Showing posts with label lawful access. Show all posts
Showing posts with label lawful access. Show all posts

Monday, August 24, 2026

Privacy, Online Harms and Lawful Access: Keep an eye on Parliament this fall

If you care about privacy, the internet, artificial intelligence, social media, free expression, cybersecurity or government surveillance, you probably want to keep an eye on Ottawa this fall.

Because Parliament comes back from its summer break on September 21st, and waiting for MPs and Senators are three important pieces of legislation.

We have Bill C-34, the Safe Social Media Act, which would create an entirely new regulatory regime for social media, online harms and AI chatbots. Including a social media ban for anyone under 16.

We have Bill C-36, the Protecting Privacy and Consumer Data Act, which would repeal and replace the privacy portions of PIPEDA — Canada's private-sector privacy law for the last quarter-century.

And then we have Bill C-22, the Lawful Access Act, 2026, which has already made it through the House of Commons and is now sitting in the Senate.

Each one of these bills would be important on its own.

Taken together, this could be one of the most consequential sessions of Parliament for Canadian privacy and digital policy that we've seen in years.

Hi. My name is David Fraser. I'm a privacy, internet and technology lawyer with the Canadian law firm McInnes Cooper. I also teach Internet and Media Law at the Schulich School of Law at Dalhousie University.

I've already done detailed episodes on each of these bills, so I'm not going to go through every clause again. I’ll link to the previous episodes below.

Instead, I want to talk about where these bills stand, what they would actually do, and — most importantly — what we should be watching when Parliament gets back to work this fall.

Part 1: Three Different Bills — One Enormous Digital Policy Agenda

I think it's useful to start by looking at these three bills together.

Because they deal with different things, but they really are pieces of the same larger picture. And I think a fourth piece is coming.

Bill C-34 is about what online platforms are required to do.

Bill C-36 is about what organizations can do with our personal information and how they are regulated.

And Bill C-22 is about how law enforcement and national security agencies can obtain information and what technological capabilities companies may be required to build to facilitate that access.

So we are talking about regulation of platforms. Regulation of data. And government access to data.

That is a pretty significant chunk of Canada's digital policy landscape.

And there is another important connection between C-34 and C-36.

Bill C-34 creates a new Digital Safety Commission of Canada. Bill C-36 would expand and restructure that institution into a Digital Safety and Data Protection Commission of Canada, which would also become central to the enforcement of Canada's new private-sector privacy law.

In other words, we aren't just talking about three new statutes.

We may be watching the construction of an entirely new federal digital regulatory architecture.

And I fully expect we will have a bill to regulate artificial intelligence, and I bet the Digital Safety and Data Protection Commission will also have oversight of AI.

That deserves attention.

Part 2: Bill C-34 — The Safe Social Media Act

Let's start with Bill C-34.

The government introduced the Safe Social Media Act on June 10th, just before Parliament rose for the summer. It received first reading and is now sitting at second reading in the House of Commons.

This is essentially the government's replacement for Bill C-63, the Online Harms Act, which died when Parliament was prorogued before the last election.

But C-34 isn't simply C-63 with a new name.

There are some pretty significant changes.

The legislation would regulate three broad categories of services: social media services, AI chatbot services and potentially other highly interactive online services that the government considers sufficiently risky to children. Exactly which services are caught will depend enormously on regulations that have not yet been written.

Perhaps the most significant addition between C-63 and Bill C-34 is a social media ban for those under 16. Bill C-34 says that users have to be at least 16 years old to have an account on a regulated social media service unless the service obtains an exemption from the new Commission. And the ban will surely go into effect before the Commission has established criteria for exemptions.

It also requires age-assurance measures for services carrying pornographic content.

And that creates a glaring privacy problem.

To keep people under 16 off social media, social media companies have to figure out who is under 16.

Which means they have to determine the age of everybody.

So legislation promoted as a child-safety measure could result in an enormous new infrastructure for age verification or age estimation across the Canadian internet.

That is going to raise some very difficult questions.

What information are companies going to collect to establish age?

Do you have to upload government identification?

Can platforms use facial age-estimation technology?

Can third-party identity providers do this?

What data gets retained?

And perhaps most fundamentally: how much additional information should adults have to provide about themselves just to use an online service?

There are also very significant freedom-of-expression questions.

Despite some people comparing “Big Tech” with “Big Tobacco”, social media is not cigarettes or booze or gambling.

Social media is fundamentally a medium of expression.

Young people use it to communicate with friends, participate in political discussions, organize, create art, learn about the world and express themselves.

So an outright age restriction raises Charter questions that I expect will receive considerable attention if this bill gets to committee.

Bill C-34 also creates four broad categories of duties for regulated operators: duties to protect children, to be transparent, to act responsibly, and to make certain content inaccessible.

The legislation continues to regulate seven categories of harmful content, ranging from intimate content communicated without consent and content that victimizes children through to bullying, hatred, violence and violent extremism.

And AI is explicitly part of this.

Regulated chatbot services would have obligations designed to prevent them from impersonating human beings or professionals and from encouraging unhealthy emotional relationships with users.

Synthetic audio and visual content would also have to be identified in certain circumstances.

So this isn't just a social-media law. It will affect a LOT of the internet.

It's also one of Canada's first significant attempts to directly regulate consumer-facing generative AI.

And then there is the regulator itself.

The new Digital Safety Commission would have significant investigation, rule-making and enforcement powers, backed by potentially enormous administrative monetary penalties — up to the greater of $20 million or five percent of global gross revenue in some circumstances.

A HUGE amount of the actual operation of this legislation is also left to future regulations and rules made by the Commission. And, as a result, so much will be determined by who is appointed to the Commission.

So when C-34 gets to committee, I would expect a lot of attention to be focused not just on what the bill says, but on how much Parliament is being asked to leave for somebody else to decide later.

Part 3: What to Watch on C-34 This Fall

There are four things I'll particularly be watching.

First, the 16-year-old social media restrictionDoes it survive in its current form? And if it does, what safeguards are added around age verification?

Second, freedom of expressionDoes Parliament seriously grapple with the Charter implications of excluding younger Canadians from major platforms for communication and expression? It will be interesting to see how the government tries to stickhandle this in their Charter Statement for Bill C-34.

Third, the scope of the legislationHow far beyond Facebook, Instagram and TikTok does this go? Gaming? YouTube? Online communities? AI services?

The more services that can potentially be brought in by regulation, the more important that question becomes. 

And fourth, the power of the regulatorParliament should be very careful whenever it creates a powerful new administrative agency and says, essentially, "We'll work out a lot of the important details later."

My expectation is that C-34 will be a significant government priority this fall.

Online safety — particularly child safety — has enormous political appeal. But that does not mean the details don't matter. In fact, it means the details matter even more. If they're going to be so ambitious, they need to really try to get it right.

Part 4: Bill C-36 — Replacing PIPEDA

Then we have Bill C-36.

This one was introduced on June 15th — only a few days before the House packed up for the summer — and it is also waiting at second reading.

If C-34 is politically flashy, C-36 may actually have the broader long-term effect.

Because Bill C-36 would repeal Part 1 of PIPEDA.

PIPEDA has been Canada's federal private-sector privacy law since 2001.

For twenty-five years, it has governed how businesses collect, use and disclose personal information.

Bill C-36 would replace that regime with a completely new statute called the Protecting Privacy and Consumer Data Act, or PPCDA.

We've been here before.

Bill C-11 tried to replace PIPEDA in 2020. It didn’t proceed. Bill C-27 tried again in 2022. It didn’t proceed. So Bill C-36 is kick number three at this particular can. 

Much of the substance will be familiar to anyone who followed Bill C-27.

  • There are more detailed accountability requirements.
  • Documented privacy management programs.
  • More detailed consent rules.
  • New consent exceptions based on business activities and legitimate interests.
  • Formal rules dealing with anonymized and de-identified information.
  • A right to disposal of personal information.
  • Data mobility.
  • Privacy impact assessments for international transfers.
  • Much stronger enforcement.
  • And enormous potential penalties.

Administrative monetary penalties can reach the greater of $10 million or three percent of global gross revenue.

And serious offences can attract fines of up to the greater of $25 million or five percent of global gross revenue.

That should get the attention of corporate boards.

But perhaps the most interesting change is institutional.

For almost twenty-five years, federal private-sector privacy law has been overseen by the Privacy Commissioner of Canada — an independent officer of Parliament.

Bill C-36 would fundamentally change that.

The existing Privacy Commissioner would no longer be the regulator administering this law.

Instead, we would get a new Privacy and Consumer Data Commissioner operating inside this broader Digital Safety and Data Protection Commission. That Commission would also function as a tribunal when organizations challenge findings and penalties. And I think that is going to be one of the most important issues Parliament has to examine.

Why are we moving privacy regulation away from an independent officer of Parliament? What problem is that intended to solve?

How independent will the new Privacy and Consumer Data Commissioner actually be?

And have sufficient institutional walls been built between the investigative side and the tribunal side?

I don't particularly like the idea of having the investigator, prosecutor and adjudicator all living under one institutional roof.

Maybe that structure can work. But if that's what Parliament wants to create, the firewalls need to be very clear and I don’t see them in the text of the Bill.

Part 5: The Other Big C-36 Issues

There are a bunch of substantive issues I expect will get attention at committee. Consent is one. Bill C-36 requires organizations to provide considerably more information for consent to be valid.

At the same time, it introduces broader alternatives to consent through legitimate interests and specified business activities. So Parliament is simultaneously making consent more demanding and creating more circumstances in which organizations don't need it.

That tension deserves some careful thought. It works in Europe, but we’re not doing exactly what they’ve done in Europe. 

International transfers are another. Organizations transferring personal information outside Canada would have to undertake privacy impact assessments. That's a significant departure from the relatively technology-neutral accountability model we've had under PIPEDA.

And then there is the private right of action. Bill C-36 would allow an individual affected by a contravention to sue for loss or injury arising from it, including in provincial superior courts. I think that provision needs considerable work. Depending on how it is interpreted, a privacy contravention involving millions of individuals could produce an enormous multiplicity of proceedings.

There is also a bigger policy question. What do we actually want Canadian privacy law to accomplish in 2026 and beyond? We're now writing the law that could govern data processing for another generation. This is not the place for Parliament to rush. Bill C-36 isn't a tune-up. It is a wholesale replacement of Canada's federal private-sector privacy regime.

Part 6: Bill C-22 — Lawful Access Goes to the Senate

And then we come to Bill C-22. This one is at a completely different stage. Unlike C-34 and C-36, Bill C-22 made it through the House before the summer break. On June 18th, the House passed Bill C-22 at third reading, and the Senate gave it first reading that same day. So when Parliament returns, the lawful-access debate moves principally to the Senate.

If you've watched my previous episode, you know I have some pretty significant concerns about this bill. 

Bill C-22 has two major substantive pieces. Part 1 creates new and modified investigative tools.

There is a new confirmation-of-service demand, allowing police and CSIS in specified circumstances to require telecommunications service providers to confirm whether they provide services associated with a person or identifier.

There is a new subscriber-information production order operating on the relatively low threshold of reasonable grounds to suspect.

There are changes dealing with voluntary disclosure, publicly available information, tracking orders, transmission data and other investigative powers.

This part is considerably better than what the government originally proposed in Bill C-2, the Strong Borders Act, but I still have issues with Part 1.

Part 2 is where I remain much more concerned. It creates the Supporting Authorized Access to Information ActThat law would create a framework under which electronic service providers can be required to build and maintain technical capabilities to facilitate authorized government access to information.

And "electronic service provider" is defined VERY broadly.

We're not just talking about Bell, Rogers and Telus. We're likely talking about cloud providers, social media services, online gaming companies, messaging services, VPNs and other digital businesses.

The legislation allows obligations to be placed on designated core providers through regulations.

It also gives the Minister of Public Safety authority to issue secret orders to individual service providers, subject to approval by the Intelligence Commissioner.

And it provides for mandatory retention of specified categories of metadata. The House did make important amendments before passing the bill. The maximum metadata retention period was reduced from one year to six monthsThe provisions dealing with systemic vulnerabilities were improved, but definitely not fixed.

The government is still creating a permanent statutory framework under which private companies can be required to design their systems so that government access can be facilitated.

And that raises some enormous questions about privacy, cybersecurity, proportionality and the future design of communications infrastructure.

As I said in my earlier episode, I think Part 1 is largely fixed. Part 2 is better than what we saw before, but I still think it is deeply problematic.

Part 7: The Senate Could Really Matter

And that makes the Senate particularly important this fall. The House consideration of C-22 ended very quickly. On June 17th, the government obtained a programming motion that dramatically compressed the remaining committee and House proceedings, and the bill was passed by the Commons on June 18th.

So the Senate now has an opportunity to give the legislation the detailed scrutiny that a bill of this significance deserves.

I hope Senators take that opportunity. I would expect witnesses from law enforcement and national security agencies. I would expect privacy and civil-liberties advocates. I would expect telecommunications companies and major technology companies. I hope there are cybersecurity and encryption experts. And I hope Senators spend a lot of time on a fundamental question:

What technological capabilities should the government be permitted to require private companies to build in advance, so they are available if government wants to use them later?

That is a very different question from whether police should be able to get a warrant. Of course police should be able to get warrants where the legal requirements are met. The much harder question is whether we should redesign communications infrastructure to make surveillance easier. Those are not the same thing.

Part 8: The Bigger Picture

And that's why I think these three bills need to be looked at together.

With Bill C-34, the government wants online services to know more about their users' ages and identities so they can control access and manage harmful content.

With Bill C-36, the government is completely rewriting the rules governing how businesses collect and use personal information.

And with Bill C-22, the government wants to ensure that information and technical capabilities exist so law enforcement and national security agencies can obtain data when legally authorized to do so.

There are legitimate public-policy objectives behind all three. Protecting children online is important. Most folks in the field agree that modernizing our privacy law is overdue. Giving police appropriate tools to investigate serious crime in a digital world is necessary. (Emphasis on “appropriate”.)

But good objectives do not automatically produce good legislation. And one of the recurring themes running through all three bills is information architectureWhat data are companies required to collect? What data are they permitted to use? What data must they retain? What technological systems must they build? Who gets access to that information? Who is the “customer”? The police? Who regulates all of this? And what checks exist on those regulators and government agencies?

Those questions are going to shape the Canadian internet for years.

Part 9: What I Will Be Watching

So here is my fall 2026 privacy and digital-policy watch list.

For Bill C-34, watch the age-16 restriction, age-verification requirements, freedom-of-expression issues, the treatment of AI and the enormous amount of substantive law being left to regulations and Commission rule-making.

For Bill C-36, watch the fate of the existing Privacy Commissioner, the structure and independence of the new regulator, consent and legitimate interests, cross-border transfers, the private right of action and the penalty regime.

And for Bill C-22, watch the Senate. Particularly watch what Senators do with Part 2, metadata retention, technical capability requirements, ministerial orders, encryption and cybersecurity protections.

And there is one final thing to watch: Speed. We've seen governments try to enact major digital-policy reforms only to have them die because they were too controversial, too complicated or simply ran out of parliamentary runway. Privacy law reform Bills C-11 and C-27 never became law. Online Harms Bill C-63 never became law. The lawful-access proposals in Bill C-2 did not survive in that form.

So introducing legislation is one thing, getting it through both Houses of Parliament is entirely different.

Bill C-22 is already well down that road. C-34 and C-36 are just getting started.

And I suspect we're going to know a lot more by Christmas about how serious the government is about getting each of them enacted.

Conclusion

So buckle up. The fall of 2026 will be enormously consequential for Canadian privacy and technology law.

And I expect I'll have plenty to talk about over the next few months. 

Thursday, May 07, 2026

My testimony on Bill C-22, the Lawful Access Act of 2026, to the House of Commons Standing Committee on Public Safety and National Security

(The full stream of the four hour meeting is here and the Notice of Meeting with the roster of witnesses is here. I was on the second panel in the second hour.)

Here is my opening statement: 

Mr. Chairman, honourable members. Thank you very much for your kind invitation to share my views on Bill C-22. I am a partner with the law firm McInnes Cooper in Halifax, where among other things, I advise clients who are on the receiving end of orders for customer information. I also teach at Dalhousie law school.


I am appearing in my personal capacity. These are my own views, and I am not speaking on behalf of any of my clients. 


I have to commend the government for its comprehensive consultation with stakeholders since Bill C-2, to which I contributed. 


I have a number of concerns and recommendations. I will note that Part 2 of Bill C-22 is VERY problematic. I can’t adequately cover all my concerns in five minutes, so I look forward to the rest of our discussion.


First, narrow the scope or raise the bar for subscriber information production orders.


The bill lowers the threshold for police to obtain a production order for subscriber information from "reasonable grounds to believe" to merely "reasonable grounds to suspect”. 


The new production orders can be directed at anyone who provides services to the public. This means police could demand records from doctors' offices, hotels, banks, and grocery stores.


Even though the definition was narrowed from previous bills, police can still demand "all the subscriber information" a service provider holds. This goes beyond a name and address and includes the "types of services provided" and all "device identifiers". This could force a medical clinic to provide info about a patient's CPAP machine, or compel Apple to hand over the digital IDs for every device a person owns, including AirTags and iPads.


Narrow the scope of these orders, or raise the bar to reasonable belief. Or it'll be found to violate the charter. 


Part 2 - the Supporting Authorized Access to Information Act (SAAIA) Generally


Nobody has made a persuasive argument that anything in Part 2 of Bill C-22 is really necessary. The Government has had 20+ years to build their case, but as NSICOP observed they only have anecdotes. We should not be undermining the privacy and safety of every single Canadian based on anecdotes. 


Part 2 of the bill targets "electronic service providers" (ESPs), but the definition is so broad it likely includes most businesses in Canada. 


If it proceeds, the Bill should include necessary guardrails: Under no circumstances should the government  be allowed to require an electronic service provider to  


(i) make changes to products or services that a business provides in the ordinary course, 


(ii) collect and retain any data beyond what the business requires for its own purposes, and 


(iii) make any changes that would affect the functionality (including ordering additional functionality) for any products or services offered by the business. 


As written, the Minister could issue a secret order to turn your Amazon Alexa into a listening device. CSIS has explicitly said they want to be able to track every single phone in Canada in real time, and telcos must make every cell phone trackable. That’s absurd. 


The Government says “we don’t plan to undermine encryption” and there are “no backdoors”. You just have to read the words in the Bill and there’s nothing to prevent that. Government officials said at this committee the Bill is “encryption neutral.” Canadians are not “encryption neutral”. 


The words of the bill clearly permit – and certainly do not prohibit – backdoors and mandatory decryption. In secret with no transparency to Canadians and little accountability. 


What the government “intends” is not relevant. What is relevant is what words end up in a statute. 


The Bill should expressly prohibit undermining or circumvention of encryption. 


Next, ministerial orders have to go 


Under Part 2, the Minister of Public Safety can issue orders to service providers that come with mandatory, permanent secrecy. 


Currently, the police and CSIS can apply to a judge for an “assistance order”, to order a service provider to provide all reasonable assistance to give effect to a warrant. This can be accompanied by a gag order if appropriate. This is judicial control. Nobody from law enforcement has offered evidence that assistance orders are inadequate and should be replaced by secret Ministerial Orders. 


The UK equivalent of a Ministerial Order was used by the UK government to secretly order Apple to remove encryption on iCloud globally. Part 2 of Bill C-22 does not contain any guardrails that would prevent that overreach. 


Secret ministerial orders have to go.


Massive Cybersecurity Risks from "Backdoors"


As legions of cybersecurity experts have said, forcing companies to build surveillance capabilities into their networks creates inherent vulnerabilities. Use your favourite search engine to look up “Salt Typhoon” or “Vodafone Greece scandal” to see examples of lawful access capabilities being exploited for widespread illicit wiretapping. 


This makes Canadian infrastructure a massive target for cybercriminals.


Metadata Retention 


The Bill permits the government to require ESPs to retain metadata, which includes your location history. The government will require everyone’s cellphone to become a retrospective tracking device without any suspicion of wrongdoing. This will almost certainly be found to violate the Charter


Collected metadata will be sought by Canadian and non-Canadian authorities based on mere suspicion. That’s a record of everyone who sought reproductive health care in Canada, which might be of interest to law enforcement from a Five Eyes partner. 


Part 2’s authorities to access data


The government says that Part 2 does not create any new authorities to access data. That’s simply not true. Take a look at section 20. Persons designated by the Minister can enter any premises without a warrant and without notice, and can examine, copy and remove any information found in that place. They can order anyone in that place to provide any data they ask for. That’s a new authority, and if the premises are an ESP’s offices, that includes access to information about their customers. There are simply no guardrails. 


I look forward to a productive discussion. 




Sunday, April 26, 2026

The government's misleading and incomplete Charter Statement for Bill C-22, the Lawful Access Act


[Note: I have 55 exams to mark, so the video and podcast versions of this will unfortunately have to wait.]

Finally, the federal government has released the so-called “Charter Statement” for Bill C-22, the Lawful Access Act of 2026. Forty three days after the bill was tabled in Parliament. I don’t know why it took so long, since they just took the Charter Statement for Bill C-2 and did some editing.

In the Charter Statement, the Minister of Justice significantly mischaracterizes his own bill in a manner that makes it appear more Charter-compliant. Given how the government has spoken about this bill, I’m NOT going to say these are honest mistakes. And the Charter Statement doesn’t even address one of the MOST problematic elements of the revised bill: mandatory metadata retention. 


As it is, I do not think that Bill C-22 is Charter compliant, but with some changes, I think that it can be made Charter-compliant. 


Some background on what Charter Statements are about can be found in the Charter Statement itself:


Section 4.2 of the Department of Justice Act requires the Minister of Justice to prepare a Charter Statement for every government bill to help inform public and Parliamentary debate on government bills. One of the Minister of Justice’s most important responsibilities is to examine legislation for inconsistency with the Canadian Charter of Rights and Freedoms. By tabling a Charter Statement, the Minister is sharing some of the key considerations that informed the review of a bill for inconsistency with the Charter. A Statement identifies Charter rights and freedoms that may potentially be engaged by a bill and provides a brief explanation of the nature of any engagement, in light of the measures being proposed.


Essentially, this is a half-hearted attempt to say this is how the government thinks this can be called Charter compliant, rather than being an honest assessment of the Charter compliance of Bill C-22. If a student handed this to me as an assessment of the Bill, it would be a bad day for that student. 


So let’s dig into it.


It starts by saying “What follows is a non-exhaustive discussion of the ways in which Bill C-22 potentially engages the rights and freedoms guaranteed by the Charter.” As you’ll see, it’s far from “exhaustive.” That said, this essay will not be exhaustive since I’m only going to focus on the deficiencies in the Charter Statement. 


With respect to the Production Order for Subscriber Information, they simply misstate what the Bill actually says.  The Charter Statement says:


The following considerations support the consistency of the amendments with section 8. The subscriber information sought does not by itself constitute particularly sensitive information, since it is limited to information that identifies clients and services, and does not include the contents of communications. The judge would have discretion as to whether to issue an order, and if they choose to issue an order, the judge would have discretion as to what information is specified in it. [emphasis added]


This last part is not true. It is simply false. The way the Bill is currently written, the judge has NO discretion. Here’s what it says in the proposed new section 487.0142 of the Criminal Code:


487.‍0142 (1) On ex parte application made by a peace officer or public officer, a justice or judge may order a person who provides services to the public to prepare and produce a document containing all the subscriber information that relates to any information, including transmission data, that is specified in the order and that is in their possession or control when they receive the order.


It says “all the subscriber information”. The words “that is specified in the order” refers to the “that relates to any information, including transmission data” part. The judge has no discretion to order the production of a subset of Subscriber Information. It is all or nothing. And what is “all” is also a problem. 


The Charter Statement also says:


The subscriber information sought does not by itself constitute particularly sensitive information, since it is limited to information that identifies clients and services, and does not include the contents of communications.


Subscriber information is actually more than that, and can be much more sensitive than they suggest.


subscriber information, in relation to any client of a person who provides services to the public or any subscriber to the services of such a person, means

(a) information that may be used to identify the subscriber or client, including their name, pseudonym, address, telephone number and email address;

(b) identifiers assigned to the subscriber or client by the person, including account numbers; and

(c) information relating to the services provided to the subscriber or client, including

(i) the types of services provided,

(ii) the period during which the services were provided, and

(iii) information that identifies the devices, equipment or things used by the subscriber or client in relation to the services.


(a) and (b) in the definition mostly do that, but paragraph (c) goes much further than that. It refers to the “types of services provided” and “devices, equipment or things” used by the customer. Remember, this order can be directed to anyone who provides services to the public, which can be a medical clinic. What sort of services you get from a medical clinic is certainly sensitive information in which there is a very high privacy interest. Those devices can include things like pace-makers, CPAP machines and insulin pumps. Again, a very high privacy interest. 


If your internet service provider is also your cable company and your cellphone provider, asking for subscriber information based on an IP address can result in information about your cable packages, your cell number, your cell’s IMEI and IMSI numbers, and the serial number of your cable modem. That is way more information than is necessary to simply connect an IP address to a person.


But of course, the government shrugs that off.


Next up is the provision regarding “publicly available information.” This provision says:


(4) For greater certainty, no production order or warrant, or confirmation of service demand made under section 487.‍0121, is necessary for a peace officer or public officer to receive, obtain and act on any information that is available to the public.


The Charter statement says “Where information is available to the public, a person will usually have no reasonable expectation of privacy in it.” I think that’s generally right. But notice the use of the words “usually”. Some critics of Bill C-2 and now Bill C-22 are concerned that this appears to authorize the cops to use information that was hacked by a third party and leaked on the internet. These hacks and leaks take place all the time. I am also concerned about the police buying location data from companies in the advertising ecosystem. That’s “available to the public”, but I’d argue that the individuals retain a significant privacy interest in that data when it’s associated with them. 


The Citizenlab recently reported that US law enforcement, like ICE and the Department of Homeland Security, have been buying this location information for use in their surveillance operations. 


I’m not sure that would survive Charter scrutiny in Canada. 


Let’s move onto Part 2, which will create the “Supporting Authorized Access to Information Act.” I have said, in general terms, that Part 1 is about new ‘authorities’ to obtain information and Part 2 is generally about new mandatory ‘capabilities’ to obtain information. That’s true in general terms, but Part 2 actually does create new authorities. 


At the beginning of the Charter Statement, it largely says “all good" …


The provisions would not grant any new authorities to lawfully access information and data or expand or derogate from any existing authorities for such access.


Now, that’s not entirely true. Part 2 does create two new authorities for accessing data. While they seem intended to allow access to information about “electronic service providers”, the guardrails are lacking. 


First of all, we have section 14 which requires electronic service providers to allow the Minister’s designates to assess and test any device, equipment or other thing that may enable an authorized person to access information.


Obligation to assist

14 (1) On request made by the Minister, an electronic service provider must provide all reasonable assistance to a person or class of persons specified in the request to permit the assessment or testing of any device, equipment or other thing that may enable an authorized person to access information.

For greater certainty

(4) For greater certainty, the assessment or testing must not have the effect of granting access to personal information.

They’ve sensibly added a bit of a guardrail in subsection (4) that says they can’t use this authority to get access to personal information. That is a new authority to obtain information. 


More troubling is section 20, which creates a search authority on the part of the Minister’s designates to enter any premises other than a dwelling, without a warrant and without notice. They don’t even need to suspect any sort of infraction. It just has to be related to an activity regulated by the Act. Once they’re in, they can examine anything, make copies of it, remove documents, use computers found there, and more:


Authority to enter place
20 (1) Subject to subsection 21(1), a designated person may, for the purpose of verifying compliance or preventing non-compliance with this Act, at any reasonable time enter any place if they have reasonable grounds to believe that anything relevant to that purpose, including any document or electronic data, is located in that place or that an activity regulated by this Act is conducted in that place.

Powers on entry
(3) The designated person may, for a purpose referred to in subsection (1),
(a) examine anything found in the place, including any document or electronic data;
(b) make copies of any document or electronic data that is found in the place or take extracts from the document or electronic data;
(c) remove any document found in the place for examination or copying;
(d) use or cause to be used any computer or data processing system at the place to examine or copy electronic data; and
(e) use or cause to be used any copying equipment at the place to make copies of any document. 

 


The Charter Statement says not to worry about it. First they say “Privacy interests are diminished in the regulatory and administrative contexts.” That’s largely correct. Then it says:


“Further, information gathered in this context would generally relate to technical capabilities of ESPs, which would not attract a heightened privacy interest. In addition, the powers would not be available for the purpose of advancing a criminal investigation.” [emphasis added]


The word “generally” is doing a lot of work there. It then says: “The proposed powers are similar to regulatory inspection powers that have been upheld in other contexts.”


Yes, it is true that warrantless inspection powers have been upheld in other regulatory contexts. However, this is unlike other regulatory contexts. For example, inspectors from the Department of Fisheries can – without a warrant – enter a fish plant or a fishing boat, and review all the records of the company’s activities. They can go in and count the halibut.


This context is qualitatively different from that. By definition, an electronic service provider is the custodian of very sensitive information of its customers and all of those customers, whether they're good guys or bad guys – and the majority will be good guys – have a Charter protected right to be free from unreasonable search and seizure. The records of your internet service provider are very different from the records of a fish plant, and the government has not included any guardrails. 


The most problematic part of this Charter Statement is what is not said. Perhaps the most problematic part of Bill C-22 – mandatory metadata retention – is not even mentioned. Just because it is one subsection among many is not an excuse.


Core providers — obligations

(2) The Governor in Council may make regulations respecting the obligations of core providers, including regulations respecting ...

(d) the retention of categories of metadata — including transmission data, as defined in section 487.‍011 of the Criminal Code — for reasonable periods of time not exceeding one year.


The loudest and most credible commentators on Bill C-22 have pointed to this and have said it will likely violate the Charter. (Michael Geist: The Lawful Access Privacy Risks: Unpacking Bill C-22’s Expansive Metadata Retention Requirements and Robert Diab: Is the Power to Preserve Everyone’s Metadata Constitutional?)


In the European Union, the Court of Justice struck down the EU Data Retention Directive in 2014 because the general and indiscriminate retention of all users’ telecommunications metadata was a disproportionate interference with the fundamental right to privacy. The Courts there have held that specific metadata retention associated with specific threats or targets can be justified, but blanket metadata retention cannot. It is simply incompatible with EU fundamental rights. 


Currently in Canada, in some circumstances, the police can simply order the retention of information or can get a court order requiring it to be done. Mandatory, blanket metadata retention is wildly problematic and the Charter Statement doesn’t even mention it. 


Finally, we have the blanket confidentiality that makes it an offence for anyone to disclose the contents of a ministerial order, the facts that it exists, what information the Minister used to make the order, any communications between the Minister and the electronic service provider and any “prescribed information”, meaning information that is prescribed in the regulations. 


Prohibition on disclosure

15 An electronic service provider and any person acting on its behalf must not disclose any of the following information except as permitted under this Act or the Canada Evidence Act:

(a) information contained in an order made under subsection 6(1) [temporary exception for a core provider] or 7(1) [ministerial order];

(b) information on which the Minister relied in making the order;

(c) the fact that the electronic service provider is subject to the order;

(d) information provided in the course of representations made under section 8 or in any response given by the Minister and the fact that the Minister has invited the representations;

(e) information contained in an application referred to in subsection 6(1) or in a decision made under subsection 6(4);

(f) information submitted under subsection 11(2) and any information received from the Minister in response;

(g) any prescribed information.


I have previously shared my view that this is over the top and the Minister should have to justify any confidentiality orders on a case-by-case basis. 


The Charter Statement says:

To achieve this objective, the provisions would place limits on communication about the technical capabilities of ESPs, which are commercial entities. While restrictions on commercial speech can engage the right to freedom of expression, they usually do not implicate the core values of the right. These include the search for political, artistic and scientific truth, the protection of individual autonomy and self-development, and the promotion of public participation in the democratic process. Rather, the restrictions would be narrowly focused on the existence and contents of orders and exemptions, all linked to the objective of protecting sensitive information. Limits on expression that do not engage the core values of the right are more easily justified. [emphasis added]

That may be generally true, but public discussion about massive surveillance of Canadians and potential government overreach and abuse is actually very, very close to the core of “Charter values” – it’s about the protection of individual autonomy and public participation in the democratic process. They’re missing the mark here, widely. 

And then there’s the cumulative effect of all of this. The government can require an ESP to retain a  year of metadata, which can include the minute-by-minute location of every phone in Canada. And then they can send in inspectors to say “hey, we’re here to inspect your metadata databases.” And by the way we’re making a copy for easier inspection back at the office. That amounts to a HUGE invasion of privacy.


The Charter Statement, not surprisingly says: “it’s fine.” 


It’s not fine.