Last week, the government announced that Canada has signed the United Nations Convention against Cybercrime, with Ministers Anita Anand, Gary Anandasangaree and Sean Fraser touting the treaty’s child protection provisions and human rights safeguards, which were described as “among the strongest found in an international criminal justice treaty.” The announcement, released in mid-July with few paying attention, left out much of the story. The reality is that the convention is not primarily a cybercrime treaty at all, but rather a sweeping cross-border surveillance and electronic evidence-sharing agreement that Canada originally opposed, that leading human rights groups and twenty Canadian organizations and experts urged the government to reject, and that key allies have thus far declined to sign. While signing the convention does not create binding obligations (that requires ratification), the decision to sign a treaty that the government declined to sign at the official ceremony less than a year ago raises troubling questions. This post seeks to answer three of them: what is this treaty, what are the risks, and what, if anything, changed in the last nine months?
Post Tagged with: "surveillance"
Rushing Lawful Access Backfires: Wyden Letter on Bill C-22 Highlights Political, Trade and Business Risks
Public Safety Minister Gary Anandasangaree and the government presumably hoped that pushing Bill C-22 through a House of Commons committee past midnight without debate or a recorded vote would put an end to the lawful access controversy. A new letter from U.S. Senator Ron Wyden, the ranking Democrat on the Senate Finance Committee that holds jurisdiction over trade, suggests the opposite. The letter, released last week, calls on the U.S. administration to treat Canada’s lawful access plans as a counterintelligence threat, to use the CLOUD Act negotiations as leverage, and to take regulatory steps to insulate American officials from surveillance demands directed at U.S. companies. Coming just weeks after House Judiciary Committee chair Jim Jordan and House Foreign Affairs Committee chair Brian Mast warned that the bill harms U.S. national security and economic interests, the letter confirms that Bill C-22 has become a bilateral irritant with the potential to emerge as a full-blown trade issue. Given the latest threats of new tariffs, lawful access could add yet another complication in the increasingly fraught trade relationship.
The Data on Australia’s Social Media Ban: The Better the Privacy Protection, The Less Effective the Ban
As regular readers know, the Canadian plan to establish a social media ban for under 16s in Bill C-34 is based largely on the Australian model that took effect last December. With more data on the ban’s effectiveness continuing to roll in, multiple studies now confirm that it simply hasn’t worked as the majority of under-age users still have access to social media accounts. Yet rather than treating that as a reason to reconsider the model, Australian Prime Minister Anthony Albanese told Parliament in late June that his government is working “as a priority” to strengthen the law. The failure highlights a troubling correlation: the better the privacy protection, the less effective the ban. In other words, since users will find ways to circumvent the ban, “strengthening” the law likely means less privacy and more surveillance.
The Lawful Access Two-Headed Surveillance Monster: How Bill C-22 Went Off the Rails
The government’s plans for lawful access have gone off the rails. In recent days, Signal has warned it would pull out of the Canadian market rather than comply with Bill C-22. Windscribe, the Toronto-headquartered VPN provider, has said it would relocate its headquarters out of Canada and NordVPN has warned it would consider following suit. Apple and Meta have both raised public concerns about the bill’s effect on encryption and cybersecurity. The Canadian Chamber of Commerce, the Cybersecurity Advisors Network, civil liberties groups, and a long line of legal and security experts have all called for changes. The chairs of the U.S. House Judiciary and Foreign Affairs Committees have written to Public Safety Minister Gary Anandasangaree warning that the bill threatens U.S. national security and the integrity of cross-border data flows. Even the bill’s own oversight body, the National Security and Intelligence Review Agency, has told the SECU committee it does not have the access it needs for effective oversight. If the government thought it could push through the bill largely unnoticed, it has been proven painfully wrong as there are now trade frictions with the U.S., the prospect of leading companies exiting the Canadian market, and weaker cybersecurity protections for ordinary users.
How did Canada’s lawful access plan go awry so quickly?
More Surveillance Demands to Come?: Government Admits Bill C-22’s Lawful Access Provisions Could Be Expanded
Debate on Bill C-22, the Lawful Access Act, continued this week with Public Safety Minister Gary Anandasangaree and Secretary of State for Combatting Crime Ruby Sahota leading the government’s case on Wednesday. I posted earlier on the first day of debate, which was notable for what the government chose not to say, as Justice Minister Fraser devoted just a single paragraph to the bill’s expansive metadata retention provisions and offered only process answers to questions about systemic vulnerability risks. The government continues to do its best to ignore the metadata issue, but the most alarming outcome of the debate was the admission that the current bill may only be the starting point, with support for an even broader scope in follow-up regulations or legislation.











