Appearance before the Standing Committee on Public Safety and National Security (SECU) Bill C-22, An Act respecting lawful access - May 5 and 28, 2026
Part 1
- Bill C-22 does not change the type of information that CSIS can collect without a warrant, nor would it expand CSIS’s mandate. C-22 will provide a critical building block for CSIS to be able to advance more efficiently through the initial stages of an investigation.
- Instead, C-22 will:
- Include a modification to the CSIS Act, which creates a confirmation of service provision that would allow CSIS to compel telecommunication service providers confirm whether they provide a service to a particular person or number.
- Permit CSIS to make a confirmation of service demand in the context of national security investigations where:
- they have reasonable grounds to suspect that an offence has been or will be committed,
- there is a threat to the security of Canada,
- and that the information that is demanded will assist in the investigation.
- A clarification clause in Bill C-22 makes it clear that CSIS can continue to receive and act on information that is voluntarily provided to them, including by service provider.
Part 2
- In addition to the confirmation of service demand, C-22 will look to develop a lawful access framework that would compel electronic service providers to maintain the technical capabilities required to enable lawful access to authorized information (e.g., communication intercepts, necessary infrastructure).
- This will be done by implementing the Supporting Authorized Access to Information Act (SAAIA).
- Canada is the only country among our Five Eyes and EU partners without such authorities and capabilities.
- This inability to keep pace with the changing technological environment has also caused Canada to rely frequently on foreign allies for national security tips and leads.
- The tools in this bill will enables us to be a better partner.
- The CSIS Act amendments were designed to balance the privacy interests of impacted persons, while providing CSIS with the minimal appropriate tools.
- This will provide a major building block to pursue judicially authorized communication intercepts, which may be crucial in advancing a national security investigation.
C-22: Case Studies (CSIS)
Part 1
- A CSIS subject of investigation is planning to travel to an ideologically motived violent extremism-related para-military training event.
- CSIS is aware that the threat actor uses a social media account associated with a Canadian phone number to share the agenda and other information related to the event. CSIS plans to seek a production order from the Federal Court to advance the investigation and intercept the subject of investigation’s communications, but to do so CSIS must establish which provider has this information. The proposed amendment would allow CSIS to require a telecommunications service provider to confirm service and enable CSIS to seek judicial authorization to proceed with the investigation.
Part 2
- CSIS cannot track a cellphone
- CSIS is trying to determine the movements of a terrorist group and has received a warrant to track a person of interest’s cellphone. The electronic service provider did not have the necessary capabilities to track the device because they are not required to. As a result, CSIS had to resort to costly and risky in-person surveillance.
- With C-22: The GIC will have the authority to make regulations requiring that ESPs develop and maintain location tracking capabilities that are standard in Europe and among the Five Eyes.
- CSIS is unable to support valuable partners
- CSIS has received information from a foreign partner carrying out an investigation outside of Canada where a few of their subjects of investigation are associated with Canadian phone numbers. The foreign partner has further highlighted that, based on their intelligence, the threat activity may be moving into Canadian territory.
- CSIS has been able to confirm that these phone numbers were obtained through a reseller that does not maintain records of its sales, nor does it track any of the clients’ activity. CSIS is unable to respond to the foreign partner and risks not being sighted on a threat directly affecting Canada.
- Under C-22, during the development of regulations resellers would be brought into the process to address this barrier.
- SAAIA Example: ESP does not collect/retain data
- CSIS is investigating a target whose device needs to be intercepted to gather evidence in a terrorism investigation. A warrant has been approved by the Federal Court to take this action. The ESP working with CSIS to intercept the device does not collect or retain historic or current location-based data associated with its mobile phones.
- With the current framework, the company cannot be compelled to maintain this capability, which is critical for investigators to receive under warrant in a national security investigation-particularly in cases of terrorism. So, CSIS is required to maintain resource-intensive, round-the-clock physical surveillance on the individual, which increases the risk of tipping off the subject or losing sight of them, leaving Canada and Canadians less safe.
- With SAAIA, the ESP would be required to maintain the technical capabilities to be intercept-capable, ensuring much more effective, predictable, and ultimately successful investigative outcomes for CSIS.