In a recent Lawfare article, Richard Salgado argues that by pursuing discredited and dangerous surveillance powers, Canada is putting in peril the legal investigative tool it needs most, a Canada-U.S. CLOUD Act agreement. Salgado contends that the anti-security powers in Part 2 of Canada’s Bill C-22 threaten cybersecurity interests that the United States considers critical in determining whether another country qualifies for the benefits of a CLOUD Act agreement.
Canada’s most pressing investigative problem in the cloud era, Salgado observes, is the difficulty its law enforcement and security agencies face in obtaining digital evidence held by U.S. providers. A Canada-U.S. CLOUD Act agreement would give Canadian authorities a faster, direct, and more comprehensive route to that evidence in serious cases, subject to safeguards and independent oversight. Canada and the United States began negotiations in 2022, and Canadian police and intelligence agencies have emphasized the importance of completing an agreement.
Salgado explains that Part 2 of Bill C-22 could jeopardize that opportunity by authorizing technical surveillance mandates, restrictions affecting security features, mandatory metadata retention, and secret ministerial orders. These powers rest on discredited premises, create serious cybersecurity risks, and have already prompted warnings from members of the U.S. Congress that they could imperil Canada’s prospects for a CLOUD Act agreement. Canada has an opportunity to change course while the bill remains pending and preserve the agreement it needs, Salgado concludes.
To read the article, click here.
* * *
These statements are attributable only to the author, and their publication here does not necessarily reflect the view of the Cross-Border Data Forum or any participating individuals or organizations.