SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • June 20, 2023
  • Rss Fetcher

Parliament must limit government powers over the private sector in the proposed Canadian cybersecurity legislation, say several civil rights groups, arguing the current version risks eroding civil liberties, privacy, and democratic freedoms.
The call came today from the Canadian Civil Liberties Association, the Canadian Constitution Foundation, the International Civil Liberties Monitoring Group, Ligue des Droits et Libertés, the National Council of Canadian Muslims, OpenMedia, and the Privacy and Access Council of Canada.
“We can address Canada’s cybersecurity needs, while upholding our rights and freedoms,” the group said in a statement accompanying detailed recommendations for fixing the Liberal government’s proposed cybersecurity legislation, Bill C-26.
The proposed bill has been referred to the House of Commons Public Safety Committee for testimony from witnesses, but a start date hasn’t been set yet.
In an email, Daniel Konikoff, director of the Canadian Civil Liberties Association’s privacy, technology, and surveillance program, said that “our hope is that the remedy package gives MPs some food for thought over the next few months, before the Committee begins reviewing Bill C-26 after the [summer] recess.”
As it stands, the proposed legislation opens to the door new surveillance obligations telcos would have to follow, gives the Communications Security Establishment (CSE) — the government’s electronic spy agency — power without accountability, and allows secret evidence to be heard in courts, the rights groups say.
“Allowing elected representatives or unelected, unaccountable bureaucrats the degree of power that Bill C-26 does is an assault on democracy and a clear and present danger to Canadians’ freedom, privacy, and autonomy,” Sharon Polsky, president of the Privacy and Access Council of Canada, said in the statement.
Formally known as An Act Respecting Cyber Security, C-26 has two parts:
— amendments to the Telecommunications Act, which oversees telecom and internet providers. If passed unchanged, it would allow the government to create regulations directing providers to do anything necessary to secure their systems against anything, including the threat by an attacker of interference, manipulation or disruption.
Without narrowing the grounds “this opens the door to imposing surveillance obligations on private companies, and to other risks such as weakened encryption standards — something the public has long rejected as inconsistent with our privacy rights,” say the rights groups;
— the Critical Cyber Systems Protection Act (CCSPA), which provides a framework for the protection of critical cyber systems vital to national security or public safety that are under federal jurisdiction. If passed unchanged, it would require designated operators to, among other things, establish and implement cyber security programs if they haven’t already done so, mitigate supply-chain and third-party risks, report cyber security incidents and comply with cyber security directions; and exchange of information with government agencies.
In response, the rights groups say Bill C-26 “lacks mandatory proportionality, privacy, or equity assessments, or other guardrails, to constrain abuse of the new powers it grants
the government — powers accompanied by steep fines or even imprisonment for non-compliance. These orders apply both to telecommunications companies and to a wide range of other federally-regulated companies and agencies designated under the Critical Cyber System Protection Act. Prosecutions can be launched in respect of alleged violations of Security Orders which happened up to three years in the past.”
The proposed narrowing of the legislation made by the rights groups largely mirrors recommendations made last October by Christopher Parsons, a senior research associate at the Citizen Lab, part of the University of Toronto’s Munk School of Global Affairs and Public Policy.
So, for example, the rights groups would limit the Industry Minister’s ability under the Telecommunications Act to issue an action order to a telco only if there is evidence of a threat of interference, manipulation or disruption to their systems. The current wording says the Minister could issue an order for any reason, including interference threats or disruption of their systems.
Similarly, the cabinet would be limited under the CCSPA to direct any designated operator or class of operators of a federally-regulated sector to take action to protect a critical cyber system only if there is a material threat. The current wording leaves the cabinet free to make an order for any reason.
In addition to wanting changes to restrain the powers of cabinet, the rights groups want amendments to protect confidential personal and business information from being accessed by Ottawa, to allow special advocates to be appointed to protect the public interest and to enhance the accountability of the Communications Security Establishment.The post Government powers under Canada’s proposed cybersecurity law should be limited: Rights groups first appeared on IT World Canada.

Previous Post
Next Post

Recent Posts

  • Aveshan Aiyer on How the Channel Powers Proactive Cybersecurity
  • Is AI the New Con Artist? Unmasking Social Engineering 2.0
  • For the love of God, stop calling your AI a co-worker
  • Elon Musk tries to stick to spaceships
  • Thousands of Netflix fans gather for Tudum

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • June 2025
  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.