Parliamentary Committee Notes: Minister Anandasangaree's appearance before the Standing Committee on Public Safety and National Security (SECU)
Bill C-22, An Act Respecting Lawful Access

May 5, 2026

Table of contents

Overview

Overview Note

General Information

Date: Tuesday, May 5, 2026
Time: 4:30 p.m. to 5:30 p.m.
Location: Room 415, Wellington Building, 197 Sparks Street

Context

As part of its study of Bill C-22, Lawful Access Act 2026, SECU has invited you and the Minister of Justice and Attorney General of Canada to appear together. Senior officials from the following departments will be joining you at the table (names to be confirmed):

  • Public Safety Canada (PS)
  • Royal Canadian Mounted Police (RCMP)
  • Canadian Security and Intelligence Service (CSIS)
  • Justice Canada

Second Reading debate showed broad agreement across parties on the need to modernize Canada's lawful-access framework. All parties supported the principle of establishing a clear, modern regime, but each identified areas of concern that will shape committee questioning. Conservative Party of Canada (CPC) members focused on risks related to "backdoor" vulnerabilities, cybersecurity, privacy and data-retention requirements, and the scope and transparency of ministerial orders. The Bloc Québécois (BQ) emphasized the absence of consultation with the Privacy Commissioner and expressed concern about the bill's reliance on regulation to define key terms.

You can expect questions on privacy protections, oversight mechanisms, plans for regulatory mechanisms, and the balance between investigative needs and civil liberties. Your briefing package includes key messages addressing these themes.

Sequence of the meeting

Officials will appear for the first hour of the meeting (3:30 p.m.–4:30 p.m.) to respond to questions from committee members.

At the start of the second hour, you and the Minister of Justice will each be invited to deliver approximately five minutes of opening remarks outlining the bill, its key provisions, and its importance in keeping Canadians safe. You are invited to appear from 4:30 p.m. to 5:30 p.m.

Speaking Notes For The Honourable Gary Anandasangaree
Minister of Public Safety

May 5, 2026
Ottawa, Ontario

I'd like to start by acknowledging that we are meeting on the traditional and unceded territory of the Algonquin Anishinaabeg People.

Thank you for the invitation to speak today about C-22.

As the Minister of Public Safety, my priority is to ensure every Canadian remains safe and secure. Since my appointment, I have heard clearly from law enforcement at all levels – municipal police services and the Royal Canadian Mounted Police (RCMP) – as well as victims' groups and others.

They have all said Canada needs modern tools to take on the wide array of illicit activities that are facilitated by the global digital environment.

Technology has fundamentally changed the nature of crime and threats globally. Criminals are continuously exploiting the digital space we all use to facilitate a wide array of offenses – this includes extortion, child exploitation, and human trafficking.

Furthermore, this environment is being used to facilitate foreign interference and violent extremism.

Our laws have simply not kept pace with our digitally-driven world. This has created a significant gap between today's crimes and threats and what our current laws can meaningfully address.

We owe it to Canadians to tackle these new threats head on.

This is what Bill C-22 aims to do.

It's worth taking this opportunity to highlight that Bill C-22 does not aim "to regulate the internet", "police activity on the Internet" or require internet service providers to become agents of the Government as some of the debate in the House has suggested.

It is simply to address gaps in our legal framework that present challenges to timely access to information and intelligence that are vital to conducting investigations.

It will give our officers the tools they need to keep Canadians safe in the 21st century, while ensuring we continue to uphold Canadians' Charter and privacy rights.

We listened to concerns raised by stakeholders and other parliamentarians after Bill C-2 was introduced.

Part 1 of Bill C-22 includes important safeguards, such as limiting the scope of the confirmation of service demand to telecommunication service providers only, a narrower definition of subscriber information, and strong judicial oversight. Police will still require court approval to obtain personal details like names, addresses, or phone numbers.

Under Part 2 of the Bill, we'll ensure electronic service providers can fulfill lawful access requests.

Let's be clear: this Part does not create new authorities for law enforcement agencies and the Canadian Security Intelligence Service (CSIS) to intercept communications or obtain information. Its focus it to ensure electronic service providers are able to comply with existing legal orders, which are found in the Criminal Code, and the Canadian Security Intelligence Service Act.

Key elements include a new compliance framework that will require "core providers" to have the technical capability to comply with legal authorization to obtain information, such as warrants and production orders.

It also gives new Ministerial Order powers to the Minister of Public Safety. Only with approval from the Intelligence Commissioner, the Minister could order an electronic service provider(s) to develop specific technical capabilities, for example to address new technologies that are developed and not captured in the regulations.

Finally, it introduces regulatory enforcement tools such as administrative monetary penalties for any provider who do not comply.

Mr. Chair, once again, I wish to underscore the safeguards that would be in place under this Part of the Bill. As I mentioned, all Ministerial Orders will require prior approval from the Intelligence Commissioner to ensure they are reasonable.

This Partalso includes an explicit safeguard to prevent the introduction of systemic vulnerabilities in electronic protections. Our government does not support the creation of backdoors.

We want Canadians to see exactly how these powers are being created and used, to ensure their implementation is subject to the highest levels of democratic scrutiny.

Under our current laws, our police and intelligence officers are trying to fight tech-savvy criminals and state actors with tools that are decades old. Bill C-22 bridges that gap, while it upholds the Charter rights and privacy of all Canadians.

Thank you and I look forward to your questions.

Current Issues

Key Messages

General

Keeping pace with new technologies:

  • Bad actors depend on digital communications to carry out their criminal and threat activities.
  • Clear, updated laws are essential for effective investigations into a variety of crimes and national-security threats.
  • It is crucial that we have laws and that they are able to keep pace with our rapidly evolving technology-driven world.

Giving law enforcement and CSIS the tools needed to keep Canadians safe:

  • Bill C-22 will give investigators the tools to advance their investigations and quickly identify which telecommunications or internet provider has the information; with lawful authorization law enforcement will be able to obtain basic information on victims, and/or suspects.
  • Bill C-22 will allow investigators to obtain critical information to keep communities safe.
  • Bill C-22 will require electronic service providers to develop and maintain the technical capability (i.e., infrastructure) needed to provide information and data that law enforcement and CSIS are legally authorized to have.

Part 1 - Timely Access to Data and Information

Delivering on the government's commitment to modernize legal authorities to meet contemporary security and enforcement challenges:

  • A new confirmation of service demand to confirm, for example, the telecommunication service provider for a phone number.
  • A new production order to obtain name and address (i.e., subscriber information) with a warrant.
  • Updated search warrant powers for computer searches to align with contemporary digital realities.
  • A new authority for Canadian police to make a request to foreign electronic service providers, including social medias (e.g. Meta or X).
  • A new tool of international cooperation to support court-ordered production of basic data requested by foreign partners.
  • Provide certainty for police and CSIS to continue use of unsolicited or voluntarily provided information, information that is publicly available, and obtaining information or data in exigent circumstances.

Part 2 – Supporting Authorized Access to Information Act (SAAIA)

Ensuring that electronic service providers (ESPs) have the required technical capabilities to support law enforcement and CSIS:

  • Requires select ESPs to develop and maintain capabilities that allow them to provide law enforcement and CSIS with information they are legally authorized to obtain.
  • Establishes two mechanisms for requiring capabilities: class-based obligations for core ESPs and Ministerial Orders for specific operational needs and emerging threats.
  • Ministerial Orders, with the approval of the Intelligence Commissioner, would allow a targeted approach, so that only specific providers—not entire sectors—must develop capabilities.

Building on current oversight and transparency mechanisms:

  • Intelligence Commissioner must review and approve Ministerial Orders to ensure they are reasonable and proportionate before they become valid.
  • Complementing the National Security and Intelligence Review Agency's (NSIRA) role, the Intelligence Commissioner would provide them with a copy of its decisions.
  • Minister of Public Safety must publish an annual report on SAAIA activities.
  • Includes safeguards to ensure that the Government of Canada cannot force ESPs to implement systemic vulnerabilities in their electronic protections

Anticipated Questions

General Committee Notes

Q1 – Why is the Government introducing this legislation now and what problem is it trying to solve
  • As the Minister of Public Safety (PS), my priority is to ensure every Canadian remains safe and secure.
  • Since my appointment, I have heard clearly from law enforcement at all levels as well as victims' groups and others.
  • They have all said Canada needs modern tools to take on the wide array of illicit activities that are facilitated by the global digital environment.
  • Technology has fundamentally changed the nature of crime and threats globally. Criminals are continuously exploiting the digital space we all use to facilitate a wide array of offenses – this includes extortion, child exploitation, and human trafficking. Furthermore, this environment is being used to facilitate foreign interference and violent extremism.
  • Our laws have simply not kept pace with our digitally-driven world. This has created a significant gap between today's crimes and threats and what our current laws can meaningfully address.
  • This is what Bill C-22 aims to correct.
Q2 – How is this bill different from C-2 and why should Canadians view this as a genuine departure rather than a rebranding
  • Substantial refinements have been made to the previous proposals that were included in Bill C-2. With respect to Part 1 of Bill C-22, key changes include the following:
    • The scope of the proposed new authority to confirm information from service providers without prior judicial authorization ("confirmation of service demand") was narrowed to apply only to "telecommunications service providers" (e.g., internet access and telephone companies).
    • The demand can only ask for confirmation of whether or not the telecommunications service provider is or has been providing telecommunication services to a subscriber, client or data point, like a phone number, specified in the demand.
    • Further, the provision has added language to make it crystal clear that the demand cannot be made if the confirmation requested would disclose medical information or information that is subject to solicitor client privilege or the professional secrecy of advocates and notaries.
    • The definition of "Subscriber Information" has been refined and narrowed to information that may be used to identify the subscriber or client (name, address, phone number, email) and the services provided.
    • The amendments proposed to the Criminal Code production order review process have also been revised to extend the proposed maximum period of 5 days to apply for review of a production order to a period of 10 business days from the day the order is received.
  • With respect to Part 2 of Bill C-22, several changes have been made to address concerns expressed by stakeholders during our engagement. Most notably:
    • Ministerial Orders (MO) are now subject to pre-approval by the Intelligence Commissioner before being issued by the Minister of PS.
    • Systemic vulnerability is now defined in the statute.
    • Privacy and cybersecurity must be explicitly considered when implementing technical solutions. Meaning that the same factors that must be considered for MOs will also be used by the Governor in Council when making regulations following royal assent of the Bill.
    • Clarification that data retention requirements can be imposed only for metadata, for a one year maximum, but not for content, web-browsing or social media history.
    • Additional parameters have been added for the inspection powers, the obligation to assist, and the confidentiality and security regulations.
    • Subsection 15(g), which could be read as prohibiting the disclosure of information related to a potential systemic vulnerability, has been removed.
    • Information provided as part of an Electronic Service Providers (ESP) internal audit or obtained during an inspection must be kept confidential by designated persons.
    • Public annual reporting has been included as a legislated requirement for transparency.
Q3 – Although Bill C-22 was introduced in March, the Charter statement was not made available for over a month. What caused that delay, and should we infer that there were concerns about Charter compliance? Is the Government confident that this new attempt at lawful access reform is Charter compliant
  • The Government is confident that Bill C-22 is consistent with the Charter.
  • Charter Statements are prepared based on the bill as introduced. While the Department of Justice Act does not specify a timeframe for tabling of the Charter Statement, the Minister normally aims to table the statement prior to second reading so that it can contribute to parliamentary debate.
  • The time taken to prepare a Charter Statement does not reflect concerns with the bill. The Charter Statement for the bill was tabled in the House of Commons on April 24, 2026.
Q4- Which stakeholders did the government consult in developing Bill C-22, and on what specific aspects of the legislation was Murray Rankin engaged during those consultations
  • The Government of Canada has been engaging with stakeholders on lawful access reforms for several years.
  • More recently, following the introduction of Bill C-2 in June 2025, Public Safety Canada held information sessions and bilateral meetings on the legislation to raise awareness of its purpose and scope, its benefits for Canadians and to seek the views of stakeholders, including civil society, academia, industry, provinces and territories, and law enforcement agencies.
  • To dive deeper into some of the questions and concerns raised following the introduction of Bill C-2, some stakeholders were invited to participate in five facilitated roundtable discussions, moderated by Murray Rankin, to discuss concerns and potential amendments for improving the legislative proposal. Invited stakeholders included a cross representation of civil liberty and privacy advocates, academics, and industry representatives, as well as indigenous, provincial and municipal law enforcement agencies.
  • These important consultations – as well as feedback from Parliamentarians – informed the key changes that have been made in Bill C-22, and demonstrate that our Government is listening to Canadians.
Q5 – Given the significant opposition and perceived unresolved privacy and Charter concerns raised during the first attempt, why is the government once again prioritizing lawful access legislation? What makes this effort different enough to warrant reconsideration
  • Our Government is committed to advancing the tools necessary to keep Canadians and our communities safe.
  • This includes providing law enforcement agencies and domestic intelligence with new tools to facilitate domestic and transnational sharing of information and data to advance investigations in a digital and globalized world where crimes transcend national borders.
  • The R v Spencer decision in 2014 has negatively impacted police investigations by requiring a general production order for every request regardless of the nature of the information requested.
  • This has resulted in several challenges for law enforcement:
    • It makes the process more burdensome and slows down investigations.
    • It creates barriers in early-stage investigations because police often cannot meet the high legal standard when they are just beginning to explore leads.
    • By the time police gather more information to obtain a general production order, the data may no longer be available depending on how long a service provider retains the data.
Q6 – Despite widespread criticism and uncertainty, the government has yet to clarify its intentions on Bill C-2. Will it be withdrawn—yes or no—and if not, why is it being kept alive
  • After introducing Bill C-2, we listened carefully to feedback from Canadians and from Parliament, and we made meaningful refinements through new legislation that addressed these concerns.
  • In developing C-22, we engaged extensively with law enforcement, privacy and security experts, and members from all parties. What we heard consistently is that Canada needs a modern framework to support lawful access investigations, but one that includes strong safeguards to prevent overreach.
  • Bill C-22 reflects that input. It strengthens investigative capacity while protecting the rights and freedoms Canadians expect.
  • While Bill C-2 remains on the Order Paper—and contains measures that may still be useful—our priority at this time is moving forward with Bill C-22.

Part 1 – Anticipated Questions

Committee Notes

Q1- How narrowly are "exigent circumstances" defined in this legislation, and what prevents warrantless access to digital information from becoming routine rather than exceptional
  • "Exigent circumstances" is a well-established concept in criminal law. It generally refers to two types of urgent situations:
    • When immediate action is needed to protect the public or police safety.
    • When there is an imminent danger that evidence will be lost, removed, destroyed, or disappear if the search or seizure is delayed.
  • Examples include locating a victim of abduction through their cellphone or stopping a live streaming of child sexual abuse by identifying the perpetrators using IP addresses and subscriber information.
  • Even in exigent circumstances, police must still meet strict conditions.
  • The situation must make it impracticable to obtain a warrant or production order, and the legal grounds for the seizure must still exist.
  • Importantly, search and seizures effected in this manner are routinely challenged in court when a person is charged with an offence, which will require the police to demonstrate that all the conditions of the provision were met.
Q2 – When law enforcement accesses data without a warrant under "exigent circumstances," what concrete recourse or review exists to prevent abuse
  • When law enforcement officers obtain data without a warrant due to exigent circumstances, the basis for obtaining that data can be challenged in court when the data is used as evidence, if the defence believes that the access was not made in accordance with the appropriate standard (of exigency).
  • Law enforcement officers should carefully consider whether it is appropriate to invoke this exceptional authority before relying on it, as its inappropriate use can have serious consequences.
  • The remedies imposed by the court can be severe, should there be found to be inappropriate use of this exception. In addition to other actions available in cases of serious misconduct, the court may exclude the evidence, which can undermine the entire basis for the prosecution.
  • In addition to the possibility of court review, concerns about police misconduct can also be brought to police oversight bodies.
  • Concerns in relation to failures by law enforcement officers to respect their obligations under the law to protect privacy can also be brought to the attention of the Privacy Commissioner of Canada, or provincial privacy commissioners, for additional scrutiny and consideration.
Q3 – Given that the confirmation of service demand can be issued without a warrant and paired with non-disclosure conditions, how can Canadians be confident this won't become a de facto workaround to the Spencer decision by allowing police to map out a person's digital footprint before ever going to a judge
  • This provision was developed to respond to some of the impacts of the Spencer decision. In Spencer, the Supreme Court of Canada (SCC) indicated that police must act on the basis of a reasonable legal authority to compel information that identifies an individual and links them to specific online activities, like uploading child sexual abuse and exploitation material.
  • The confirmation that a telecommunication service provider provides telecommunication services to a specific person or identifier, like an IP address or phone number, is not the type of information that was at issue in Spencer because it does not identify a person behind specific online activities. Yet, since Spencer, some service providers have been reluctant to provide this confirmation to police without a warrant. The new confirmation of service demand would provide a clear legal basis for police to compel this information.
  • The Government believes that this tool is a reasonable legal authority and the Minister of Justice is of the view that it is consistent with the Charter.
  • This authority would be strictly limited to demanding confirmation of service, a "yes/no" answer. It is not a tool that would enable the police to map out a digital footprint.
  • The police would only be permitted to make a confirmation of service demand in the context of a criminal investigation, where they have reasonable grounds to suspect that an offence has been, or will be committed, and that the information that is demanded will assist in the investigation of the offence.
  • The main purpose of this new tool is to enable law enforcement agencies to identify the telecommunications service provider most likely to be in possession or control of information that is relevant to an investigation. This confirmation information is essential to obtain a judicially authorized production order, which could be used by police to compel the disclosure of records containing personal information.
  • The authority could NOT be used to demand subscriber information.
  • The non-disclosure provision could only be used if the peace officer or public officer has reasonable grounds to believe that the disclosure of the existence of the demand would jeopardize the conduct of the investigation.
  • The telecommunications service provider would also be able to challenge the demand to a court and have it revoked or varied. There would be no obligation for the service provider to provide the confirmation until a final decision is made.
Q4 – What precisely qualifies as "transmission data" or "metadata" under this Bill
  • Transmission data, as defined in the Criminal Code, refers to information about how a communication is routed between devices over telecommunications networks. Examples include phone numbers, IP addresses and transmission logs.
  • Transmission data can show the type of communication (e.g., email, voice message, image), along with details like the date, time, duration, direction, origin and destination of the communication. Importantly, it does not include the actual content of the communication, which is explicitly excluded from the definition to protect privacy.
  • The term metadata is not the equivalent of the defined term transmission data. Metadata is understood to mean "data about data". Metadata would, for example, include data relating to the size, format, and geolocation related to a digital photo, none of which is transmission data.
  • The Bill amends the tracking warrant (section 492.1 of the Criminal Code) and transmission data recorder warrant (section 492.2 of the Criminal Code) to allow the judge or justice to authorize the collection of tracking data or transmission data from devices that are unknown at the time the warrant is issued but are similar in nature to those described in the warrant.
  • These amendments do not change the existing legal thresholds for issuing tracking or transmission data recorder warrants. They simply clarify and extend the scope of what can be authorized under those warrants, ensuring police can act effectively while also respecting privacy protections.
  • These amendments are meant to address a situation in which a suspect may regularly switch mobile phones (e.g., burner phones) or vehicles to evade surveillance. The proposed amendments would allow law enforcement agencies to: track new burner phones or vehicles used by a suspect; or obtain transmission data from those without having to re-apply for new warrants for each phone or vehicle.
Q5 – How much information would be provided to police under the new production order for subscriber information? Would that include medical records
  • The new production order would only compel "subscriber information" as defined in the Criminal Code.
  • The new definition of subscriber information would only include information that may be used to identify the subscriber or client of a service, including their name, pseudonym, address, telephone number and email address. It would also include identifiers assigned to the subscriber or client by the service provider such as a phone number or SIM card number, and information relating to the services provided.
  • This would not include medical records or other type of content information that belongs to the client or subscriber.
Q6 – The authority to include "unknown but similar" devices risks significant scope creep. What enforceable safeguards ensure that such warrants do not expand well beyond the original investigative justification
  • These warrants would remain tied to the investigative justification as they are today, and if these reforms are enacted, the authority that would be provided would be subject to the same limits in scope of the warrant.
  • What would change would be that a court that authorizes police to obtain tracking data from a thing that a person uses, carries or wears, such as a cell phone, may, when issuing the warrant, authorize obtaining tracking data from another phone that is not known when the warrant is obtained.
  • This extension to another device is only permitted if the justice or judge is satisfied that there are reasonable grounds to suspect that the person will use, carry or wear that similar thing, such as a new cell phone, for example.
  • Similarly, a court that authorizes police to obtain transmission data would be able to, in the warrant, authorize obtaining transmission data that relates to a new means of telecommunication that was unknown at the time the warrant was issued but is of a similar type as in the warrant.
  • As with the tracking data warrant, this can only be done if the judge or justice is satisfied that there are reasonable grounds to suspect that the person will use that other means of telecommunication.
  • The current approach in the law is tied to specific devices and means of telecommunication. The laws were enacted when it was not usual for these devices and means of telecommunication to frequently change.
  • Police need modernized approaches to authorizing investigative tools. Police need to readily adapt to change, such as when someone buys a new device, which is easily done today.
  • There is no expanded authority to go beyond what is being investigated under the warrant. The proposed provision would allow a judge to authorize police, where appropriate and justified, to obtain tracking data from another phone that is not known when the warrant is obtained. An example of an appropriate and justified instance for a judge to authorize police to investigate, would be when a suspected drug dealer is suspected to use multiple burner phones; in this case, the Bill's proposed provision would allow police to be able to effectively investigate when the suspect keeps changing devices or means of telecommunication.
  • Police activity outside the scope of the warrant would be subject to challenge by the defence at the time of prosecution, which could result in the evidence being held to be inadmissible, among other consequences. Police misconduct would also be subject to consequences from both the courts and from those responsible for police oversight.
Q7 – Is using a 'reasonable grounds to suspect' threshold for a subscriber-information production order, instead of a 'reasonable grounds to believe' threshold, consistent with R. v. Spencer and the privacy protections guaranteed under the Charter
  • In R v Spencer (2014), the Supreme Court of Canada held that internet users have a reasonable expectation of privacy in their identity when linked to anonymous online activity.
  • Accordingly, the court held that police need some type of legal authority (e.g., legislative authority or prior judicial authorization) to obtain subscriber information in certain contexts.
  • Because no specific tool exists to obtain subscriber information, police have had to use the only tool available - the general production order based on the reasonable grounds to believe standard.
  • These amendments are proposing the creation of a new production order that is specific to subscriber information. It is carefully designed to balance the privacy interests of impacted persons engaged by the disclosure of subscriber information, while addressing the need to ensure that law enforcement agencies have appropriate tools to fulfill their mandates.
  • Police will only be able to use this new tool to obtain subscriber information, as defined, on the conditions that they have satisfied a judge that there are reasonable grounds to suspect that an offence has been or will be committed that the person has possession or control of the information, and that the information will assist in the investigation of the offence.
  • The new production order for subscriber information would not be the first or the only production order to be issued on a reasonable suspicion standard. The Criminal Code currently contains different other production orders and warrants for specific types of data that are obtained on a reasonable suspicion standard. For example, police can obtain a production order for transmission data (section 487.016), which can provide a person's calling history, on that standard.
  • The Bill would establish the most privacy-protective legal standard for accessing subscriber information among Canada's core and likeminded international partners.
  • For example:
    • Practices vary widely across countries, but none of Canada's Five Eyes partners require judicial authorization to obtain subscriber information.
    • In countries with inquisitorial systems, such as France and Spain, prosecuting authorities can issue production orders themselves without judicial oversight.
    • Other democracies like Germany and Finland also allow law enforcement agencies to access subscriber information without prior judicial authorization.
Q8 – In light of the findings from Project South, which revealed unlawful access to police databases and the leaking of sensitive personal information to criminal associates, what measures are in place to ensure that law-enforcement agencies properly store, safeguard, and control access to private data
  • Project South is a months-long criminal investigation led by York Regional Police which uncovered evidence of a criminal network involving police officers, including from Toronto Police, who are alleged to have shared confidential information including with organized crime groups. The findings of the investigation were made public in February 2026, and resulted in arrests of seven serving Toronto police officers, a retired officer, and over 19 other individuals, as well as suspensions of some additional officers in the Peel Region.
  • This is a very serious case, involving allegations of: use of leaked information by criminals in shootings; extortion and commercial robberies; a plot to murder a corrections officer; as well as links to a transnational drug ring. The matter is ongoing and as such, it would not be appropriate for me to comment further.
  • In addition, as an immediate response to concerns about the wide-reaching nature of the findings of the investigation, the Ontario Inspector General of Policing announced a province-wide review would be undertaken of all 45 Ontario police departments.
  • The activities exposed by the Project South criminal investigation occurred under current laws. Nothing in these proposals would reduce the oversight that led to the exposure of the criminal activities alleged to be committed by the officers arrested in this case, and the new investigative tools would assist in appropriate cases with such investigations in the future, should they be enacted.
  • Police in Canada are bound by the applicable privacy legislation. In the case of provincial and municipal forces, they are bound by provincial privacy statutes. In addition, their actions are governed by: the Charter; limitations on investigative authorities set out in legislation such as the Criminal Code and under the common law; through jurisprudence; as well as directives in law and regulation governing their respective police forces.
  • The lawfulness of their activities is assessed by courts in the context of criminal prosecutions, as well as through the work of oversight bodies, such as the Ontario Inspector General of Policing that is conducting a review of Ontario policing in the wake of the Project South investigative findings.
Q9 – Under Bill C-22, what legal recourse does an Electronic Service Provider have if it disagrees with a production order or a confirmation-of-service demand, and how can it challenge or object to the requirement before complying? What sort of timelines are involved with these processes
Production Order
  • Currently under the Criminal Code, section 487.0193 sets out the process for a person, financial institution or entity to apply in writing to the justice or judge who made the production order or to another judge in the judicial district where the order was made, to request that the court revoke or vary the order, prior to being required to comply with the order.
  • This process will be available for the new production order for subscriber information as well.
  • Under existing law, the application can be made before the applicant is required by the order to produce the document, where notice of intent to do so is provided to the peace officer or public officer named in the order within 30 days after the day the order is made. Bill C-22 proposes to change this to a requirement to apply to the court in writing before the requirement to produce takes effect but not later than 10 days after the day on which the order was received, and for the notice of intention to be made to the peace officer or public officer named in the order before the application is made.
  • The court may revoke or vary the order when satisfied that it is unreasonable in the circumstances to require the applicant to prepare or produce the document or the production of the document would disclose information that is privileged or otherwise protected from disclosure by law.
Confirmation of Service Demand
  • A similar process is set out in the Bill for the new confirmation of service demand. The telecommunications service provider may, within five (5) business days after the day on which they receive the demand, apply in writing, to a judge in the judicial district where the demand was received, to revoke or vary the demand.
  • A shorter delay – five (5) business days – would be provided to apply to review the confirmation of service demand because the confirmation entails a single "yes or no" answer, whereas responding to a production order involves identifying and collecting responsive information or documents.
  • The telecommunications service provider may make an application if, before the confirmation is required to be provided, they give notice to the peace officer or public officer who made the demand of the telecommunications service provider's intention to make the application.
  • The telecommunications service provider is not required to provide the confirmation until a final decision is made with respect to the application.
  • The judge in the judicial district where the demand was received may revoke or vary the demand if satisfied that it is unreasonable in the circumstances to require the applicant to provide the confirmation; or provision of the confirmation would disclose information that is privileged or otherwise protected from disclosure by law.
Q10 – Given the increasing complexity of digital communications, what guidance or training will be provided to law enforcement and the judiciary to support consistent application of the updated transmission-data and tracking-data provisions
  • Organizations responsible for applying and enforcing the law are generally conscious of the need to develop guidance and training for their members when changes are made to the law and will make use of existing mechanisms to ensure up-to-date information is made available.
  • In the federal policing context, the Royal Canadian Mounted Police (RCMP) has established governance and implementation mechanisms to adapt to new legislation.
  • Should the proposed amendments to the transmission data and tracking data provisions come into force, the RCMP would support implementation through a coordinated approach that includes:
    • Updating operational policy and associated guidelines;
    • Communicating updates to RCMP employees through broadcasts and other standard communications mechanisms; and
    • Reviewing and updating existing training products.
  • These actions are intended to promote a consistent, lawful, and Charter-compliant application of the authorities across the RCMP organization, while ensuring investigators remain informed of evolving legal requirements.
  • The RCMP also participates on various committees and forums that have representation from law enforcement agencies from across Canada that could be leveraged to communicate legislative changes and support consistent application of any new legislative provisions among other police agencies.
  • In addition, there are various committees and forums that have representation from law enforcement agencies across Canada, such as the Canadian Association of Chiefs of Police, that the Government regularly engages with and that police use to communicate with each other, and which can assist in relation to legislative changes, to support consistent application of any new legislative provisions, including to the transmission data and tracking data provisions in the Criminal Code.
Q11 – When Canada enforces a foreign request for subscriber or transmission data, what protections ensure that Canadian privacy and Charter standards are respected, especially when the requesting country has lower legal safeguards
  • Under the proposed Mutual Legal Assistance in Criminal Matters Act provision, in order for the foreign request to be executed in Canada, it must satisfy Canadian legal requirements for the compelled production of subscriber information and transmission data.
  • More specifically, a Canadian judge must apply the same legal threshold for the production of subscriber information or transmission data that they would apply if Canadian police were seeking the same information to support a Canadian investigation.
  • For transmission data, the legal test that a judge would apply in assessing the foreign request is set out under subsection 487.016‍(2) of the Criminal Code. For subscriber information, the test set out in proposed new subsection 487.‍0142(2) of the Criminal Code would apply.
  • In either case, a Canadian judge must be satisfied: that an offence has been committed or will be committed; that the data sought by the foreign authorities is in the possession or control of a person in Canada; and that the data or information will assist in investigating the offence identified in the request.
  • The proposed provision has other important checks and balances to ensure compliance with Canadian privacy interests and the Charter.
  • This includes an initial assessment of the foreign request by the Department of Justice to ensure: that it complies with the terms of any applicable treaty between Canada and the foreign partner; that the request does not interfere with any Canadian criminal investigation; and that it does not otherwise compromise Canada's public interest.
  • It is only after this initial vetting process that the request would be presented to a Canadian judge to assess whether it meets the Canadian legal threshold for data production.
  • As well, if the judge grants the request for data production, the judge will have the discretion to also order that a second hearing be held to determine whether the data, once produced, should be sent to the foreign partner and whether any conditions should be imposed on the sending. This would be determined by the judge on a case-by-case basis.
  • Finally, the Mutual Legal Assistance in Criminal Matters Act includes appeal rights applicable to all of the measures provided in the legislation. That avenue of appeal would likewise apply in respect of orders made under the proposed new provision.
Q12 – How will the International Production Request ensure that Canadians' subscriber and transmission data is not shared with foreign authorities in ways that exceed the privacy protections Canadians would receive if the data were held domestically
  • The proposed new International Production Request would not involve sharing Canadians' subscriber and transmission data with foreign authorities.
  • The data requested in an International Production Request is being held by a foreign entity that provides telecommunications services (e.g., AT&T, Verizon) or that provides services by means of telecommunication (e.g., OpenAI, Apple, Meta).
  • The data received by investigators in Canada pursuant to an International Production Request would be subject to the privacy protections applicable to data held domestically.
  • In the new proposed International Production Request, section 487.‍0181 of the Criminal Code would create a new authority, for an ex parte application to be made by a peace officer or public officer to a Canadian justice or judge to authorize a peace officer or public officer to make a request to a foreign entity that provides telecommunications services — or that provides services by a means of telecommunication — to the public to prepare and produce a document containing transmission data or subscriber information that is in the foreign entity's possession or control when it receives the request.
  • The justice or judge may authorize a peace officer or public officer to make the production request only if the justice or judge is satisfied by information on oath that there are reasonable grounds to suspect that an offence has been or will be committed under the Criminal Code or any other Act of Parliament; and the transmission data or the subscriber information is in the foreign entity's possession or control and will assist in the investigation of the offence.
  • The authorization must specify that a peace officer or public officer must not send a production request more than 30 days after the day on which the authorization is granted.
  • The production request may include any information that is required by the foreign entity, by the foreign state in which the foreign entity is located or under an international agreement or arrangement to which Canada and the foreign state are parties.
Q13 – With the ability to access cloud-based data through a device already in police possession, what measures will ensure that searches remain limited to the specific offence under investigation and do not inadvertently capture broader personal information
  • The law is clear that police searches must be limited to the authority to search in relation to the offence under investigation.
  • The proposed amendments to the Criminal Code's main search warrant (section 487) will not change this.
  • Should the police exceed their authority to search, this could be challenged by the defence as unauthorized and in excess of their authority and the court could impose remedies including exclusion of the evidence.
  • In addition, the Bill would require that a copy of the examination warrant be given to relevant persons, like the owner of the computer. This requirement provides transparency and supports full answer and defence in relation to investigations made under these warrants.
  • The Bill would also provide for the following limited exceptions to this requirement:
    • where the person already has a copy of the warrant
    • where the judge or justice who issues the warrant sets aside the requirement if they are satisfied that doing so is justified in the circumstances.
    • where a judge or justice extends the period within which a copy of the warrant shall be given, if the interests of justice warrant the granting of an extension, or a subsequent extension, of the period. No extension may exceed three years.

Part 2 – Anticipated Questions

Committee Notes

Q1 – What meaningful reporting and independent oversight mechanism would exist for ministerial orders, and why should Parliament accept that these powers will not be exercised without adequate scrutiny
  • To ensure robust oversight, the Intelligence Commissioner (IC) must review and pre-approve Ministerial Orders (MOs) before they are issued by the Minister of Public Safety to electronic service providers (ESPs).
  • The IC will provide an essential layer of accountability and transparency by ensuring that the Minister's decision to issue an MO is reasonable and proportionate.
  • The IC must also provide a copy of their decision to the National Security Intelligence Review Agency, which, at their discretion will be able to review the usage of the MO scheme.
  • Additionally, to enhance transparency and strengthen accountability, the Minister of Public Safety must publish an annual report on the activities taken under SAAIA during the previous calendar year, including on the issuance of MOs.
  • We are confident that this proposal brings the right balance between supporting effective investigations and privacy rights.
Q2 – What assurances can the government provide that Intelligence Commissioner reviews occur promptly, and why should ESPs accept Ministerial Orders when their options to challenge or appeal them appear limited or unclear
  • It is important to note that the analysis to support a MO will be led by the department of Public Safety Canada, not the requesting operational agency, and approvals will be sought from the Minister of Public Safety and the IC before an MO can be issued by the Minister of Public Safety to an ESP.
  • Underthe Intelligence Commissioner Act, the IC would be required to complete their review within 30 days or within any other period agreed to between the Minister and the Commissioner.
  • In terms of judicial challenges and appeal the administrative review process would be utilized.
  • The only condition is the requirement to wait at least 15 days before filing an application for judicial review, as the ESP must provide the Minister with written notice in advance, including a copy of the notice of application.
  • This is to allow the Minister, if needed, the time to ensure the confidentiality of sensitive information during the proceedings.
  • Otherwise, the judicial review would proceed as normal with the Federal Court.
Q3 – In light of 'expert' warnings that technical capabilities can create "back-door" vulnerabilities, what specific safeguards in Bill C-22 prevent harm to system security and private data
  • The Government of Canada does not support, nor does SAAIA require, the creation of "backdoors" or the weakening of electronic protections.
  • In fact, subsections 5(5) and 7(5) provide explicit safeguards that would ensure the Government cannot force ESPs to comply with regulatory requirements or MOs that would create systemic vulnerabilities or prevent them from being rectified.
  • This means that, if an ESP were to assess that they cannot comply with a requirement without introducing a systemic vulnerability into their electronic protections, which includes encryption, they would not have to abide by it.
  • A similar protection was implemented in Australia.
  • Moreover, both in the making of the regulations and the issuance of Ministerial Orders, the Government of Canada will be required by law to consult the impacted ESP and take into account the potential impact on cybersecurity and privacy protections.
Q4 – Would the government experts – like Communications Security Establishment - concur that there are no "back door" vulnerabilities created by this bill
  • Cyber security is a top-of-mind concern in the development of Canada's lawful access framework.
  • The Government of Canada does not support, nor does Bill C-22 require, the creation of "backdoors" or the weakening of other electronic protections.
  • Experts from across the Government, including the Communications Security Establishment (CSE), were consulted in the development of this Bill and its safeguards against systemic vulnerabilities.
  • What we heard from CSE was that the threat of malicious cyber activity already exists for organizations across Canada and that Bill C-22 will improve cyber security by driving consistency in lawful access approaches – moving away from Ad Hoc and voluntary solutions to standardized approaches that are managed at the enterprise level.
  • I want to stress that the Government will set requirements for electronic service providers, but will not impose a particular technical solution for them to abide by.
  • Bill C-22 does not alter the existing responsibility of electronic service providers to protect their networks from hacking or other unauthorized access.
  • This is why the Government already provides detailed technical guidance to Canadians on how to protect themselves against malicious cyber activity.
  • This is also why the legislation articulates the ability for electronic service providers to push back when they determine that a solution could introduce a systemic vulnerability – they know their systems and have a vested interest in keeping them secure.
Q5 – Will new lawful-access technical capabilities under Bill C-22 result in costs being shifted onto provinces, local law-enforcement agencies or the clients of the ESPs, and how will those financial pressures be managed
  • In the proposed regime there are two possible options where the government could consider creating funding mechanisms for those implicated, at the discretion of the Minister of Public Safety. First, in the case of the costs incurrent by ESP(s) related to a specific MO. Second, a fee scheme for law enforcement and CSIS to pay for their requests to implicated electronic service providers by the regime.
  • At present, we are focused on passing the Bill, which – as we all know – has been attempted many times.
Q6 – Given that many major ESPs are U.S.-based, what credible enforcement mechanisms does Bill C-22 rely on to ensure they actually comply with the legislation
  • Part 2: Supporting Authorized Access to Information Act (SAAIA) requirements apply to any ESP that conducts all or part of their business in Canada or offers services to persons in Canada, which would include providers based in another country, such as the United States.
  • However, the domestic laws of foreign ESPs and Canada's treaty obligations will be considered during the development of class definitions for core providers and their obligations. This type of work does not happen over night.
  • Additionally, to encourage and ensure compliance, Bill C-22 includes Administrative Monetary Penalties that range from a minimum of $50,000 to a maximum of $250,000 for each violation.
  • Offences would also be an option for particularly egregious contraventions. Upon summary conviction, fines would range from $100,000 to $500,000 for each offence.
Q7 – Based on the government's experience with other digital services measures (e.g., Open AI), what is the risk that large companies will simply refuse to comply or exit the Canadian market altogether
  • Similar requirements to develop and maintain technical capabilities for key electronic service providers have existed for decades in most other jurisdictions based on internationally developed standards. The Canadian Government's imposition of lawful access requirements would not be new for any of them. Canada is the outlier when it comes to a regulatory scheme.
  • Before the regulations for core providers are set or a Ministerial Order is issued, the Government will also be required to consult the concerned ESPs who would then be able to flag any issues.
  • To encourage and ensure compliance, Bill C-22 includes Administrative Monetary Penalties that range from a minimum of $50,000 to a maximum of $250,000 for each violation, which could be compounded daily.
  • Offences would also an option for particularly egregious contraventions. Upon summary conviction, fines would range from $100,000 to $500,000 for each offence.

Background Information

Technical Briefing Deck

Purpose of Bill C-22

  • Bill C-22, An Act respecting lawful access, aims to address fundamental gaps in Canada's lawful access framework by modernizing legal authorities to access information, and requiring that electronic service providers develop and maintain technical capabilities that would enable access to information pursuant to lawful authority.
  • The Criminal Code of Canada and the Canadian Security Intelligence Service (CSIS) Act already give criminal and intelligence investigators the authorities to obtain electronic information.
    • But this does not reflect the current technology driven society we live in.
  • Such authorities and capabilities exist in all other Five Eyes, the EU and all of their states and beyond.
  • Recently, roundtables were conducted with stakeholders including civil liberty and privacy advocates, academics, industry, victims' advocates, and police to identify potential amendments/refinements from previous proposals.

Legal Authority – Committee Notes

Why is timely authorized access to information important? (Part 1)
  • In terms of legal authorities (warrants and orders):
    • The online environment has made it easier – even facilitates – criminals/criminal activity and threat actors. However, Canada's legal tools to access information have not kept pace with changes in technology and jurisprudence.
    • Police and CSIS need these tools to investigate national security threats and organized crime: foreign interference, extortion, terrorist threats, child exploitation – to protect Canadians law enforcement need the right tools at the right time. These tools are the basic building blocks for the broader Criminal Code powers.
    • Canadian police services and CSIS are facing challenges in timely access to information and intelligence that is critical to their investigations.
How does C-22 address these issues? (Part 1)
  • Part 1 would modernize Canada's legal authorities:
    • Create a new confirmation of service demand to confirm, for example, the telecommunication service provider for a phone number.
    • Create a new production order to obtain name, address (i.e., subscriber information).
    • Update search warrant powers for computer searches.
    • Create a new authority for Canadian police to make a request to foreign electronic service providers, including social medias (e.g. Open AI)
    • Create a tool of international cooperation in criminal matters to facilitate obtaining the court-ordered production of specific electronic data at the request of Canada's foreign partners.
    • Provide clarifications for police use of unsolicited or voluntarily provided information, information that is publicly available, and obtaining information or data in exigent circumstances.
Amendments: Timely Access to Digital Information (Part 1)
  • Some of the substantial refinements to previous proposals, as a result of consultations:
    • Revising the "information demand" proposal,
      • New name – "confirmation of service demand" to better reflect the nature of the tool;
      • New limited scope:
        • Demand to "telecommunications service providers" only (e.g., internet access and telephone companies)
        • Only a yes/no confirmation of whether or not "telecommunications services" are provided or have been provided to the person or account identifier specified in the demand.
    • "Subscriber Information" definition: Narrowing the definition to information that may be used to identify the subscriber or client (name, address, phone number, email) and the services provided.
    • Production Order review process: Revising the application for review of production orders to change the period of 5 days to a period of 10 business days.
Operational Examples for Part One
  • A victim comes to the police to complain about being sextorted on Instagram, a US-based company. Existing tools to request information from foreign companies are lengthy and complicated. This significantly slows down the identification of a perpetrator who is using a false identity or pseudonym on Instagram. The new tools proposed in Part 1 would provide police with:
    • A new authority (judicial authorization from a Canadian judge), to request Instagram to provide the IP address associated with the threatening communication;
    • A confirmation of service demand, so that police can identify the Canadian telecommunications service provider who is most likely in possession of subscriber information related to the IP address; and
    • A production order for subscriber information to compel the Canadian telecommunications service provider to produce the name, address and phone number of the alleged perpetrator.

Technical capabilities – Committee Notes

In terms of technical capabilities (Part 2)
  • Canada is the only Western democracy that does not have a legal framework requiring electronic service providers to develop and maintain technical capabilities.
  • Aside from an outdated licensing scheme from the 90's, collaboration between Canadian police services, CSIS, and electronic services providers is only on a voluntary basis with individually negotiated contracts and no set standards, creating an uneven playing field across these providers.
    • For example, no coverage of satellite services and inconsistent location tracking.
  • As Canada struggles to obtain basic capabilities for phone location and interception, other countries are advancing tools for vehicles, satellites, and emerging tech like 6G. Canada risks an increasing reputation of being a haven for criminal and threat actor communication activities.
How does C-22 address these issues? (Part 2)

Part 2 would ensure that technical capabilities are in place.

  • Establish baseline requirements for "core providers" (such as telecommunication service providers) to develop and maintain technical capabilities aligned with international standards so that they are able to respond to lawful access requests quickly and accurately.
  • Empower the Minister of Public Safety to issue flexible and targeted Ministerial Orders (MOs) compelling an electronic service provider to develop and maintain specific capabilities. MOs would be based on operational needs, as new technologies develop, and could be issued to both non-core and core providers.
  • Create enforcement tools for Public Safety Canada to ensure compliance. Should an electronic service provider be found non-compliant with its obligations, the Minister could apply monetary penalties or regulatory offences.
Amendments: Part 2 Supporting Authorized Access to Information Act (SAAIA)
  • Refinements after consultations:
    • Ministerial Orders (MOs) are now subject to approval by the Intelligence Commissioner, and privacy and cybersecurity are explicit factors for consideration.
    • The same factors that must be considered for MOs must now also be considered by the Governor in council when making regulations for the core providers.
    • Clarification that data retention requirements can be imposed only for metadata, for a one year maximum, but not content, web-browsing history or social media history.
    • Additional parameters have been added for the inspection powers, the obligation to assist, and the confidentiality and security regulations.
    • Clarification that information provided as part of an internal audit or obtained during an inspection must be kept confidential by designated persons.
    • Subsection 15(g), which has been interpreted as prohibiting the disclosure of information related to a potential systemic vulnerability, has been removed.
    • Public annual reporting has been included as a legislative requirement.
    • Systemic vulnerability is now defined in the statute.
Operational Examples for Part Two
CSIS cannot track a cellphone (Part 2)
  • CSIS is trying to determine the movements of a terrorist group and has received a warrant to track a person of interest's cellphone. The electronic service provider did not have the necessary capabilities to track the device because they are not required to. As a result, CSIS had to resort to costly and risky in-person surveillance.
  • With C-22: The GIC will have the authority to make regulations requiring that ESPs develop and maintain location tracking capabilities that are standard in Europe and among the Five Eyes.
Police cannot consistently obtain location information (Part 2)
  • An at-risk 16-year-old girl was reported missing. She had already been missing for 10 days when she made an emergency call. The telecommunications provider was able to confirm the call and the tower used to make the call but could not provide the last known location of the phone before it was disconnected since they are not required to have that capability.
  • With C-22: Core providers would be required to maintain accurate and consistent localization capabilities across the country.

Conclusion

  • This proposed legislation will, if enacted, help to keep Canadians safe by ensuring law enforcement has the right investigative tools to strengthen our response to increasingly sophisticated criminal networks and to combat transnational organized crime, while maintaining robust safeguards including Charter protections.
  • Further information about the new proposed legislation can be found on the Government of Canada website.
Date modified: