The committee studied Bill C-8, which proposes cybersecurity and critical infrastructure protections, hearing from Kate Robertson, John de Boer, Matthew Hatfield, Todd Warnell, and Francis Bradley.
Kate Robertson, a lawyer and researcher at Citizen Lab, argued that Bill C-8 lacks explicit protections for encryption, warning that broad ministerial powers under proposed section 15.2 could be used to compromise encryption for surveillance, despite government assurances. She also highlighted a constitutional deficit in the warrantless collection power under section 15.4, recommending Federal Court authorization for collecting personal or de-identified information, and agreed with the Privacy Commissioner that current safeguards are inadequate.
John de Boer of BlackBerry strongly supported Bill C-8, especially part 2, noting Canada is the only G7 country without mandatory cyber-incident reporting for critical infrastructure. He recommended clear definitions of reportable incidents, tiered reporting within 72 hours, secure tools for communication, liability protections for good-faith reporting, and business continuity requirements, drawing on examples from the U.S., Europe, and Australia.
Matthew Hatfield of OpenMedia criticized Bill C-8 for giving ministers unchecked power to issue secret orders to telecom providers without independent review, calling the current oversight "accountability theatre." He urged amendments requiring judicial and technical expert review of orders, explicit prohibitions on weakening encryption, rapid destruction of incidentally collected personal information, and greater public and NSICOP disclosure, disagreeing with the view that judicial review alone is a sufficient safeguard.
Todd Warnell of Bruce Power emphasized the urgency of Bill C-8, citing real-world threats from nation-state actors pre-positioned in critical infrastructure. He supported the legislation as a necessary first step for proactive risk management and speed of response, and recommended clearer separation between the Canadian Centre for Cyber Security's technical role and sector regulators' responsibilities to ensure coordinated responses.
Francis Bradley of Electricity Canada supported the bill's objectives but raised concerns about potential chilling effects on information sharing due to a lack of safe harbour protections, and risks to existing collaborative relationships with the Cyber Centre if shared information could be used for regulatory enforcement. He also warned of duplicative regulatory frameworks for the electricity sector, which already follows NERC standards, and proposed amendments to mandate recognition of equivalent existing standards rather than leaving it optional.
The committee debated a motion to invite the Minister of Industry to appear before proceeding to clause-by-clause on Bill C-8, with an amendment proposed to set a deadline of January 30, 2026, for the appearance and to schedule clause-by-clause immediately after, with no other business until completion. The discussion was adjourned.
AI-generated summary — may contain errors; verify against the official evidence.