat to Canada is becoming increasingly internal rather than external. We all know this is a slippery slope for a liberal democracy.
In closing, we believe that the Canadian Parliament should not adopt such a fundamentally transformative bill based on unfounded assumptions, fears or premises that have not been publicly demonstrated. There is no back door that is only used by the good guys. The history of cybersecurity shows us precisely the opposite.
[Translation]
Since the likelihood of potential abuses and their effects are too great, we are calling for Bill to be withdrawn in its entirety.
Thank you.
Members of the committee, thank you for inviting me to share my views on Bill .
Last week, I made a written submission to the committee, which I will address in greater detail today.
Bill reintroduces lawful access provisions that were originally proposed in Bill , but with several changes that reflect feedback the government received. Some of these changes are consistent with written recommendations on Bill that I submitted to the last November.
[English]
Bill improves on its predecessor, Bill , in several respects. In particular, I welcome the more narrowly tailored confirmation of service demand. I appreciate the addition of potential privacy and cybersecurity impacts as factors that must be considered in the making of regulations and orders under the supporting authorized access to information act, the SAAIA. I'm also pleased to see the act's new oversight role for the intelligence commissioner with respect to ministerial orders.
That being said, in my written brief to this committee, I've highlighted some aspects of Bill that would warrant, in my view, further amendments to strengthen and ensure privacy protections for Canadians.
Specifically, I recommend narrowing the definition of “subscriber information” to a closed list of discrete identifiers, such as a subscriber's name, address, telephone number and IP address. This would help to avoid capturing information that could attract a heightened expectation of privacy.
I also recommend restricting the range of persons or entities who could be compelled to produce subscriber information to telecommunications service providers, and ensuring that the justice or judge making the order can specify the subscriber information that must be produced.
[Translation]
In addition, I recommend defining “publicly available information” to exclude information in respect of which an individual has a reasonable expectation of privacy, as defined in the Communications Security Establishment Act.
The concept of so-called publicly available information continues to evolve, and an individual does not automatically waive any reasonable expectation of privacy for information that may be available online. Take, for example, a situation where an individual's information was disclosed as a result of a data breach or published without their knowledge or consent.
[English]
Another recommended amendment would be to add an overarching requirement that obligations imposed under the SAAIA be limited to what is necessary and proportionate. This would help to ensure that any such obligations, including with respect to the retention of metadata, are tailored to minimize privacy impacts.
On the issue of accessing information, I would recommend amending the definition of “systemic vulnerability” to clarify that it includes any action that would render systemic methods of authentication or encryption less effective, as in Australia's analogous law. In addition, I recommend specifying that regulations and orders must not have the effect of requiring an electronic service provider to introduce, or of preventing an electronic service provider from rectifying, a systemic vulnerability.
[Translation]
Finally, I recommend adding an exemption to the confidentiality rules set out in the supporting Access to Information Act which would expressly authorize electronic service providers to share information with appropriate regulators, such as the Office of the Privacy Commissioner of Canada, to enable them to properly exercise their powers and duties.
Thank you for your attention. I look forward to your questions.
[English]
Monsieur Dufresne, the scope of this legislation is to provide basic information on an individual, not the content of their data, not what they browse and not what is in their emails. The department has taken the time to carefully consider privacy concerns and charter considerations. However, we have heard concerns that the current wording in proposed section 487.011 could capture services outside Internet service providers, worded as “who provides services to the public”.
As the Privacy Commissioner, what language changes would you suggest to narrow the scope of services captured in proposed section 487.011 so that these concerns are addressed, while ensuring law enforcement have tools to access the information they need?
:
Absolutely, it's important that this bill balance the need for police forces to have the tools they need with protecting Canadians' privacy, and we can do that. It's not a zero-sum game between privacy and security. We address this in our written brief in our first three recommendations.
Specifically, the first thing that should be done is to narrow the definition of “subscriber information”. Change it from what it is here, which includes broader concepts like “information that may be used to identify” individuals or “information relating to the services”, and narrow that to specific items such as the name, address, telephone number and email address. We specify that in our brief.
The second thing is to restrict the scope of who can get those orders to telecommunications service providers. That's already there for the warrantless requests on confirmation of service demand, but in terms of the subscriber information, it's open to “a person who provides services”. That in our view is too broad. It could capture medical offices and law offices, and capture any amount of sensitive information.
The last element is that you should provide more specificity in terms of what the judge's order will be. Right now, it says “any subscriber information” and “all the subscriber information” related to something, and that could be broad. We're suggesting a narrowing of that language.
I'll flag the last element in terms of the non-warrant search or confirmation of service demand. There's an exception for medical and privileged information, and that exception is also absent in terms of the subscriber information.
Those are the recommendations I would make.
Let me start by saying how disappointed I am to have so little speaking time with such a rich panel of witnesses.
Since time is limited, I will try to keep my questions short, so you can provide clear answers.
Personally, the more I learn, the more confused I am. The views on the bill are vastly divergent and very polarized, depending on whether we're speaking to a police officer or a privacy advocate. My goal is to tell stakeholders that, yes, this is an important and necessary bill, but also to figure out what that balance is going to look like.
Mr. Dufresne, I'm always surprised that your recommendations aren't heeded before a bill is drafted. We're always a bit behind. We went through that with Bill . No one bothered to consult you. Now you're here with your recommendations, and opposition parties are the ones proposing them as amendments to the bill. I find that strange, especially since we have so little time to debate them. We would have preferred that the government do its job, listen to you and include your seemingly reasonable recommendations in the bill. It would have made for a better bill and saved us time.
Mr. Lefebvre, you got my attention when you said a lawful access regime had not been shown to lead to a decrease in crime in the U.S. There is no evidence of that. Weaker encryption doesn't necessarily equal less crime. Here's what police tell us: They'll be more effective, they'll stop more criminals and they'll be able to combat organized crime.
You seem to be telling us it's not that straightforward.
Can you give us more information on that?
:
The tendency to try to control what we call lawful access in Five Eyes countries goes back 10 or 15 years. Australia's and the United Kingdom's laws are particularly robust when it comes to collecting data for the stated purpose of combatting pedocriminality, going after criminals and such.
To date, however, there is no evidence that crime decreases when law enforcement has greater access and more say over the level of encryption of applications, messaging platforms and other tools. Those broader powers have not been shown to lead to a decrease. At the end of the day, more information is being collected, but crime isn't going down. That's all this is doing.
What we actually see with the broadening of powers is that criminals tend to go dark. They use other methods, other tools, and the trail ends up going cold anyway. Nevertheless, more and more data are being collected on ordinary people—people who aren't involved in these activities.
:
I would say two things to that.
First, it makes sense that police services would welcome this legislation. I come from a family of police officers who were involved in fighting pedocriminality and the like. I completely understand the excitement, and it's necessary. It's no surprise that police forces are pleased about this. It's perfectly commendable.
Second, my sense is that the pressure is coming mainly from members of the Five Eyes group, which is looking for more and more visibility across the network, as well as from allies. Canada is indeed lagging behind when it comes to being able to provide access to those data. There's clearly some political pressure to do that.
It's probably the easiest solution for the government to say that it's going to bypass encryption to give police forces access to Canadians' data. Police will be happy. It's easier than allocating more financial, technical and human resources to fighting crime. At the same time, it will make our allies happy. That's the impression I have.
:
They aren't drafted how the Office of the Law Clerk would draft them, but I don't think it should be too difficult to turn them into amendments, given how we've laid them out in our brief.
We refer to existing regimes, such as Australia's law, which stipulates that orders must not have the effect of rendering encryption less effective. That amendment is in there. One of the provisions in the bill we're concerned about says that the provider is not required to comply with an order.
We feel it's important to state that the order shouldn't be made at all. It puts the provider in a tough spot. They are being ordered to do something but are allowed to disobey the order under the law. I think things should be done right from the start.
We addressed necessity and proportionality, referring to Great Britain, which takes those factors into account. Australia does too. They are core principles, so it's not hard. They can be added to the factors the minister or Governor in Council has to take into account.
The eight recommendations we've made are targeted and concise. Essentially, they're intended to achieve that critical balance.
:
Thank you, Mr. Chair. I wanted to wait until my colleague Madame DeBellefeuille was finished.
I heard the Privacy Commissioner tell us about a submission he made to this committee. I believe the submission was sent to the chair on May 21. We had not received that submission until just now.
I'm not trying to attribute malice to anyone, but my ability, as a parliamentarian, to scrutinize this legislation and be prepared for today's meeting was really impacted. By not receiving documents sent in by witnesses, I have no ability to properly review them.
As an aside on another point, we still don't have the transcript from our meeting two weeks ago. I just raised this with our clerk, who assures me that it's coming. You know, we had a two-week break. If we're not able to get critical information to help us do this, given the rushed nature of this legislation we're sending through.... I have very serious reservations about how quickly this process is going, as we're not being given adequate information and evidence to get this bill done.
With regard to the transcript, we have been informed that the publications department of the House of Commons has set service standards. I can look into those service standards and get back to the committee, as I don't have them with me right now. However, they wrote to me on Friday indicating that there have been some delays, notwithstanding the length of the meeting on May 7, which was four hours instead of two, and the large volume coming through their office as well. They've indicated that they are working as hard as they can to get that transcript out.
I can send the blues to you right now, Mr. Lloyd, and I will do that. The blues are usually available within the firewall. If any member cannot access them, we can send copies to them.
With regard to the document from the Privacy Commissioner, that mistake was entirely mine. I do apologize to the committee. Unfortunately, it slipped through my fingers and I did not get it out in as timely a fashion as I would have preferred. I beg the committee's indulgence on that. You have my apologies.
Thank you.
I really do appreciate the explanation from the clerk. We know that accidents like this happen.
I was told that we could access the blues within the firewall on our devices. I have my House of Commons phone here. I just looked, and the blues are not available on my House of Commons phone.
You know, despite the fact that this does look like it was an honest mistake, given the gravity of the legislation we have before us, I feel that I've been really disadvantaged and that my privilege has been violated by not being able to have the correct information available to me in order to participate in the session. I'm looking for some guidance from the chair. I believe my privilege has been violated here.
:
Yes. I'll intervene just briefly.
Given what Mr. Lloyd has reflected on, that his privilege has been breached, and not even as a prima facie breach but as an obvious breach, I would ask, Mr. Chair, if you and the clerk would be able to canvass the Privacy Commissioner's ability to return next week and, in any event, prior to clause-by-clause consideration.
I also think the appropriate remedy here is that we do not have amendments close tomorrow. I think it's very obvious that this is the only remedy in what is already a very rushed process. I think this is symptomatic of the fact that we have been moving very quickly. I do not place any blame on the clerk. These things happen. Mistakes happen. We've had four-hour meetings. We're in the midst of another four-hour meeting.
I won't say any more. Thank you.
:
Actually, some metadata are encrypted, depending on the system. Signal is a great example.
On Signal, the metadata are encrypted. Data that aren't encrypted include the account creation date and the last date of a user's connectivity. However, once a user is connected to Signal and in their account, there's no way to know who a user is communicating with, when or what the content of their discussions is, as opposed to email.
With an email application, certain data are available: who communicated with who and when, what server the email was sent on, what the subject of the email was. The content of the message isn't necessarily available, but those metadata are. It all depends on the type of system, on the type of encryption the application uses.
In this case, the purpose is to access data that weren't previously available, such as in Signal, by reducing the level of encryption.
:
Okay. I accept your definition, Mr. Lefebvre. Signal stands out because of the secrecy around its metadata.
Unless I'm mistaken, messages are encrypted most of the time, and the government made clear that it didn't want any information in the messages. We are talking about dates, locations and other such data. That isn't encrypted information. The government isn't on a mission to decrypt people's communications.
Mr. Dufresne, you say that the government is there to go after the bad guys. We aren't there to look at information about people's health. We aren't there for that.
Given that we and our colleagues opposite didn't see your report, can you tell us your main recommendation to ensure that the legislation captures only information relating to criminal activity?
:
I would say recommendations 1, 2 and 3 in the brief.
The purpose is to limit the type of information that can be obtained. I think that's what the government is trying to do, so specifying the information in question will reassure those who are concerned.
The idea is also to limit the types of persons and entities subject to these orders. As it stands, the production order applies to any person who provides services to the public. That's a broad range of people, so it would be possible to obtain people's medical information, for instance.
I think it should be limited to telecommunications service providers, as in the earlier provisions relating to non-warrant requests. I think that would restrict access to only the information the bill is really trying to capture.
You talked about the threshold and the difference between “reasonable grounds to suspect” and “reasonable grounds to believe”.
Obviously, no one is against virtue. Everyone would prefer a higher threshold. The premise of the government, however, is that the information being sought, in other words, metadata, isn't evidence that can be presented to the court. It's information that will help further an investigation, to obtain evidence that can ultimately be used in court. That is why the government used the “reasonable grounds to suspect” threshold instead of “reasonable grounds to believe”. It is an accepted, recognized and well-known legal standard, after all.
:
I have a point of order, please.
For a moment there, I thought it was me and the with Mr. Ramsay and our witness, but my point of order has to do with Mr. Lloyd's issue of privilege.
I've spoken with the clerk. I would ask that the clerk confirm on the record and that you, Mr. Chair, confirm on the record that you did not see the submission from the Privacy Commissioner, and that the clerk, to the best of his knowledge, did not forward it to you.
Is it accurate, Mr. Chair, that you did not see the submission from the Privacy Commissioner?
Mr. Nadeau, my questions are along the same lines as the parliamentary secretary's, so I'm going to continue the discussion with Mr. Marchand.
Basically, if I understand correctly, the “reasonable grounds to suspect” threshold in Bill applies to specific data that aren't considered sensitive.
You are arguing the opposite. The , the justice department and department officials are saying this respects the Supreme Court's decision, but you don't seem to agree.
Can you elaborate on why you think that, to help us really understand your point?
:
Good morning, everyone.
We are beginning the second part of this meeting with new witnesses, whom I would like to welcome.
We are joined by Erik Neuenschwander, senior director of User Privacy and Child Safety, from Apple.
From the Canadian Civil Liberties Association, we are joined by Tamir Israel, director of the Privacy, Surveillance, and Technology Program. He is participating in the meeting via video conference.
From Google, we have Katherine Charlet, senior director, and Jeanette Patell, director of Government Affairs and Public Policy, both participating via video conference.
We will now begin the five-minute presentations.
Mr. Neuenschwander, you have the floor.
Good afternoon, Mr. Chair, vice-chairs and members of the committee. My name is Erik Neuenschwander, and I'm the senior director of user privacy and child safety at Apple, where I've been a software engineer for 19 years. I worked as the first data analysis engineer on the first iPhone, and I founded Apple's privacy engineering team. Today, my job is to make sure that Apple's products and services keep our users' information safe. Thank you for the opportunity to speak with you today.
As you know, this may be one of the last times we're permitted to discuss the consequences of this legislation publicly. That's because of the bill's secrecy provisions, which forbid companies like Apple from even discussing, with our users or the public, the orders we receive.
Today, I want to be clear about how we approach privacy at Apple. I want to be clear about why encryption is so important to defending the privacy and security of people in Canada and around the world.
These issues have never been more important because our world is becoming more digital by the day. As users, we depend on our technology to securely store and process highly sensitive data like health metrics, photos and the locations of our loved ones. The places where we keep our money, store our files and conduct business are increasingly online and, sometimes, only online. The critical infrastructure we often take for granted, from the electric grid to transportation networks, is increasingly dependent on connected devices as well.
However, as technology evolves, so do the bad actors trying to steal our data. Canada has witnessed this first-hand. In 2023, Canada was one of the countries most frequently targeted by ransomware attacks. Just last year, malicious actors targeted Canadian telecom and other networks as part of the massive Salt Typhoon attack, not to just steal customer data but to also conduct broad espionage and to control the communications infrastructure that billions of people rely on every day.
As a technology company, Apple is constantly working to anticipate and prevent these threats. As an engineer, I can tell you that end-to-end encryption is one of the most effective security technologies available to defend against them. Encryption protects Canadians from identity theft, fraud, unlawful surveillance and data breaches. It protects critical infrastructure. It protects the data and communications Canadian businesses and government rely on, which are crucial to Canada's economic success and national security.
Our users trust Apple with their most sensitive information. They expect and deserve the strongest protections. That's why we're so concerned about the threat to encryption posed by Bill . As drafted, this bill allows the Government of Canada to force companies to break encryption by inserting back doors into their products, something Apple will never do.
I want to be clear that we share the government's commitment to the safety and security of all Canadians. We have a team of dedicated professionals on call, 24 hours a day, to assist law enforcement. From 2020 to 2024 alone, we received just over 3,200 Canadian government requests for information, about 35% of which were emergency requests. We're committed to supporting law enforcement's work to keep Canadians safe, and we're committed to encryption technology for the same reason, to keep Canadians safe.
Again, speaking as an engineer, I do not know of a way to deploy encryption technology that provides access for only the good guys without creating new ways for the bad guys to break in. In other words, when you build a back door into an encrypted device, anyone can walk through, and because so much depends on encryption, we can't take that risk.
Look no further than Salt Typhoon. The United States passed a law requiring telecommunication companies to build access points for law enforcement into their systems, which state-sponsored actors then exploited. That law was narrower than Bill , so imagine what could happen if more companies were required to create these vulnerabilities.
Apple has provided a written submission outlining targeted amendments that would improve the bill, which I'm happy to discuss. We urge the committee to adopt amendments that would, in particular, explicitly prohibit any requirement that would weaken, bypass or undermine end-to-end encryption. We believe these changes would still expand lawful access and provide Canadian law enforcement with new tools to fight crime in the 21st century.
Again, thank you for the opportunity to speak today, and I look forward to your questions.
:
Mr. Chair and honourable members of the committee, good afternoon. I thank you for inviting me to speak before you today on Bill , an act respecting lawful access.
Part 1 of Bill represents a meaningful improvement over its predecessor legislation; however, elements of part 1 continue to suffer from overbreadth. These include the use of low standards for judicially authorized access to sensitive subscriber data and a framework that invites unconstitutional collection of publicly available data.
Elements of part 1 also allow Canada to adopt at least one, if not two, international information-sharing agreements, despite a growing tendency to use these tools for cross-border repression and an absence of comparable safeguards.
CCLA is filing a joint brief with Kate Robertson and Cynthia Khoo from the Citizen Lab, which will elaborate on these and other problematic elements of Bill . I'll focus the remainder of my remarks this afternoon on part 2 of the bill, which would enact the supporting authorized access to information sct, or SAAIA.
At various points in time, governments have sought to expand their surveillance capabilities at the cost of cybersecurity, with encryption being a recurring target. Too frequently, these expansions have been justified by the expectation that surveillance capabilities will only be used by lawfully authorized government agencies and not malicious actors, yet time and again, this expectation has been proven false. The Salt Typhoon attack is the latest and perhaps the most potent reminder of this hard lesson.
It's also notable that the case for this legislation has not been made. Indeed, half of our Five Eyes partners have limited their surveillance capability regimes to imposing wiretapping obligations on telecommunications carriers. With a troubling historical track record in mind, SAAIA is fundamentally flawed in three interrelated ways.
First, SAAIA is exceedingly broad. It applies to any provider of any service that has a digital component. Under the Australian version of this law, everything from a fast-food chain that provides its customers' Wi-Fi to an electronics store that helps maintain customers' phones and computers, to any retailer that has a mobile phone application or online website, has been listed as an anticipated target.
SAAIA is also broad in terms of what obligations the government can impose. These range from requiring the ability to covertly reset customer passwords or requiring an automatic tool that generates realistic undercover profiles on social media platforms to requiring the ability to block a target's use of encrypted private messaging services in order to force them to use insecure alternatives.
SAAIA's metadata retention mechanism is equally broad. Services can be required to retain a detailed record of every single person's movements, interpersonal interactions, what applications they use and more. This is highly sensitive data.
Second, stay of limitations and safeguards fails to constrain the multiple ways that privacy, encryption and other data protections might be compromised in light of the law's broad scope. SAAIA's systemic vulnerability limitation, for example, would not apply to a set of algorithmic monitoring tools referred to as client-side scanning. Because these tools bypass encryption rather than compromising it directly, they fall outside the systematic vulnerability limitation as drafted. They nonetheless create systematic vulnerability in practice.
Third, courts remain the primary vehicle for authorizing CSIS and police surveillance activities, but SAAIA does not rely on judicial authorization, despite authorizing powers that frequently rival their Criminal Code counterparts in breadth. For example, if police want to force a company to keep a specific customer's metadata for 90 days, they need a court order, but to force the same company to keep the same metadata on every single customer for up to one year, the government need only impose an obligation through SAAIA. Judicial review is available and even required in some instances, but judicial review is highly deferential to government decision-making and no substitute for independent authorization, de novo review or full appeal rights. This is particularly the case when many of the obligations are imposed in secret, as is the case under SAAIA.
In sum, SAAIA poses a significant threat to privacy and cybersecurity. It's unclear how SAAIA's many overlapping flaws can be remedied through the highly attenuated legislative study it's receiving. Australia's technical capability regime was amended 173 times during a detailed committee study. Despite these changes, they were still held to be likely incompatible with human rights and a mandatory assessment of the legislation.
We therefore urge you to recommend that the government advance Bill without part 2. This legislation will be in place for years to come, and it's critically important that we get it right. The stakes are simply too high.
Thank you. Those are my opening comments, and I invite your questions.
:
Good afternoon, Mr. Chair, vice-chairs and honourable members of the committee.
My name is Jeanette Patell, and I'm the director of government affairs and public policy for Google Canada. I'm joined today by Kate Charlet, a senior director on Google's public policy team, where she leads our work on cybersecurity, privacy and child safety. Before coming to Google, she spent a decade in national security roles at the Pentagon and White House.
Google is committed to supporting the efforts of law enforcement in protecting the public against crime and terrorism. We firmly believe that improving public safety and maintaining user security are highly compatible goals.
As a global leader in building safe and secure products, we take the privacy and security of our users very seriously. Our business is built on the trust our users place in us to keep their data safe. Google products are private and secure by design, protected by multiple layers of security and leading technologies, such as encryption.
I want to be unequivocally clear that Google has never built a back door or any other mechanism to circumvent end-to-end encryption in our products. When we say a product is end-to-end encrypted, it is.
In today's rapidly evolving threat environment, we believe it is critical to find ways to support law enforcement's important work without engineering vulnerabilities into products and services that weaken security for everyone.
Within this context, Google has significant concerns with several elements of part 2 of Bill as it is currently drafted.
First, the proposed regime contemplates obligations and order-making powers that are unduly broad and practically boundless. It goes well beyond lawful access regimes in other G7 democracies and risks creating new surveillance infrastructure that would introduce serious security vulnerabilities, undermine user trust and hinder our ability to innovate and offer pro-privacy technologies.
Second, the proposed framework for secret ministerial orders is unprecedented and undermines accountability and user trust. Part 2 gives the sweeping powers to issue secret orders mandating providers to create or maintain data interception capabilities, while permanently prohibiting companies from disclosing the existence of these orders. As written, this could give the government the power to secretly force companies to redesign products to include invasive surveillance capabilities, and to do so without sufficient safeguards or oversight.
Ministerial orders are not only alarming but also unnecessary. Canada already has an effective, transparent system where law enforcement can apply to the courts for reasonable assistance orders subject to judicial oversight. Secret orders are out of step with other democratic countries and would severely restrict companies' abilities to be transparent with users about how their data is protected.
Third, the bill's definition of “systemic vulnerability” is dangerously narrow. The legislation sets a very high bar, only recognizing a “substantial risk” of unauthorized access as a vulnerability, while ignoring severe risks to data integrity and availability. The current definition fails to explicitly protect the comprehensive security measures that Canadians rely on, which go far beyond encryption.
Without stronger definitions, the law could be used to force the dismantling of critical privacy architecture, such as breaking encryption, overriding users' data deletion controls or building remote access capability, all of which could facilitate foreign interference and weaken global user privacy. At a time when cyber-threats are increasing in frequency and sophistication and malicious actors are using AI tools to find and exploit vulnerabilities more quickly, we cannot afford to be creating new vulnerabilities.
[Translation]
Finally, the bill imposes overly broad requirements regarding the retention of metadata, without any geographic, temporal or targeted criteria. Such requirements would mandate the blanket and indiscriminate retention of people's communications data and risk treating the entire population as potential suspects.
Unnecessary data retention threatens the fundamental rights and freedoms of Canadians, infringes on their privacy and creates a massive trove of sensitive data that amplifies the consequences of any potential security breach. The existing provisions for targeted retention orders in the Criminal Code already meet law enforcement needs while respecting the rights guaranteed by the charter.
[English]
To ensure that Bill achieves its public safety objectives without compromising the digital security of Canadians, Google has submitted a number of legislative amendments. We'd be pleased to discuss them today.
Thank you for the opportunity to contribute to this process. I look forward to your questions.
:
The Australian regime does not include judicial authorization. This has been one of the heaviest criticisms levelled at the regime, including by an independent review of the regime that was conducted two years ago. It was the single biggest flaw that the independent review considered needed to be fixed right away. The U.K. regime does rely on judicial review by a commissioner.
Under Canadian law, judicial review, as a mechanism, is different from judicial authorization, and it's important to keep the differences in mind. Judicial review is an assessment of whether the decision-maker made a reasonable decision based on the information in front of them. In contrast, when judges are authorizing a search warrant or something of that nature, they are the ones who are weighing the different considerations.
Given the nature of the bill, it's particularly problematic to rely on judicial review alone, as opposed to a stronger type of independent scrutiny.
:
Thank you very much, Mr. Chair.
I thank the witnesses for joining us.
Ms. Patell, I thank you and congratulate you for taking the time to deliver part of your remarks in French. Your French is excellent, as is your pronunciation. So, thank you very much.
Your company operates in all Five Eyes countries, if I am not mistaken. Therefore, you are already subject to legal access regimes or laws, such as those in the United States. When compared to the United States, we see that Canada has more laws, mechanisms and institutions that protect privacy. At least, that is my interpretation.
So, given that your company also operates in the United States and that you say you find the Canadian government's bill too restrictive, can you tell us how, in your view, it compares to that of the United States?
I think the primary comparison here is to privacy principles. We think of privacy principles around data minimization and user controls and about the potential that Bill could undermine those privacy principles.
Just as an example, if we look at Google's provision of user controls, we offer users the ability to choose to delete their data after three months. Retention requirements or product changes that require us to make changes that would require retention for longer than three months would be against the wishes of a user. We look at this with concern in terms of privacy principles that are global in nature.
On your question regarding U.S. law, we look to U.S. law—CALEA specifically. CALEA does explicitly forbid governments from forcing a company to break encryption. That is a similar protection that we would be seeking in Bill .
:
You said six, so it's too late. I want those seconds back, though.
I'd like to start by talking about the fact that this is rushed. We've mentioned this before. It feels rushed to me as a parliamentarian. I had questions in the last hour that I really wanted to get to and wasn't able to because of how fast all this is proceeding. I made the statement early on that I thought we should be careful not to just race to royal assent. If we're going to do this, then we need to get it right.
I know that we've missed getting some submissions to the committee, and I don't fault anyone for that. I know there was no malice intended. I don't fault the clerk for that. It's to be expected in such a rushed environment that those types of things will happen.
Mr. Neuenschwander, it is my understanding that you did provide submissions to this committee. I don't believe it has come through the clerk yet, but thankfully, you sent them to each of us directly. I appreciate that very much.
I want to backtrack with regard to what I hear over and over again, the term “back door”. I think Canadians really need to understand what that means.
On the Government of Canada website from five days ago, under lawful access, it says, “Bill C-22 does not require ESPs to create 'backdoors' to their systems or [to] weaken electronic protections, including encryption.”
Also said in testimony by Mike McGuire was:
This part does not create new powers for law enforcement or CSIS to intercept communications or obtain information, nor does it allow direct government access to electronic service providers' systems. It also explicitly prohibits the creation of systemic vulnerabilities, to ensure that a regulation or ministerial order does not weaken encryption or create back doors.
The said:
This part also includes an explicit safeguard to prevent the introduction of systemic vulnerabilities in electronic protections. Our government does not support the creation of back doors.
Testimony today seems to make that obviously not really the case, so I need some clarification. I'm happy for each one of you to provide that clarification. I think the word “explicit” is worth taking a longer look at, because it doesn't seem to be explicit in this legislation. I know that there are ways that we can make it explicit, so I'd like each of you to talk about that briefly. Thank you.
We'll start with Mr. Neuenschwander.
:
I echo your concerns about intent versus application. It took seven or eight years before the U.K. version of this law was used to strip all people in the U.K. of a critical encryption safeguard for their Apple iCloud backup. It's not the immediate intent of the government that's relevant. It's how the bill could be applied over time.
In this instance, the bill does prohibit the imposition of systemic vulnerabilities, but that, by definition, does allow non-systemic vulnerabilities, first. Second, it leaves a lot of e-terms in the definition open to interpretation through regulation.
A big problem with the constant attempt to maintain end-to-end encryption secure is the multiple ways that governments and bad actors keep coming up with to get around encryption. Some of these mechanisms directly compromise encryption. I've seen government definitions of back doors limited to those examples, but other tools that are commonly advanced, for example, client-side scanning, which essentially places an AI tool on everybody's device that monitors their content before it's encrypted and sent onwards and has been assessed by leading security technologists around the world as creating systemic vulnerabilities, do not compromise encryption in the way that this exception would prevent. You need a comprehensive exception that rules out all back doors and all ways of bypassing encryption.
Thank you. I'm sorry for the long answer.
Mr. Neuenschwander from Apple and Ms. Patell from Google, I appreciate your testimony and your being here. I've read your submissions. As a general counsel for a computer company before I went into politics, I'm sympathetic to strengthening protection for encryption and clarifying the definition of “systemic vulnerability” and some of the other provisions you mentioned.
I want to respond to something Ms. Kirkland said. Authorities provisions are standard in any compliance framework. They are in many federal laws, and they don't really specifically relate to the core lawful access provisions of this bill. I just wanted to get that out.
Mr. Neuenschwander, I've read what you said. Has Apple ever gone before a parliamentary committee or made a submission to a national parliament on a lawful access regime that Apple actually supported?
:
I understand that. I understand that both Apple and Google are largely supportive of the idea but have objections to specific provisions of the bill. I just wanted to establish whether you have ever seen a bill that you didn't have objections to some portions of.
I think people are overstating some of the objections. I don't disagree with some of the objections you raised, but I don't think some of the claims that are being made—for example, surveillance equipment that could be installed in devices and forcing companies, even under orders, to put in surveillance equipment—are reasonable or logical. I don't think they bear out in the wording of the bill.
What I'm asking is this: Have you guys ever gone before a committee or made a submission in the U.K., in Australia or in the U.S. and said, “Wow, we think this bill is great”?
Erik from Apple Inc., welcome to public safety and national security.
I see a comment, which was made by the Apple company, in The Globe and Mail that this legislation could allow the Canadian government “to force companies to break encryption by inserting back doors into their products—something Apple will never do.”
For the record, Conservatives oppose the breaking of encryption. However, I'd like you to follow up on this comment by Apple that breaking encryption by inserting back doors into your products is something you would never do. Let's say that this legislation passes in its current form and the Liberals get their way. What happens then?
:
We are resuming the meeting. This is the third part. We are welcoming new witnesses, to whom we extend a warm welcome.
We welcome Mr. Mathias Van Laer from the Royal Canadian Mounted Police, who is here with us.
[English]
I invite everyone to be a bit more attentive.
[Translation]
From the Canadian Association of Chiefs of Police, we welcome Commissioner Thomas Carrique.
From the city of Brampton, we welcome Mr. Patrick Brown, mayor of Brampton.
I would like to welcome our witnesses.
We will now begin the five-minute presentations.
Mr. Van Laer, you have the floor.
:
Good afternoon, Mr. Chair and honourable members of the committee. Thank you for the invitation to appear today, as we gather on the traditional and unceded territory of the Anishinabe nation and recognize the continuing presence of first nations, Inuit and Métis people in this region.
My name is Mathias Van Laer. I served as a regular member of the RCMP for 25 years and, eventually, retired in 2022 as a staff sergeant.
[Translation]
I would also like to point out that I am of French-speaking origin. I will be happy to answer your questions in the official language of your choice.
[English]
During my service, I was a non-commissioned officer in charge of the RCMP E Division's integrated child exploitation unit, located in the Lower Mainland district but representing the whole province of British Columbia. Following my retirement in 2022, I returned to the RCMP as a reserve constable for the city of Kamloops, B.C., to continue my work within their sex crimes unit, where I actively work on ongoing investigations, prepare judicial authorizations and oversee the intake of all online child sexual abuse investigations within the city of Kamloops, providing guidance, direction and training.
To provide you with some background, the RCMP's child exploitation units are specialized teams dedicated to preventing, detecting and investigating crimes involving the sexual exploitation of children, both online and off-line. Their mandate focuses on protecting vulnerable victims, identifying and apprehending offenders, and working collaboratively with domestic and international partners to disrupt networks involving child abuse material and exploitation. Key priorities include proactive intelligence gathering, victim identification and support, digital forensic analysis and public awareness initiatives to reduce risk and increase reporting.
During my time with the B.C. ICE unit, I have worked to address the growing demand, driven by the increasing use of the Internet, for online child sexual exploitation investigations. In collaboration with the RCMP's digital forensic services, B.C. ICE supports law enforcement agencies across British Columbia, works to identify and assist child victims, and identifies offenders to support appropriate criminal charges.
As investigators, we are constantly adapting investigative techniques to try to keep up with criminals, especially those who operate in the digital space and who do the greatest harm to vulnerable Canadians, including children. Bill , an act respecting lawful access, would modernize our law so that Canadian police services can investigate crimes and target those who prey on the vulnerable.
RCMP child exploitation units increasingly rely on digital tools, data analysis and collaboration with intelligence partners to make progress in investigations. The Criminal Code amendments, proposed through Bill , could improve timeliness and consistency in obtaining digital evidence, particularly in urgent or rapidly evolving cases.
Child exploitation investigations predominantly depend on IP address tracing, subscriber information and preserving volatile online data before it is deleted or purged. Enhanced lawful access provisions could streamline production orders and preservation demands, allowing investigators to act more quickly to identify suspects and to safeguard victims.
Protecting children remains a core priority for the RCMP. Teams are committed to safeguarding vulnerable victims, pursuing offenders and adapting to evolving online threats through strong partnerships and modern investigative tools. Whether through enforcement, victim supports or prevention efforts, the RCMP continues to place the safety and well-being of children at the forefront of its mandate, recognizing the critical importance of protecting them from harm in all environments.
Thank you very much. I look forward to your questions.
:
Distinguished committee members, thank you for the opportunity to comment on Bill .
Today, virtually every serious criminal investigation has a digital component. Organized crime groups, child predators, fraudsters, violent offenders and extremists rely on encrypted communications, digital platforms, anonymized tools and forum-based services to coordinate criminal activity, evade detection, frustrate prosecution and ultimately victimize innocent Canadians. Criminals are leveraging digital infrastructure and encryption, while the police are hindered by outdated legislation that does not prioritize public safety.
Bill is not about expanding unchecked police powers. It's about ensuring that judicially authorized investigations can function effectively in a complex and ever-changing digital environment. To the benefit of bad actors, too often debates on lawful access focus exclusively on privacy interests of suspects and the financial interests of big tech, while overlooking the rights of victims to safety, justice and timely intervention.
The police are not asking for, nor does Bill authorize, broad surveillance. It does not permit warrantless interception of communication. It does not eliminate judicial oversight. It does not provide unrestricted access to browser history or to social media content. The legislation preserves charter protections and maintains judicial authorization requirements for advanced investigative techniques.
Bill also addresses practical investigative steps. For example, it creates confidential confirmation of the service process with a simple yes or no so that investigators can determine which telecommunication provider actually holds relevant records before spending valuable time seeking judicial authorizations for records that simply may not exist. It creates a production order process for basic subscriber information based on reasonable suspicion, allowing investigators to advance early-stage investigations. It also addresses delays involving foreign-held evidence for cases in which investigators currently rely on mutual legal assistance processes that take many months, often while evidence disappears. In fact, Bill provides clear statutory rules in areas where courts, providers and investigators currently face inconsistent interpretations and legal uncertainty.
Bill prevents the harbouring of criminals by setting out the requirement for electronic service providers to develop and maintain systems capable of providing police with communication and information that they are legally authorized to obtain and that they require to advance criminal investigations.
It's important to note that Bill is not a surveillance tool; it's a lawful access framework. Metadata would be retained for a maximum of one year, including information such as date, time, duration and origin of transmission. It's critical to note that there will be no obligation to retain content such as emails, web browsing history or social media activities.
Furthermore, retention does not equal access. Judicial authorization will still be required. Metadata is the bare minimum of information that could assist investigators in complex investigations, such as those for homicides, international child sexual exploitation, extortion, cross-border auto theft, human trafficking and the smuggling of drugs and firearms. These types of crimes can far exceed a one-year investigation period that can involve the need for lawful access.
Absent reasonable suspicion of criminal activity, police will not and cannot judicially seek and lawfully obtain communication metadata about a private citizen of Canada going about their daily activities. Additionally, there are other safeguards built into the bill. Regulations made by the Governor in Council must consider privacy and cybersecurity implications, feasibility, cost to providers and impacts to customers, and the intelligence commissioner must approve orders prior to their issuance on an electronic service provider.
Bill also prevents any requirement that would cause an electronic service provider to introduce a systemic vulnerability, defined in the bill as “a substantial risk that secure information could be accessed by a person who does not have any right or authority to do so.”
Frankly, from a law enforcement perspective, the concerns by some major telecommunication companies and special interest privacy advocates about encryption and cybersecurity are overstated. The legislation as written does not compel companies to weaken encryption or create vulnerabilities; rather, under a legislative framework, it ensures that electronic service providers are not serving as a safe haven for criminal and terrorist-related activity and compromising public safety locally, nationally and internationally.
:
I was going to celebrate my birthday, but when I heard you were talking about such an important topic, I did not want to miss this opportunity to speak on behalf of the residents of Brampton and the Peel region, where we have unfortunately faced significant criminal activity and where Bill could have made a world of difference.
I want to share a few things with the committee today.
Organized crime is sophisticated. I wear two hats, one as mayor of Brampton and one as a member of the Peel Police Service Board. Commissioner Carrique's comments, which were so eloquent, were what I hear from our senior police. This could be the most significant investigative tool for police since DNA evidence changed the game.
Organized crime does not want Canada to update our lawful access legislation. Frankly, they've been able to conduct criminal activity with impunity in our country. Police have their hands tied, and it's unfortunate. There are more victims and there are more preventable crimes. I'm sure that if this committee or the Parliament of Canada dithers or delays, the Bishnoi gang will be elated, the Sinaloa cartel will be elated and For Brothers will be elated, but there will be more victims.
I come from a community where I've seen too many cases of child exploitation, human trafficking and extortions. Don't even get me started on extortions, because they have terrorized our community. I can tell you that in Peel region over the last year, we've had 476 extortions on families and businesses. This legislation is absolutely critical for us to be able to hold these criminal organizations accountable.
In the case of extortions, production orders can take three, four or five weeks, and sometimes even longer. There are continuous delays. With these delays on production orders, investigations go cold.
Police investigations are most efficient when they have the tools to do their job, and I can tell you that organized crime is utilizing all of these modern technology tools. When investigators have to wait 45 days for critical information, video from local cameras disappears, critical evidence disappears and more innocent victims are traumatized.
I've had victims call me. I had a father call me who said, “My kids can't sleep after our house was shot up.” Can you imagine having your children not being able to sleep for months because they were terrorized by an extortion? These extortions could have been prevented if the police had the tools to do their job.
I know there were concerns from the opposition over the initial incarnation of this bill. However, I can tell you—and I know the Peel police have been involved in providing input—that this is a balanced approach that gives the police the same tools as other Five Eyes countries. I know there are going to be tech lobbyists aggressively lobbying against this bill for their own reasons, but if this works in other Five Eyes countries where there is a balance between protecting privacy and giving police the tools to do their jobs, we can find that balance in Canada.
I was at the big city mayors' caucus, where we lobbied specifically to give local police forces this tool that is so critical. For those who have privacy concerns, my message would be this: Don't commit a crime. Don't be involved in a heinous crime. Then you won't have your privacy abridged.
You hear law enforcement saying that it will be utilized only when there is reasonable suspicion of a crime. If we have video evidence of someone being involved in a crime, it shouldn't take 45 days to get that digital information.
This is the new warfare. I read these police reports and I study them. I can tell you that I have asked our senior leadership in the Peel Regional Police again and again how long this investigation would have taken if we had lawful access. Time and time again, they respond that it would be a fraction of the time. For investigations that have gone cold, this could have made a difference by actually preventing crime and preventing more victims, so I implore this committee to not dither and delay.
If there are reasonable adjustments and amendments, we have reasonable parliamentarians here. Please find that consensus, but do not dither and delay. The only people you will please with any dither and delay on this critical information that law enforcement is begging for are organized crime members.
I'm happy to be before this honourable committee today.
Happy birthday, Mayor. It's nice to make your acquaintance over Zoom.
It's nice to see you again, Commissioner Carrique. I've had the pleasure of meeting you many times.
It's nice to see you, Mr. Van Laer.
Mr. Van Laer and I worked together on investigations relating to child sexual abuse and exploitation material. One of the reasons that I invited him here and wanted to hear from him is that we haven't heard from anybody yet who has told us what it's like to kick down a door or what metadata you look for when you're doing child sexual abuse investigations.
Mr. Van Laer, I'm going to focus my questions on you for the time being.
This bill focuses on metadata. Are you familiar with metadata in the context of child sexual abuse material cases and Internet luring cases? I assume you're aware of metadata and how it all works.
First of all, metadata is quite broad, so there might be a need to make sure that we understand what exactly we are referring to when we say metadata. It's information captured by an electronic service provider insofar as every little bit of that information can be considered metadata.
Ultimately, the role of the police is not just to identify an Internet subscriber. An Internet subscriber is just the person who pays for the Internet connection. Our job, in order to satisfy prosecution, is to identify the person behind the keyboard. In order to do so, we need to dig into the content of what's happening on the Internet to identify the actual suspect user as opposed to simply a subscriber. The subscriber is a piece of the puzzle, and it leads our investigation into, hopefully, the user. We can't identify a user if we can't see their traces or identify them through some of their traces on the Internet, if that makes sense.
:
Currently, what we are required to do from there is to draft a production order to get the subscriber's name and address. That process takes man-hours. It takes time to draft the production order, but then, insofar as the result of the production order, it is left to the Internet service provider to give us that result. It can take up to 30 days, if not more sometimes.
That's not the end of the road, though, obviously. Once we have the IP address identified to a subscriber, we then have an address. Once we have the address, we start to do our investigation into that address and into the residents of that address. Then, more often than not, it will lead to a search warrant. We will need to satisfy the courts and provide reasonable, probable grounds to believe an offence was committed within that residence and evidence exists within it. We will then go through that door, get and seize those computers and electronic devices, and look for the traces that led us to that door in the first place.
You have to remember that we don't get an IP address out of the blue. It's been pre-identified for us. It's been given to us by an electronic service provider that is self-reporting online criminal activity. They see it as criminal activity, they report it and then it lands on our desk, unsolicited. We receive those reports, which are provided to us voluntarily by the electronic service provider.
Thank you to all of our witnesses for appearing before the committee today.
I would like to ask Mayor Brown my first set of questions. First and foremost, I would like to wish one of the best mayors that Brampton has had a very happy birthday.
Mayor Brown, you have been one of the most more vocal municipal leaders calling for stronger lawful access tools for police services, particularly as Brampton and Peel region confront rising levels of enabled crime, including extortion and organized criminal activity predominantly targeting the South Asian community and their businesses.
Last year, in December of 2025, Brampton city council adopted a motion approving a letter to the federal and provincial governments calling for, among other measures, federal action on digital evidence access, a dedicated extortion and organized crime task force, victim support and community outreach funding, and the establishment of a formal intelligence-sharing framework across federal, provincial and municipal law enforcement.
Can you speak to what the measures in Bill will mean at a community level to our constituents in the city of Brampton?
:
Thank you for that question, MP Sodhi.
What I've heard from law enforcement is that this is an incredibly important tool that will make a world of difference.
Yesterday, we had a major police announcement by Chief Nish. There were 17 individuals arrested for violent extortions. I was told that the investigation took very difficult police work. You had police members who put themselves in harm's way to hold these international criminals to account. They told me that the investigation literally could have been done in two or three months, not eight months, and that there was a litany of victims in that period, which this legislation could have prevented.
It's not just extortions, MP Sodhi. I can tell you about some of the worst crimes in the region. This is a tool that could have prevented them. Let me give you one example that was shared with me by the Peel Regional Police. We had two victims of a recent cybercrime—a cryptocurrency scam—and the two innocent victims were defrauded of $1.6 million. This is a case where the lawful access provisions would have allowed them to get those responsible and to have them charged before this crime was successful.
For human trafficking and child exploitation to extortions, this is a tool that I think our police desperately need. When you hear chiefs of police and police unions across the country pleading for this help and saying that this is a tool they need, I can't comprehend why there would be such hesitation behind this. I was told very clearly by our chief of police, in whom I have a great level of confidence—I think he's one of the best chiefs in the country, and he was actually chief of the chiefs at one point—that this is balanced. It's carved out to focus on those crimes where there's a reasonable suspicion of a crime. There's not an overextension of where it could be applicable. For those who are sharing privacy concerns, I think you do not need to worry about your privacy being infringed if you're not committing criminal activities.
I'd ask this question: How about the right to privacy of victims? How about the right to not get your house shot up? How about the right to not have your children terrified?
Amandeep, you represent the Brampton riding. I'm sure you've heard countless concerns as well. I get calls from the victims who say, “What are you going to do, Mr. Mayor, to stand up for us?”
One of the things we've been doing is pleading with the Government of Canada to deliver updated lawful access legislation. I'm grateful that the government has done so. I know that our hard-working police officers are grateful that this hope and this help are on the horizon. I really hope that we don't see delays in the passage of this legislation.
:
I believe there's a strong consensus.
With organized crime, if they see a loophole.... Right now, they view a loophole in Canada that other Five Eyes countries have closed. We don't have lawful access for police. This is going to replicate itself across the country. It will mushroom. It may have started out in Surrey and Brampton, but we've heard of cases in Calgary, Edmonton and Winnipeg. I've had colleagues, other mayors across the country, call me and say the same terrifying incidents I've told them about are now happening in their communities.
Other gangs and organized criminal syndicates will commit these extortions and heinous criminal activities if they can get away with them. The lawful access legislation is a clear tool to police to make sure that they don't get away with them. Don't give a gift to organized crime. Don't dither and delay. Right now, it may be in 10 or 15 Canadian cities, but it will be in 100 Canadian cities in no time if we do not act. We've been too slow as it is, and that's why the police have been so united, clear and eloquent on the need for this legislation.
:
I would like to thank the witnesses very much for coming here today to appear before us.
Mr. Commissioner, I don’t know if you were connected to the meeting earlier, but representatives from the Barreau du Québec came to express their disagreement regarding the use of “reasonable grounds to suspect” rather than “reasonable grounds to believe”—the higher threshold—when issuing an order.
According to the president of the Quebec bar, including “reasonable grounds to suspect” in the bill does not respect the spirit of the Supreme Court’s decision. However, the Department of Justice and its claim the opposite.
Can you explain to me what difference it makes for investigators to use “reasonable grounds to suspect” rather than “reasonable grounds to believe” when issuing an order?
:
I can give you a very specific example in response to this important question.
Let's take a case where we have a missing person. That investigation is proceeding, and it gets to the point that we believe there may be foul play and the missing person may have been subjected to a homicide. We have a number of phone calls coming in to that individual's phone. These are the last known phone calls. That would not give us reasonable grounds, under the current legislation, to seek a production order. However, it would give us reasonable suspicion. That production order would only provide us with subscriber information, not content.
I think it is a very important, progressive step in our legislation to allow us to deal with the challenges of legislation and the complexities of technology, and to service the victims of crime much more efficiently and effectively.
Thank you to the witnesses.
Mayor Brown, happy birthday.
Something you said really struck me. You said if people are concerned about their privacy, don't commit a crime. Their privacy won't be abridged. However, something we've learned with this legislation—we saw it with the Salt Typhoon hacks in the United States—is that if we create the ability for ministerial orders to infringe upon the integrity of encryption systems, we could be creating back doors that hackers could be using to go after the information of innocent, law-abiding Canadian people.
My question for you, Mayor Brown, is this: Would you still support this legislation if you knew we were creating a vulnerability that could result in your own personal information and your own private messages being hacked and used by extortionists?
Thank you, committee members, for giving me the time.
Thank you, Mayor Brown. Happy birthday to our hard-working mayor.
Mayor Brown, you have publicly stated that the police and border agents need stronger tools, and they need faster and more effective access to digital subscriber and transmission data to identify suspects before an attack occurs. We know you are a long-standing advocate for increased supports and digital screening tools for our law enforcement officers, and for the safety and security of Brampton. Our communities are terrified by extortions, and there are other crimes, too.
How do you think Bill , the lawful access for law enforcement legislation, can give modernized tools to law enforcement and police agencies and also build trust in the community?
:
The last part of that question, about trust, is so important. Right now, there is a sense of hopelessness because so many of these extortion investigations have gone cold. I hear again and again from law enforcement that if we had lawful access, they would be able to chase this one down, but it goes cold.
Let me give you an illustration of what I mean, MP Sidhu. If the Peel police observed a suspect.... This is from a senior officer who shared this with me about why he needs this legislation. He said if you were to observe a suspect, after a crime, speaking on a cellphone on the video camera, the police could write a production order for a cell tower site. Right now, that order would take upwards of three, four or five weeks, or maybe 45 days, and then all of the key evidence would be lost. Evidence would be lost. Video would be lost. More crimes would potentially be committed, and the criminals would evade justice.
To give another illustration, one of the investigations we had recently was successful because they had lawful access in the U.S. One of the criminals was operating out of the U.S. and they were able to nab him.
Canadian law enforcement shouldn't have to depend on other countries to do their job. They should have the same modern tools that other countries with similar charter protections and similar laws have. If other countries found that balance, I know Canada can. I believe this is a balanced approach that our hard-working police desperately need.
:
Thank you very much, Mr. Chair.
Commissioner, I would like to discuss the issue of retaining metadata for one year.
We have raised this issue with department officials. They set the retention period at one year in what appears to be a rather arbitrary manner. In Australia, it is two years. I have heard that in the United States, no specific period is set.
What does a one-year period mean to you, as an investigator?
We have received recommendations to set this at 90 days or three months, for example, and to make these periods renewable upon request, rather than retaining all Canadians' metadata for a year.
If we reduced this period, under certain conditions, and allowed you to request the data again, could you live with that? I don't really understand the importance of having a one-year retention period.
What is your perspective on this as a police officer and investigator?
Commissioner Carrique, you have spoken at length, and very passionately, about the necessity for this bill. As somebody who comes from a prosecutorial background, I understand that. I think one of the main things I'd like to ask you about...and Mayor Brown is free to weigh in on this as well. This is important legislation, but it's equally important that we get it right—for instance, on the “reasonable grounds to suspect” versus the “reasonable grounds to believe”. Would you support the fact that this is complicated stuff?
We can't even agree on a number, for instance, for retaining metadata. At some point, we have to delve into this and get it absolutely right. I don't think there's much room for error here. I feel that the process has been rushed on this. Mayor Brown used the word “dither”. In my life, I have looked at the ceiling at night in investigations where we could not put the person behind the computer. It sucks. At the same time, we as parliamentarians have to make sure we get it right.
What do the two of you say to that?
:
First, I want to thank the three witnesses.
They were very eloquent. I had several questions, and they answered them. However, I would like to return to one of those questions to clarify things.
There is a sense that we are rushing things and that everything is a bit improvised. I think you have all clearly demonstrated that the provisions of the bill are quite well thought out and that they address very specific needs.
People often try to give the impression that the government has embarked on a hunt for all kinds of information regarding metadata. However, I think it is important to clarify one thing. To my knowledge, the metadata covered by the bill is as follows:
[English]
Internet transmission data, tower signalling data, signalling data for VOIP calls and vehicle manufacturer telemetry data.
[Translation]
That is all there is to it. It is specific. I think that instead of arguing, we should acknowledge that Bill actually clarifies the scope of the data and prevents a witch hunt.
I would like to hear your opinion on this, Commissioner.
:
I am very pleased to hear that.
One of the witnesses from the Barreau du Québec even seemed to claim that with an IP address, one could access our dreams. That’s a bit of a stretch. It’s a bit of nonsense. The IP address remains basic information that will allow police, with a warrant, to go and get the information they need.
The other point we discussed is the famous three-month period, which might be insufficient. What I gathered from all three of your testimonies is that investigations often begin after crimes have already been committed, and we can’t know in advance what information we’ll need. So, we can’t say we’ll just keep a specific piece of information because that’s all we’ll need. That’s not how it works.
Mr. Van Laer, what are your thoughts on this?
:
Thank you for your question.
I agree with you.
To answer your first question, I’d like to comment on the IP address, if I may. You’re absolutely right: We don’t have access to everyone’s dreams through an IP address. So, I’m glad that this has been taken into account as a factor. It’s important that the people here, around the table, can develop laws based on real activities or processes—that is, things that are actually possible. It’s impossible for anyone to identify someone based on an IP address without going through a judicial process. So, that’s important.
To answer your second question, I would say yes.
I hope that answers your questions.
:
We are resuming the meeting.
I welcome the members back and greet all the witnesses.
We shall resume the meeting by welcoming our distinguished guests: the Canadian Telecommunications Association, represented by Mr. Eric Smith; the Ontario Child Sexual Exploitation Investigators Association, represented by Andrew Ullock and Lisa Henderson, both participating via video conference; the Peel Regional Police, represented by Mr. Nick Milinovich; and Murray Rankin, a highly esteemed colleague whom we have missed for a very long time and whom we are fortunate to see again today among us in person.
We will begin by hearing a five-minute statement from each person.
Mr. Smith, you have the floor.
:
Thank you, Chair and members of the committee, for the opportunity to appear before you today on behalf of the Canadian Telecommunications Association.
Our association is dedicated to building a better future for Canadians through connectivity. Our members include service providers, manufacturers and other organizations that invest in, build, maintain and operate Canada's world-class telecommunications networks.
Having listened to the discussions before this committee, I will say it is clear that there is broad agreement on two important principles. First, Canadians' privacy rights must be protected. Second, law enforcement and national security agencies must have the ability to access information through lawful processes to support legitimate investigations and protect public safety.
The central question, therefore, is not whether these objectives matter: It's how to appropriately balance them. That balance is critically important because Canadians use digital services every day with the expectation that their personal information will be handled securely and that any access to that information will occur within a clear, proportionate and accountable legal framework.
We appreciate the efforts of government in consulting with stakeholders and making Bill an improvement over the earlier proposals in Bill . To be clear, we are not against the bill. However, we have remaining concerns, which are set out in a written brief that has been provided to the committee. I'll touch on three of them.
One item that hasn't been mentioned before deals with part 1 and the requirement that confirmation of service demands must be responded to in as little as 24 hours. While most service providers have processes in place to deal with urgent requests from law enforcement, treating all confirmation of service demands with the same level of urgency and a 24-hour turnaround time is impractical and unrealistic.
The number of requests, the complexity of searches and the fact that not all service providers have staff available on a 24-7 basis make an across the board 24-hour response time near impossible to facilitate. A more workable response time would be no less than three business days, which would be suitable for most situations and would not prevent service providers from responding to truly urgent requests in a shorter period, as they do today.
The second concern is the requirement to retain broad categories of metadata for as long as one year. You've already heard from other witnesses about the privacy concerns this requirement raises. We are also concerned about the security risks as well as the lack of guardrails around the use of metadata. The metadata provisions of Bill should either be removed or substantially restricted, both in retention time and purpose.
Finally, there is the issue of reimbursement for the substantial cost of providing lawful access services. These are state-mandated tools and services created for the exclusive use of law enforcement and security agencies and are not part of normal commercial operations.
In a previous government consultation on lawful access, law enforcement agencies submitted that communication service providers “should be able to recover reasonable costs incurred in providing court-ordered assistance”.
Likewise, the lawful access advisory committee established by the RCMP and CSIS has as one of its key principles a commitment to a cost-neutral and fair compensation model. Again I will quote:
The lawful access community acknowledges that [communication service providers] are private or semi-private companies and deserve fair compensation for the effort required to develop, maintain, and operate capabilities that is not part of their normal business processes.
These economic realities are recognized in other jurisdictions, such as the U.K., which reimburses telecommunication providers for both capital and operational costs associated with the creation of intercepting capabilities and the production of communications data. This concept should be included in Bill .
Reimbursing service providers reflects the philosophy underpinning U.K. law that while private companies have a statutory duty to assist with the implementation of warrants, they should not be expected to act as an uncompensated arm of the state. Government funding also helps ensure market fairness and competitiveness, mitigates financial impacts on smaller businesses, provides oversight over the quality, standards and security of intercept capabilities, and prevents citizens from facing increased monthly bills to pay for law enforcement investigation infrastructure.
In closing, we understand the need to update Canada's lawful access framework. With targeted refinements, Bill can provide a framework that balances the interests of privacy and public safety, and that is proportionate, accountable and does not pass the costs to Canadian consumers.
Thank you. I'd be pleased to answer your questions.
Thank you for giving us the opportunity to share with you the perspective of the Ontario Child Sexual Exploitation Investigators Association, or OCSEIA, on Bill . OCSEIA is comprised of police officers, former Crown prosecutors and members of the private sector who work together to advocate for those who work to rescue children from online child sex offenders.
My name is Andrew Ullock, and I volunteer as the chairman of the board for OCSEIA. I am an officer with 28 years of experience, 14 of which was in the field of online child exploitation. I have worked both as an investigator and a supervisor of officers in this field.
Joining me is fellow OCSEIA board member, Lisa Henderson, who recently retired after working for over 30 years as a Crown prosecutor. Since the early 2000s until her retirement, Lisa worked both as the chair of the Attorney General's task force on Internet crimes against children and also as the provincial Crown coordinator for Ontario's provincial strategy to combat Internet crimes against children.
The law must create a proper balance between protecting privacy and protecting the public from crime. As technology continues to evolve, the challenge of striking this balance becomes more and more complex. One of the bedrock foundations of criminal law in Canada is that the burden of proof falls to the state, exercised through its agents in law enforcement. The state must establish beyond a reasonable doubt that an individual is guilty of a crime, an essential safeguard that cannot be compromised. That being the case, if law enforcement is tasked with the burden of meeting this necessarily high threshold, then the law should have within it reasonable tools that make it possible for the police to accomplish this objective.
Since the creation of the Internet, there has been very little change in statutory law to regulate the manner in which police obtain evidence of criminal offences, be it online or in computer data stored on devices. Without updates from Parliament, the courts are forced to adapt by filling the legal gap with a patchwork of decisions that can be confusing, inconsistent and redundant. This patchwork amounts to what OCSEIA calls legal inflation, where the number of steps and authorizations that police must go through to complete an investigation increases over time but never decreases.
Time is a finite resource for law enforcement. There are simply only so many hours a single officer can work in a given year. As the amount of time required to complete an investigation increases, the number of investigations that police can complete simultaneously decreases. The objective of privacy laws should not be to create redundant obstacles or barriers that are impossible for the police to overcome. Sensible limits on the investigative powers of police protect the privacy and dignity of citizens; insensible ones protect crime.
Bill has inspired a lot of discussion regarding the privacy rights of Canadians. OCSEIA agrees that this is an important debate and appreciates the contributions made by privacy advocates. However, on the topic of privacy, OCSEIA wants to ensure that the discussion is a complete one that considers all facets of this issue.
Behind each statistic or police report regarding online child exploitation is a real child who has suffered immense abuse at the hands of a predator. These children are equally entitled to have their privacy considered in this debate, since it is their privacy that is violated in perpetuity in the most horrendous way imaginable. Once an offender creates and then shares an exploitive image of a child, it becomes a permanent part of the Internet. From that point forward, that child's privacy rights get trampled upon each time a new offender consumes or shares that image.
The best way we as a society can respond to these violations of privacy is to find and hold accountable those who thrive on the abuse of children. To do that, law enforcement needs the right tools. OCSEIA believes that there are a lot of reasonable tools that can be brought about to accomplish this.
Law enforcement in Canada should not have to obtain a mutual legal assistance treaty order instead of a production order to obtain content data from online service providers who are physically present in Canada, just because they are international companies.
Law enforcement should not have to obtain a second redundant search warrant to analyze a computer device simply because it was seized from a person's hand or pocket during the execution of a residential search warrant that already authorized the seizure and analysis of any device found in that place.
Law enforcement should not have to obtain prior judicial authorization to seize an IP address that is being broadcast in plain view to millions of other users over a peer-to-peer file-sharing network.
Law enforcement should have the ability, through prior judicial authorization, to obtain Internet subscriber information for longer than 30 days after an offender has exploited a child, thereby allowing them to find that offender and, in some cases, rescue a child being abused.
To be reasonable, investigative authorities for law enforcement must not unreasonably intrude on the privacy of citizens. On that, we can all agree. However, they must also be capable of accomplishing their intended purpose. It is not reasonable to expect law enforcement to protect society from crime a quarter of the way through the 21st century using search and seizure laws drafted in the 19th and 20th centuries.
OCSEIA believes that our input and recommendations will go a long way in assisting Parliament to find the right balance.
We are happy to take any of the committee's questions.
:
Chair and members of the committee, thank you for allowing me the opportunity to speak about Bill , an act respecting lawful access. This discussion sits at the intersection of two priorities that Canadians care very deeply about—public safety and privacy interests. As police leaders, we support both.
Crime has evolved significantly over the last decade. Organized crime groups, extortionists, human traffickers, fraud networks and—as we just heard—child exploitation offenders operate primarily through digital platforms, whereas many investigative authorities were developed for a much different technological environment.
The objective of Bill , from our perspective, is not to weaken privacy protections or to expand unchecked government authority. It is to ensure that investigators can continue to lawfully obtain critical evidence in serious criminal investigations while remaining subject to judicial oversight, legal thresholds, accountability and charter protections.
Today, I would like to share the perspective from our front line, our investigators and our community, which has been affected deeply by crime. They have a vested interest in this topic. On their behalf, I urge the swift passage of Bill , the lawful access act.
Our current investigative laws were built for a pre-digital world. Today, criminals are actively taking advantage of that lag in high-growth regions and diverse regions like Mississauga and Brampton. We are seeing tech-facilitated crime move at an entirely unprecedented rate.
Our teams are hitting systemic and artificial walls. We are watching active threats disappear into digital shadows, simply because our legal framework forces us to investigate 2026 digital sophistication with outdated analog tools.
Yesterday, our service announced the outcomes of one of the largest extortion investigations in our community. It started with a threat that was delivered digitally from an encrypted platform in November 2025. If Bill had been in place at the time, it would have resulted in a more effective and efficient investigation and the closure of those extortion threats.
In Peel region—and in Canada—police are combatting a highly disruptive rise in extortion rackets, human trafficking, child exploitation and a variety of other transnational crimes. Almost every single one of these cases shares an identical pattern. It starts with digital communication, an encrypted message and an online profile or anonymous IP address, before escalating into real-world violence on our streets and impacts for our community.
Right now, when a digital tip comes in, identifying the telecommunications carrier or provider that hosts that suspicious account can take weeks of bureaucratic back-and- forth. By the time we navigate that maze, the trail can be cold, data is deleted and evidence is lost. The reality is that criminals are continuing their activities and continuing to prey upon our communities.
I believe that Bill introduces the necessary measures to radically shorten our investigative timelines. It allows us to narrow down suspects and stop a series of criminal activities before they turn violent. It will allow us to prevent victimization and crime in our communities.
As law enforcement professionals, we swear an oath to uphold the Canadian Charter of Rights and Freedoms. We do not want arbitrary surveillance capabilities in our community. Privacy and public safety must and can coexist, and I believe Bill strikes that balance.
As I mentioned, we recently arrested 17 people who were targeting our South Asian business community. This investigation, again, has taken seven months to date, and it is continuing. During that time, we believe that this group was responsible for firing over 320 rounds in our community. That's more than half of the rounds fired from illegal firearms in our community this year.
We are very pleased with the results, but as I mentioned, I believe it could have been quicker and more effective, and we could have prevented more victims of crime.
This is the case, again, for extortion investigations, but it's also been the case for homicides, national security investigations, human trafficking and, as we've heard, child exploitation, as well as a variety of other transnational crimes we are beginning to experience very locally in our communities.
Timely access to digital evidence has to be non-negotiable if we want to better locate victims and prevent community harm. I believe Bill provides the precise, transparent and judicially overseen tools we need to better do our jobs. We ask for your support to pass this vital legislation.
Thank you. I'd be happy to answer any questions.
Members of the committee, thank you very much for inviting me to appear today. I'm pleased to be here to discuss Bill .
This is an important, complex and sensitive piece of legislation. It touches on public safety, privacy, cybersecurity, the Canadian Charter of Rights and Freedoms, and the actual ability of police officers and members of the Canadian Security Intelligence Service to do their jobs in a digital world.
This debate is not merely technical; it's a societal debate. How do we protect Canadians from child sexual exploitation, fraud, extortion, terrorism and espionage, while safeguarding the fundamental rights that define our democracy? In my view, these objectives are not contradictory; they're complementary. Government access to information must be lawful, necessary, proportionate, clearly authorized and subject to effective accountability.
I served as the first chair of the National Security and Intelligence Review Agency, and that experience left a deep impression on me. It taught me two things. First, security and law enforcement agencies need modern tools. Second, these tools must be governed by clear legislation, an independent oversight body and Parliament.
[English]
That is why I strongly support the need for a lawful access bill. The digital world has changed the nature of investigations. Criminals, hostile states and sophisticated networks use technologies that simply didn't exist when many of our investigative tools were designed. Canada desperately needs a modern legal framework, but it must be a Canadian-made framework. It has to be compliant with our charter, privacy-protective, technologically realistic and subject to meaningful oversight.
I was pleased to assist in the consultation process following Bill . I met separately with stakeholders from law enforcement, national security, industry, civil society, academia and privacy communities. In my view, bringing them together in one room was a very positive experience. People disagreed, sometimes strongly, but the process was meaningful. I believe my report reflects the range of perspectives accurately.
I was also pleased that the vast majority of my recommendations found their way into Bill . The bill is now stand-alone. The information demand has been narrowed and reframed as a confirmation of service demand. The bill includes greater attention to oversight, transparency, cybersecurity and parliamentary review. That does not mean the bill is perfect. No bill ever is. The minister has said he is open to amendments, and I take that seriously. As a former member of Parliament, I have great respect for the work of parliamentary committees like this one. This is where legislation can be improved and made more durable.
In my respectful view, the task before you is not to choose between privacy and public safety; it's to insist on both. The bill should preserve operational effectiveness while protecting privacy, charter values and cybersecurity. It should protect privileged, medical and highly sensitive information. It should ensure that any new powers are used properly, by properly trained officials, and reviewed after a reasonable period.
I would particularly encourage this committee to focus on five issues: the clarity of the confirmation of service demand, the definition of systemic vulnerability, the role of the intelligence commissioner and NSIRA, transparency and annual reporting, and a mandatory parliamentary review after three years.
Finally, I believe the purpose of this legislation should be made plain. State access to information for investigative purposes must be lawful, necessary, proportionate and subject to effective authorization and accountability, consistent with the charter and Canada's privacy laws.
Thank you again for inviting me, Mr. Chairman. I look forward to your questions.
Thank you all for being here.
I would be remiss to not mention again that I feel like I'm drinking from a fire hose, as the phrase goes. There's so much information here. There are five different people. I would love to spend all of my time delving into each one of their opening testimonies, but frankly, we don't have the time to do that, which is unfortunate.
I know that you all appreciate the role of members of the opposition, specifically you, Mr. Rankin. I appreciate your being here. You were an opposition MP for a number of years, so you understand that sometimes in opposition it looks like you're just opposing when that's not the case. Those of us who are looking very closely at this want to get this right. I'm nervous that the role of MPs in opposition is being negated a little bit when we rush through legislation. Words like “dither” were used earlier, which I didn't appreciate, simply because we want to look at this in depth. It deserves to be done right.
In 2012, a Conservative government tried to do this and ended up having to back off because the Liberal public safety critic at the time had a real problem with it. This bill actually takes things a little further.
I got into a bit of a preamble, but there's so much I really want to dig into. I know I can ask you all privately, but that wouldn't allow Canadians and Quebecers to hear what they need to hear openly and in public.
Mr. Rankin, you mentioned the process you went through and the round tables. I'm really happy to see you here. I'm happy we did get a version of the report. It might have been redacted somewhat, but at least it's something. This was something I asked for, so I'm very happy to see it here.
How long was the process that you spent on this? If you were to put it in hours, would you be able to give that number, approximately?
:
I'm happy to have some of that conversation, but we would have to be here much longer than six minutes in order for me to do that.
The reality is that if we look at the legislation surrounding lawful access, the last time there was a substantial update was prior to the development of Google. If you imagine us operating right now, very simply put, we are delayed in our ability to secure information. We are not as effective as we could be, and we are certainly not as effective as some of the other Five Eyes countries are. We are hamstrung by outdated legislation, and it needs to evolve.
It is virtually the foundation of every complex investigation we complete. Normally, it begins with a production order and may result in a number of other different judicial authorizations, but we're receiving them slower than we should and not with the level of detail that we should have in order to accomplish the roles we've been provided. It's a difficult spot to be in.
I'll give you an example. If we were to watch an extortion happen in Peel, and the investigators go out, do their investigation and identify a corner store that captured that extortion on video, with the person speaking on a cellular telephone, we may write a production order for that tower site. The results of that production order, in some jurisdictions, could take up to 30, 45 or 50 days. In that time, we've lost evidence. We've lost the opportunity to prevent additional crimes. It doesn't happen all the time, but that's one of the big issues that we are dealing with.
There's an opportunity to be more effective and more efficient in our investigations through enhancements to the legislation surrounding lawful access.
:
That's a great question.
I tend to agree with Mr. Rankin. There has to be a timeline. We need to require people to keep that metadata to a certain level, because it's not as though a crime happens and we immediately arrive at the opportunity to collect this stuff. Crimes, and particularly more serious ones, don't have a statute of limitations. We're not talking about theft from a grocery store. We're talking about child exploitation or transnational crime, and that information can become incredibly valuable to the investigative community and policing.
Of course, I understand people's concerns about it in terms of a private citizen who commits no crimes. I understand that, but the reality is that nobody is going to look at their metadata, because they aren't doing anything wrong from the policing perspective. When you're a criminal and you're targeting our communities, it's the longer the better for us.
:
Thank you very much, Mr. Chair.
First, Mr. Rankin, I want to thank you for speaking French, because I don't know whether my anglophone colleagues would have tolerated that 80% of the testimony not be in their official language. It's very difficult to concentrate and understand everything when listening to interpretation. So thank you very much. It was a long statement, so I wanted to thank you.
My question is for you, Mr. Smith. The Canadian Chamber of Commerce noted that Bill raises concerns and creates unpredictability because it's unclear who will be covered, due to the lack of definitions, which will be specified by regulation.
You seem to share this concern. Do you think some sectors or suppliers should be excluded? I'll give you the examples of Interac or Desjardins, whose representatives told us they should be excluded. Do you think we should specify in advance which sectors are excluded from the definition of primary suppliers, while still leaving the government some regulatory leeway, even as we try to narrow the range of primary suppliers?
Do you think specifying primary suppliers or setting out exclusions, for example, could be a reasonable solution?
:
Mr. Rankin, you've led the consultations. If I recall correctly, you told us from the outset that you had the privilege, I think it's fair to say, of being the first chair of the National Security and Intelligence Review Agency.
Personally, I think the agency is a great idea. It's great to have it, and I believe in the work it does. The government has decided to make drastic cuts to the agency. It has clipped its wings by reducing its ability to investigate and lead more extensive investigations. The agency's budget was cut by 15%, or $2.5 million out of a $17 million budget. That's a pretty significant cut.
You chose not to invite Justice Deschamps, the current chair of the agency, to the round table. She told us she hadn't been invited to appear. I must tell you that this came as quite a surprise.
When she appeared before the committee, she recommended that amendments be made to the bill. At the Bloc Québécois, we will be presenting and supporting these amendments. I think the government is well aware of our position on this issue. Justice Deschamps told us that it would be important for her and for the agency, and especially to reassure Canadians, that the agency be notified in real time, as is the case for the intelligence commissioner. This would allow the agency to document decisions rather than having to rely on a retrospective investigation. We estimate that the agency would be informed about a year and a half after the interventions. I find these amendments very reasonable, especially since they wouldn't cause any delays, because she doesn't have access to the decisions.
During his appearance, the minister told us that granting this authority would slow down the process. The intelligence commissioner, former Justice Noël, told us that he did not share that view, that there would be no delays and that, in his view, it was entirely normal for her to be notified in real time.
What is your opinion on the matter, Mr. Rankin?
:
First, I'd like to thank you for your comments about my French. I really appreciate that, but if I may, I'll answer your question in English. I spent many years in British Columbia, and my French is a bit rusty.
[English]
I'm going to try to answer your excellent question in English.
Madam Justice Deschamps is somebody who succeeded me and is doing an excellent job at NSIRA. I am aware of the budget cuts, and I share your deep concern about them.
On the issue of the role for NSIRA, however, I point out that it is a body that does after-the-fact reviews. It has no current mandate, as contemplated in Bill , for an oversight role. However, the intelligence commissioner has that role of reviewing ministerial orders. The commissioner already has an oversight role.
I don't think NSIRA, in my judgment, is set up for that kind of role. What I do think would be helpful is if NSICOP and NSIRA were asked to review later—not on a case-by-case basis, as I think you're contemplating, but overall—how the system is working. I think that would be very valuable.
:
Thank you very much, Mr. Chair.
I want to thank all of the witnesses.
Deputy Chief Milinovich, I took heed of what you said. My colleague Ms. Acan asked you a question and you said that it was going to take a lot longer than six minutes, and I understand why. This isn't easy stuff.
This is complex stuff: how metadata leads to an offender, how a production order is authorized.... I mean, we haven't even gotten into that. I don't think that even once we've talked about the test for getting a production order. I think Mr. Van Laer did very briefly last time, but we haven't even talked about that here. That's part of the point I've been making. I know that my Liberal colleagues may think I'm a broken record, but the reality is that this is not easy stuff. This is where we have had lawyers come in here and disagree: knowledgeable lawyers, people who have practised law for a great deal of time.
I would love to hear more from you. I know that extortion is a huge issue in your area. You and I spoke—I believe it was just last month—and I really appreciate your passion for trying to bring safe streets to the Peel region. I echo that.
The thing that stands out for me—and this goes for all of our witnesses here—is that we all want safe streets. We all want to put bad people in jail. We all want people who hurt kids to go to jail and—I can say on this end—for a very long time. I would hope that my Liberal colleagues would join that, yet here we are, on the precipice of having to deal with a bill that has huge ramifications and huge implications.
I'm going to ask you just one brief question, Mr. Rankin. Was there one recommendation that you really hoped would have made it in here and didn't?
Here is the reality, Mr. Chair. My friend and colleague Mr. Powlowski, when he was asking questions, talked about how he was still figuring this out. We are all still figuring this out. That's why I referenced Deputy Chief Milinovich's comment on how much time we have.
One theme that I've been stating throughout, and that I've been stating publicly and privately, is that we need more time with this bill. Yes, we've had three meetings. That's not nearly enough. These have been exhausting meetings. They've been going on for four hours. We're into the fourth hour, and we don't know basic things, such as how long metadata should be retained. I don't think we've actually gotten into the technical nature of how metadata leads to an arrest, which leads to a charge, which leads to a conviction. We haven't even touched on that. We have not touched on what the U.K. does, what Australia does, what the EU does or what Sweden does. We've heard it's 10 months, one year or two years. We have not gotten into that.
Speaking as somebody who wants to see bad people put behind bars, I know that we have to balance it with getting it right, period. I don't think anybody around this table wants to have legislation that will not stand up constitutionally. For that reason, I will be moving a motion. The clerk has received copies in both English and French, I believe.
This should not come as a surprise to any of my colleagues. I think we as Conservatives have been very transparent on this. We have been transparent on the necessity for more meetings.
Mr. Chair, as it stands right now—as it stands right now—we are going to hear from witnesses on Thursday, yet amendments are due tomorrow. We will actually be hearing from officials when the deadline for amendments has passed.
I checked with Mr. Rankin. I think we should have an hour or two with just him. It's been a major failing of this meeting, alone, that we crammed in 12 excellent witnesses who could probably have had an hour on their own—each one. We crammed them in, sometimes getting only two rounds.
With that in mind, I am putting forward this motion:
That, in relation to the ongoing study of Bill C-22, an Act respecting lawful access,
a) the study be extended to accommodate further examination of Part 2 of the bill which would enact the Supporting Authorized Access to Information Act, provided that the following witnesses appear separately, for at least one hour each:
1. the Minister of Industry, in relation to the impact on electronic service providers and their industry,
2. the Minister responsible for Canada-US Trade, in relation to trade and security implications raised by American lawmakers,
3. the Secretary of State (Combatting Crime);
b) the committee receive an additional 8 hours of witness testimony, provided that the committee prioritize another briefing with departmental officials and hearing the testimony of representatives from Signal, NordVPN, OpenMedia, Centre for Free Expression, Canadian Constitution Foundation, Canadian Muslim Public Affairs Council, Migrant Workers Alliance for Change, and the testimony of Glenn Greenwald, Safiyya Ahmad, Noura Aljizawi, Teresa Scassa, and Jane Bailey, in addition to additional testimony deemed relevant by the committee;
c) the chair be authorized to seek additional meeting time to accommodate this testimony in a timely manner;
d) the deadline for submitting amendments be extended until the testimony outlined in this motion has been received;
e) the chair only be authorized to schedule a meeting for the purposes of clause-by-clause consideration of the bill after the witnesses listed in part a) have appeared, and the number of hours of testimony in part b) have been received.
Mr. Chair, we owe it to the people who have appeared and who have told us of the necessity for this bill, we owe it to the victims and we owe it to Canadians to get this right and to get this right the first time. That is why I'm moving this motion.
I implore my colleagues to accept this motion. Let's get this bill done. Let's explore it, and let's get it done right.
Thank you.
Witnesses, this concludes your appearance. We won't keep you any longer. Given that the motion has been moved, we'll certainly spend the next few minutes discussing it. Therefore, we won't deprive you of the pleasure of returning home or wherever you'd like to go.
[English]
I'm happy to say that your day is over. Ours is not yet over, because we'll have to discuss that motion. We are obviously very grateful for your participation, either virtually or in person. Your views have been quite clearly heard, but not completely so. We look forward to more possible engagement with you in the future.
Have a great night. We won't suspend and shake hands, but you understand why we'll now focus on our own internal work. Thank you.
[Translation]
Ms. Kirkland, the floor is yours.
:
Chair, I'm really concerned that we are just not spending the time necessary to get this right. When I first spoke to departmental officials, before we even started studying this bill here in committee, I assured them that we want, for those who are committing the most heinous crimes, the best possible lawful access regime that could potentially do the job that it's supposed to do, but what we don't want is to have one thing at the sacrifice of another.
As an example, we had today, in our committee time, four hours. One hour only had two rounds. There were issues of privilege, and these were brought up simply because we don't have time. We're not getting the information that we need in a timely manner, and that's not anyone's fault. It's the clock's fault.
The only fault that we can place on this is the fact that the government, to be fair, has decided that it wants to ram this legislation through and race to royal assent, as I have said several times. This is not doing the justice that this type of legislation deserves. Canadians deserve to hear everything. I said before that I could ask these witnesses the questions that I have privately, but that is not appropriate for all Canadians. They want to know the answers to these questions.
I'm specifically shocked and annoyed by words that were used by the mayor of Brampton. Although I respect him greatly, it's not dithering to properly look at legislation and take it apart piece by piece. That is our job. If we're not going to do our job, then what are we here for? Is it the job of the opposition, as well, to just sit back and say, “Yes, yes, yes”, and be yes-people?
It's just outrageous to me that we've spent such little time. Asking for eight more hours seems very congenial. It should be easy to do. If we do four-hour meetings again, that's two more four-hour meetings.
I know we're tired, but this is our job. If we don't get this right, then we could be causing lots of problems going forward, and I fear that we already are. We've seen news reports. Anyone who has reached out to my office has said, “Yes, we understand the need for lawful access, but my concerns are regarding my privacy and my safety.”
I implore everyone on this committee to take this motion seriously. It is made in good faith. I want to do my job, and I want to do my job effectively. I hope that everyone on this committee wants to do their job effectively to properly scrutinize this bill and to get it right. That's truly all we're asking for.
With that, I will leave it. The only possible thing I would like to mention is the idea of amendments being due before we finish hearing testimony. I don't understand that at all, and I don't think it's just because I'm a one-year, new parliamentarian.
:
Thank you very much, Mr. Chair.
I thank Mr. Ramsay for the motion, although I think our motion is far superior.
Somebody is going to have to explain some logic to me here. Maybe I missed the boat. When I first raised the issue about officials, I did that in what I believe was good faith. It came about through a private conversation where I said that there are some issues here.
We heard from officials for one hour on this bill. When we heard from officials in the one hour, we had very few answers to the technical aspects of the bill. I will reiterate: What we have heard so far on this bill doesn't relate to the technical aspects. It relates to the philosophical aspects. Ninety per cent of what we've heard relates to the philosophical aspects. Even when we hear from police officials, they say that they really need this because it will help them track down people who do bad things. Well, okay, but we haven't really gotten into the mechanics of it, if we're being honest. We haven't gotten into the mechanics of it as far as how that happens.
I challenged Professor Geist on this. I don't know if anybody remembers. He was here and I asked him about metadata. I asked him what he thought. He said that a year is far too long. He said, “30 days”. I asked him what he'd say to the fact that there might not even be an investigator after 30 days. Mr. Van Laer talked about that. Sometimes you have to get a production order. Sometimes you don't know these things. He said that whatever you do, it has to be evidence-based. That was his response.
Can we say that so far we have figured out what that number should be? We've heard about stuff that's happening elsewhere in the world—in Sweden, it's apparently 10 months, and in Australia, it's apparently two years—and things like that. That is the very reason I think the officials are so vital. We have not gotten into the technical aspects of this, so when we are talking about this, I still think we need to hear from officials a whole lot more.
I'm just going to look at this motion here. The amendment deadline goes to 5:30 on Monday. Yes, we hear from witnesses on Thursday the 28th, but we run into the exact same problem: We have amendments due on Monday, we have officials on Tuesday and then we go to clause-by-clause on Thursday. Why are we hearing from officials after amendments are due?
I'm saying this rhetorically. I'm not expecting an answer. I think I would get no answer anyway.
Mr. Powlowski looks like he's chomping at the bit to give me an answer. He's just mastered this bill in the last 45 minutes or something like that.
I don't mean to make light of this. I take him at his word when he says, “We don't really get this.”
Okay, Ms. Acan really gets the bill.
:
I am still processing what is in this bill. As a result, in order to fulfill our obligation as His Majesty's loyal opposition, we should have the right to hear from officials fulsomely before we have to submit amendments. Otherwise, we are essentially going to a glorified clause-by-clause because, in that case, we're going to hear from officials after amendments are in, which we would normally do in a clause-by-clause setting anyway. We're almost postponing the unavoidable. We're not really following a proper process in that.
I reiterate that there has been substantial questioning on this bill, and dare I say, from some people, substantial opposition. We heard today that a lot of people are really in favour of this bill. We have a group that is quite in favour of the bill. We have a group that is quite opposed to the bill. Our job is to try to find some middle ground that puts bad people behind bars and ensures that privacy and charter rights are protected. I think everybody around this table would want to see that. How do we do that when we have amendments that are due before we hear from officials? To me, it is eminently reasonable that we would hear from officials before amendments. I don't understand why we wouldn't do it.
For instance, let's look at part 1, “reasonable grounds to suspect” versus “reasonable grounds to believe”. We heard about the lower threshold from Commissioner Carrique. The only time we actually talked about reasonable grounds to suspect versus reasonable grounds to believe was when I asked the question.
My recollection of reasonable grounds to believe is that a peace officer personally or subjectively believes that an offence has been committed—not suspects—and that the belief is objectively reasonable. That is reasonable grounds to believe, or it was five years ago when I was still practising law.
:
That's a point of order, which is disguised as a point of information.
I'm not a lawyer, so you would be better than me at describing it, but that's a very fair statement because I was going to make that statement.
We have three minutes before we need to adjourn this meeting.
As MP Housefather has said, if we don't vote on that motion, we have the existing motion, which prevails. That means we're going into clause-by-clause work next Tuesday, June 2, and the deadline for amendments is tomorrow. I'll let you know that because we have a default motion, default agenda, which we have voted on. We have an opportunity now to vote on a different agenda. We need to do this in the next two minutes, now.
Are we ready to vote on that?
:
Yes, I want to ask a question, but I also don't want to cede the floor to ask the question. That's what I'm concerned about.
I don't understand at all how this is a solution. I know that Mr. Ramsay said, “Oh, I have a solution: Let's adjourn debate on your motion and let me introduce this beautiful motion, which is the solution to all of our concerns.”
The solution seems to be to leave in place the same scenario, where amendments are due before we have heard from department officials again, and to add an extra two hours for witnesses. Quite frankly, we had 18 witnesses here today. I know that Mr. Caputo said we had 12. We had 18 witnesses here today: 18 people and maybe 12 or 13 organizations. We didn't get to ask them questions.
My concern with this is that we had no time. We don't have any time. This government is just frankly abusing its power, in my opinion, by ramming through legislation without giving the opposition a chance to properly question witnesses so that we can pass a bill that is done right. We want a bill that is done right. We want it.
I'm a little bit blown away. In fact, I'm a lot blown away that we don't want to do our jobs, that we want to limit the amount of time that we're studying this bill and that we just want to go, go, go, to the detriment of Canadians and their privacy and their rights. Quite frankly, I'm baffled that everyone at this table is okay with that. I really am. I don't really understand it at all.
When I first started hearing about this bill and looking at it—