individual “by identifying the location of a thing that is usually carried or worn by
the individual” is available on the more stringent “reasonable grounds to believe”
standard.
100
In addition to these law enforcement provisions, amendments to PIPEDA in 2015
permit information sharing between private sector organizations where it is “reasonable for the purposes of investigating a breach of an agreement or a contravention of
the laws of Canada or a province that has been, is being or is about to be committed
and it is reasonable to expect that disclosure with the knowledge or consent of the
individual would compromise the investigation”.
101 A further exception deals with
information sharing between organizations that is related to “detecting or
suppressing fraud or of preventing fraud that is likely to be committed and it is
reasonable to expect that the disclosure with the knowledge or consent of the
individual would compromise the ability to prevent, detect or suppress the fraud”.
5 Data Protection and Electronic Surveillance for Security
and Defence Purposes
The collection, use, retention and disclosure of information by the Canadian Security
Intelligence Service in relation to national security are governed by the Canadian
Security Intelligence Service Act.
102 As with criminal investigations, prior judicial
authorization is required for investigations that impact a reasonable expectation of
privacy. The CSIS Act provides for warrants on a “reasonable grounds to believe”
standard.
103 The system is one in which oversight is “front-ended”
104 meaning that
authorization is required in advance of information collection. Bill C-59, before the
Senate at the time of writing, would overhaul the security intelligence system,
creating, among other things, new powers for bulk surveillance combined with
new oversight mechanisms. The Bill would permit the creation of some bulk data
sets with judicial authorization; there are also “judicial controls on retention, exploitation and querying of at least some sorts of information”.
105
The Communications Security Establishment (CSE) which is established by the
National Defence Act,
106 has intelligence gathering functions although, unlike CSIS,
these are aimed outside of the country. The CSE has engaged in bulk metadata
collection, which has raised concerns about breach of privacy under the Canadian
100 Criminal Code, s. 492.1(2).
101 PIPEDA, s. 7(3)(d.1).
102 RSC 1985, c C-23 [CSIS Act].
103 CSIS Act, s. 21.1(2).
104 Forcese (2018), p. 3.
105 Forcese (2018), p. 4.
106 RSC 1985, c. N-5.
70
T. Scassa
the individual” is available on the more stringent “reasonable grounds to believe”
standard.
100
In addition to these law enforcement provisions, amendments to PIPEDA in 2015
permit information sharing between private sector organizations where it is “reasonable for the purposes of investigating a breach of an agreement or a contravention of
the laws of Canada or a province that has been, is being or is about to be committed
and it is reasonable to expect that disclosure with the knowledge or consent of the
individual would compromise the investigation”.
101 A further exception deals with
information sharing between organizations that is related to “detecting or
suppressing fraud or of preventing fraud that is likely to be committed and it is
reasonable to expect that the disclosure with the knowledge or consent of the
individual would compromise the ability to prevent, detect or suppress the fraud”.
5 Data Protection and Electronic Surveillance for Security
and Defence Purposes
The collection, use, retention and disclosure of information by the Canadian Security
Intelligence Service in relation to national security are governed by the Canadian
Security Intelligence Service Act.
102 As with criminal investigations, prior judicial
authorization is required for investigations that impact a reasonable expectation of
privacy. The CSIS Act provides for warrants on a “reasonable grounds to believe”
standard.
103 The system is one in which oversight is “front-ended”
104 meaning that
authorization is required in advance of information collection. Bill C-59, before the
Senate at the time of writing, would overhaul the security intelligence system,
creating, among other things, new powers for bulk surveillance combined with
new oversight mechanisms. The Bill would permit the creation of some bulk data
sets with judicial authorization; there are also “judicial controls on retention, exploitation and querying of at least some sorts of information”.
105
The Communications Security Establishment (CSE) which is established by the
National Defence Act,
106 has intelligence gathering functions although, unlike CSIS,
these are aimed outside of the country. The CSE has engaged in bulk metadata
collection, which has raised concerns about breach of privacy under the Canadian
100 Criminal Code, s. 492.1(2).
101 PIPEDA, s. 7(3)(d.1).
102 RSC 1985, c C-23 [CSIS Act].
103 CSIS Act, s. 21.1(2).
104 Forcese (2018), p. 3.
105 Forcese (2018), p. 4.
106 RSC 1985, c. N-5.
70
T. Scassa
