This is a single speech (committee meeting) resource from the openparliament.ca API. If you’re new here, you might want to look at the documentation. If API and JSON are gibberish to you, you’re better off at our main site.

Content

Get this resource as raw JSON.

See the corresponding webpage.

{
    "time": "2023-10-26 15:45:00",
    "attribution": {
        "en": "Prof. Colin Bennett (Professor, Political Science, Unversity of Victoria, As an Individual)",
        "fr": "M. Colin Bennett (professeur, \u00c9tudes Politiques, Universit\u00e9 de Victoria, \u00e0 titre personnel)"
    },
    "content": {
        "en": "<p data-HoCid=\"8007788\" data-originallang=\"en\">Thank you very much, Mr. Chair.</p>\n<p data-HoCid=\"8007789\" data-originallang=\"en\">I'm from the University of Victoria, although I'm currently in Australia. I wish everybody a good day.</p>\n<p data-HoCid=\"8007790\" data-originallang=\"en\">I would like to emphasize five specific areas for reform of the CPPA and to suggest ways in which the bill might be brought into better alignment with Quebec's law 25. I don't think that Bill <a data-HoCid=\"11873796\" href=\"/bills/44-1/C-27/\" title=\"An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts\">C-27</a> should be allowed to undermine Quebec law, and in some respects, it does. I also think these are some of the areas where the bill will be vulnerable when the European Commission comes to evaluate whether Canadian law continues to provide an adequate level of protection.</p>\n<p data-HoCid=\"8007791\" data-originallang=\"en\">Some of these recommendations are taken from the report that you have from the Centre for Digital Rights, which I'd like to commend to you.</p>\n<p data-HoCid=\"8007792\" data-originallang=\"en\">First, I believe that CPPA's proposed section 15, on consent, is confusing to both consumers and businesses. In particular, I question the continued reliance on \u201cimplied consent\u201d in proposed subsection 15(5), which states, \u201cConsent must be expressly obtained unless...it is appropriate to rely on an individual's implied consent\u201d.</p>\n<p data-HoCid=\"8007793\" data-originallang=\"en\">The bill enumerates those business activities for which consent is not required, including if \u201cthe organization has a legitimate interest that outweighs any potential adverse effect on the individual\u201d. That's a standard that has been imported from the GDPR. However, in the GDPR, \u201cconsent\u201d means express consent; it's \u201cfreely given, specific, informed and unambiguous\u201d.</p>\n<p data-HoCid=\"8007794\" data-originallang=\"en\">In the current version of the CPPA, businesses can have it both ways. They can declare that they have implied consent because of some inaction that a consumer allegedly took in the past because of not reading the legalese in a complex terms-of-service agreement, or they can assert a \u201clegitimate interest\u201d in the personal data by claiming that there is no \u201cpotential adverse effect on the individual\u201d. That is a risk assessment performed by the company rather than a judgment made about the human rights of individuals to control their personal information. </p>\n<p data-HoCid=\"8007795\" data-originallang=\"en\">In that respect, it's really important that the bill be brought within a human rights framework. There should be no room for implied consent in this legislation. It's a dated idea that creates confusion for both consumers and businesses.</p>\n<p data-HoCid=\"8007796\" data-originallang=\"en\">Second, there is no section in the CPPA on international data transfers. I find that very odd. I know of no other modern privacy law that fails to give businesses proper guidance on what they have to do if they want to process personal data offshore. The only requirement is for the organization to require the service provider, \u201cby contract or otherwise,\u201d to ensure \u201ca level of protection of the personal information equivalent to that which the organization is required to provide under this Act.\u201d That's proposed subsection 11(1) of the CPPA.</p>\n<p data-HoCid=\"8007797\" data-originallang=\"en\">That due diligence applies whether the business is transferring personal data to another province in Canada or overseas to a country that may or may not have strong privacy protection or, indeed, a record of the protection of human rights. That's particularly troubling because of proposed section 19 of the CPPA, which reads, \u201cAn organization may transfer an individual's personal information to a service provider without their knowledge or consent.\u201d</p>\n<p data-HoCid=\"8007798\" data-originallang=\"en\">The Canadian government has never gotten into the business of adopting a safe harbour approach or a white list, and I'm not recommending that. However, Quebec, I believe, has legislated an appropriate compromise under section 17 of law 25, which requires businesses to do an assessment, including of the legal framework, when sending personal data outside of Quebec. As many businesses will have to comply with the Quebec legislation, why not mirror that provision in Bill <a data-HoCid=\"11873796\" href=\"/bills/44-1/C-27/\" title=\"An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts\">C-27</a>?</p>\n<p data-HoCid=\"8007799\" data-originallang=\"en\">Third, the bill ignores important accountability mechanisms that were pioneered in Canada and exported to other jurisdictions, including Europe. Therefore, it's very strange that those same measures do not appear in the CPPA. In particular, privacy impact assessments are an established instrument and a critical component of accountable personal data governance, and they should be required in advance of product or service development, particularly where invasive technologies and business models are being applied, where minors are involved, where sensitive personal information is being collected, or where the processing is likely to result in a high risk to an individual's rights and freedoms. Businesses do the PIAs, and they stand ready to demonstrate their compliance or their accountability to the regulator.</p>\n<p data-HoCid=\"8007800\" data-originallang=\"en\">A fourth and related problem is the absence of any definition of sensitive forms of personal data. The word \u201csensitivity\u201d appears throughout the legislation in several provisions of the bill, but with the exception of the specification about data on minors, it is nowhere defined. In my view, the bill should define what \u201csensitive information\u201d means, and it should also enumerate a non-exhaustive list of categories, which, in fact, occurs in many forms of legislation.</p>\n<p data-HoCid=\"8007801\" data-originallang=\"en\"> Finally\u2014I know you've heard about this in the past, and I've researched on this\u2014the absence of proper privacy standards for federal political parties is unjustifiable and untenable. The government is relying on the argument that the FPPs\u2019 privacy practices are regulated under the Elections Act, but those provisions are nowhere near as strong as in Bill <a data-HoCid=\"11873796\" href=\"/bills/44-1/C-27/\" title=\"An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts\">C-27</a>. I think businesses resent the fact that parties are exempted. This is not an issue that will go away, given advances in technology and its use in modern digital campaigning. Canada is one of the few countries in the world in which political parties are not covered by applicable privacy law.</p>\n<p data-HoCid=\"8007802\" data-originallang=\"en\">Thank you so much.</p>",
        "fr": "<p data-HoCid=\"8007788\" data-originallang=\"en\">Merci beaucoup, monsieur le pr\u00e9sident.</p>\n<p data-HoCid=\"8007789\" data-originallang=\"en\">Je suis rattach\u00e9 \u00e0 l'Universit\u00e9 de Victoria, mais je me trouve actuellement en Australie. Bonjour \u00e0 tous.</p>\n<p data-HoCid=\"8007790\" data-originallang=\"en\"> J'aimerais mettre l'accent sur cinq domaines pr\u00e9cis de la r\u00e9forme de la Loi de la protection de la vie priv\u00e9e des consommateurs, la LPVPC, et sugg\u00e9rer des fa\u00e7ons de mieux harmoniser le projet de loi avec les nouvelles dispositions prot\u00e9geant la vie priv\u00e9e des Qu\u00e9b\u00e9cois, la loi 25. Il faut veiller \u00e0 ce que le projet de loi <a data-HoCid=\"11873796\" href=\"/bills/44-1/C-27/\" title=\"An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts\">C\u201127</a> ne porte pas atteinte \u00e0 la loi qu\u00e9b\u00e9coise, comme le font certaines dispositions actuelles. J'estime \u00e9galement que certains domaines rendent le projet de loi vuln\u00e9rable lorsque vient le temps pour la Commission europ\u00e9enne d'\u00e9valuer si le droit canadien continue d'offrir un \u00ab niveau ad\u00e9quat de protection \u00bb.</p>\n<p data-HoCid=\"8007791\" data-originallang=\"en\">Certaines des recommandations qui suivent sont tir\u00e9es du rapport du Centre pour les droits num\u00e9riques, qui vous a \u00e9t\u00e9 remis et dont je vous recommande fortement la lecture.</p>\n<p data-HoCid=\"8007792\" data-originallang=\"en\">Premi\u00e8rement, je crois que l'article 15 de la LPVPC, qui porte sur le consentement, porte \u00e0 confusion tant pour les consommateurs que pour les entreprises. Je m'interroge en particulier sur le fait que l'on continue de s'appuyer sur le \u00ab consentement implicite \u00bb au paragraphe 15(5), qui stipule que le consentement doit \u00eatre \u00ab obtenu express\u00e9ment \u00bb, \u00e0 moins qu'il ne soit \u00ab appropri\u00e9 de pr\u00e9sumer le consentement implicite de l'individu \u00bb.</p>\n<p data-HoCid=\"8007793\" data-originallang=\"en\">Le projet de loi \u00e9num\u00e8re les activit\u00e9s commerciales pour lesquelles le consentement n'est pas requis, notamment si l'organisation a \u00ab un int\u00e9r\u00eat l\u00e9gitime qui l'emporte sur tout effet n\u00e9gatif que la collecte ou l'utilisation peut avoir pour l'individu \u00bb, une norme provenant du R\u00e8glement g\u00e9n\u00e9ral sur la protection des donn\u00e9es, le RGPD. Cependant, dans le RGPD, le consentement signifie le consentement expr\u00e8s, qui est librement donn\u00e9, pr\u00e9cis, \u00e9clair\u00e9 et sans ambigu\u00eft\u00e9.</p>\n<p data-HoCid=\"8007794\" data-originallang=\"en\">Dans la version actuelle de la LPVPC, les entreprises peuvent jouer sur les deux tableaux. Elles peuvent d\u00e9clarer qu'elles ont un \u00ab consentement implicite \u00bb en raison d'une certaine inaction qu'un consommateur aurait commise dans le pass\u00e9 parce qu'il n'a pas lu le jargon juridique des conditions g\u00e9n\u00e9rales d'utilisation complexes. Elles peuvent \u00e9galement affirmer un \u00ab int\u00e9r\u00eat l\u00e9gitime \u00bb \u00e0 l'\u00e9gard des donn\u00e9es personnelles, et pr\u00e9tendre qu'il n'y a pas d'effet pr\u00e9judiciable potentiel pour la personne. Il s'agit d'une \u00e9valuation des risques effectu\u00e9e par l'entreprise, plut\u00f4t que d'un jugement portant sur le droit des personnes de contr\u00f4ler leurs renseignements personnels.</p>\n<p data-HoCid=\"8007795\" data-originallang=\"en\">\u00c0 cet \u00e9gard, il serait important que le projet de loi s'inscrive dans un cadre des droits de la personne. La notion de consentement implicite n'a pas sa place dans ce projet de loi. C'est une id\u00e9e d\u00e9pass\u00e9e, qui cr\u00e9e de la confusion chez les consommateurs autant que chez les entreprises.</p>\n<p data-HoCid=\"8007796\" data-originallang=\"en\">Deuxi\u00e8mement, la LPVPC ne contient aucune disposition sur les transferts internationaux de donn\u00e9es, ce qui est particuli\u00e8rement \u00e9trange. Je ne connais aucune autre loi moderne sur la protection des renseignements personnels qui ne donne pas aux entreprises des directives appropri\u00e9es sur ce qu'elles doivent faire si elles veulent traiter des donn\u00e9es personnelles \u00e0 l'\u00e9tranger. La seule exigence est que l'organisation oblige le fournisseur de services, \u00ab par contrat ou autrement \u00bb, \u00e0 assurer une protection des renseignements personnels \u00ab \u00e9quivalente \u00e0 celle qu'elle est tenue d'offrir sous le r\u00e9gime de la pr\u00e9sente loi \u00bb, tel qu'il est \u00e9nonc\u00e9 au paragraphe 11(1) de la LPVPC.</p>\n<p data-HoCid=\"8007797\" data-originallang=\"en\">Cette obligation de diligence s'applique, que l'entreprise transf\u00e8re des donn\u00e9es personnelles \u00e0 une autre province du Canada ou \u00e0 l'\u00e9tranger, dans un pays qui peut ou non avoir une solide protection de la vie priv\u00e9e ou un registre en mati\u00e8re de protection des droits de la personne. C'est particuli\u00e8rement troublant si on consid\u00e8re qu'il est pr\u00e9vu \u00e0 l'article 19 de la LPVPC que \u00ab l'organisation peut transf\u00e9rer \u00e0 des fournisseurs de services les renseignements personnels d'un individu \u00e0 son insu ou sans son consentement \u00bb.</p>\n<p data-HoCid=\"8007798\" data-originallang=\"en\">Le gouvernement canadien n'a jamais adopt\u00e9 une approche de \u00ab sph\u00e8re de s\u00e9curit\u00e9 \u00bb ou de liste blanche, et ce n'est pas ce que je pr\u00e9conise. Pourtant, selon moi, le Qu\u00e9bec a trouv\u00e9 un compromis acceptable \u00e0 l'article 17 de la loi 25, qui oblige les entreprises \u00e0 faire une \u00e9valuation, y compris du cadre juridique, lorsqu'elles envoient des renseignements personnels \u00e0 l'ext\u00e9rieur du Qu\u00e9bec. Puisque de nombreuses entreprises canadiennes devront se conformer \u00e0 la loi qu\u00e9b\u00e9coise, pourquoi ne pas reproduire cette disposition dans le projet de loi <a data-HoCid=\"11873796\" href=\"/bills/44-1/C-27/\" title=\"An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts\">C\u201127</a>?</p>\n<p data-HoCid=\"8007799\" data-originallang=\"en\">Troisi\u00e8mement, le projet de loi ne tient pas compte des importants m\u00e9canismes de reddition de comptes qui ont \u00e9t\u00e9 mis au point au Canada et export\u00e9s dans d'autres pays, notamment en Europe. Il est donc tr\u00e8s \u00e9trange que certaines de ces mesures ne figurent pas dans la LPVPC. En particulier, les \u00e9valuations des facteurs relatifs \u00e0 la vie priv\u00e9e, ou EFVP, sont un instrument \u00e9tabli et une composante essentielle de la gouvernance responsable des donn\u00e9es personnelles, et elles devraient \u00eatre requises avant l'\u00e9laboration de produits ou de services, particuli\u00e8rement lorsque des technologies envahissantes et des mod\u00e8les d'affaires entrent en jeu, lorsque des mineurs sont concern\u00e9s, lorsque des renseignements personnels sensibles sont recueillis et lorsque le traitement est susceptible d'entra\u00eener un risque \u00e9lev\u00e9 pour les droits et libert\u00e9s d'une personne. Les entreprises effectuent les EFVP et sont pr\u00eates \u00e0 attester leur conformit\u00e9 ou leur volont\u00e9 de reddition de comptes \u00e0 l'instance de r\u00e9glementation.</p>\n<p data-HoCid=\"8007800\" data-originallang=\"en\">Un quatri\u00e8me probl\u00e8me li\u00e9 se pose, soit l'absence de d\u00e9finition des \u00ab formes de donn\u00e9es personnelles sensibles \u00bb. Le terme \u00ab sensible \u00bb revient dans plusieurs dispositions du projet de loi mais, outre la mention expresse des donn\u00e9es concernant des personnes mineures, cette notion n'est d\u00e9finie nulle part. Le projet de loi devrait pr\u00e9ciser ce qui est entendu par \u00ab renseignements de nature sensible \u00bb, et il devrait contenir \u00e9galement une liste non exhaustive de cat\u00e9gories, qui par ailleurs sont utilis\u00e9es dans plusieurs mesures l\u00e9gislatives.</p>\n<p data-HoCid=\"8007801\" data-originallang=\"en\">Enfin, et je sais que vous l'avez d\u00e9j\u00e0 entendu \u2014 j'ai fait mes recherches \u2014, l'absence de normes appropri\u00e9es en mati\u00e8re de protection de la vie priv\u00e9e pour les partis politiques f\u00e9d\u00e9raux est injustifiable et inacceptable. Le gouvernement s'appuie sur l'argument comme quoi les pratiques en mati\u00e8re de protection de la vie priv\u00e9e des partis politiques f\u00e9d\u00e9raux sont r\u00e9glement\u00e9es en vertu de la Loi sur la modernisation des \u00e9lections de 2018, ce qui rend leur inclusion dans le projet de loi inutile. Toutefois, les dispositions de cette loi ne sont qu'une p\u00e2le imitation des dispositions du projet de loi <a data-HoCid=\"11873796\" href=\"/bills/44-1/C-27/\" title=\"An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts\">C\u201127</a>. Je pense que les entreprises n'appr\u00e9cient gu\u00e8re que les partis politiques soient exempt\u00e9s. Ce probl\u00e8me ne dissipera pas, compte tenu des progr\u00e8s de la technologie et de son utilisation dans les campagnes num\u00e9riques modernes. Le Canada est un des rares pays d\u00e9mocratiques o\u00f9 les lois sur la protection des renseignements personnels ne s'appliquent pas aux partis politiques et aux renseignements de nature sensible sur les opinions politiques.</p>\n<p data-HoCid=\"8007802\" data-originallang=\"en\">Merci beaucoup.</p>"
    },
    "url": "/committees/industry/44-1/92/prof-colin-bennett-1/",
    "politician_url": null,
    "politician_membership_url": null,
    "procedural": false,
    "source_id": "12397099",
    "document_url": "/committees/industry/44-1/92/",
    "related": {
        "document_speeches_url": "/speeches/?document=%2Fcommittees%2Findustry%2F44-1%2F92%2F"
    }
}