Does CSE comply with the law?
The Prime Minister and his ministers frequently reassure Canadians that they need not worry about the potential for misuse of CSE’s highly intrusive eavesdropping powers because the CSE Commissioner reviews CSE’s compliance with the law and has always declared CSE to be in compliance.
This April 2014 statement by then-Defence Minister Rob Nicholson is a good example:
Such statements artfully avoid the fact that CSE is able to collect and analyze a surprisingly large amount of information about Canadians entirely legally, at least in the view of the government and the Commissioner. (Others are not so sure about the legality of such activities; see here and here for a couple of different views.)
But, still, the CSE Commissioner’s annual affirmation ought to have some reassurance value.
At least, it would if it actually meant what the government would like you to think it means.
If they had to guess, most people would probably imagine that the process of compliance monitoring looks something like this:
The CSE Commissioner examines CSE's activities during the year under review, determines whether or not they comply with the law, and reports his conclusions.

The reality is a bit more… complex.
A look at the reporting done by CSE Commissioners over the history of their operations suggests that the actual process looks more like this (click on flowchart to see larger version):

The following notes, keyed to the numbers in brackets in the flowchart, provide further explanation and some actual examples:
1: The first question facing the Commissioner is whether to even look at a particular activity of the agency. No review body can examine every activity undertaken at every moment by the agency it watches. CSE Commissioners prioritize the activities they review to try to cover the most significant risks, and anything not on their list during the current set of reviews goes unexamined.
As the Commissioner’s 2003-04 report explained,
An example of one of the questions the CSE Commissioner has chosen not to address is CSE’s cooperation with CSIS to “craft” the affidavit and oral testimony that CSE provided to the Federal Court of Canada in 2009 in support of a CSIS application for a warrant to monitor Canadians traveling abroad. Justice Richard Mosley declared that CSIS’s failure to disclose to the court that the assistance of Second Parties would be sought in the execution of such warrants was a breach of its “duty of candour” to the court. He did not specifically characterize CSE’s behaviour, but he did note CSE official James D. Abbott's acknowledgement that his testimony was “‘crafted’ with legal counsel to exclude any reference to the role of the second parties”.
Is it legal to withhold relevant information from a judge in order to get a warrant approved? The CSE Commissioner has chosen not to report on this question.
2: The Commissioner’s ability to review CSE relies on the agency keeping meticulous records of its activities, and Commissioners frequently recommend ways to improve CSE’s record-keeping. Nonetheless, sometimes CSE’s records are missing or insufficient to enable the Commissioner to properly assess the legality of a CSE activity, as noted here:
In 2006-07, for example, the Commissioner reported that
Similarly, although it is illegal for CSE to intercept “private communications” except when it has a Ministerial Authorization to do so, when such interceptions inadvertently occurred during the five years between the first appointment of a CSE Commissioner and the establishment of the Ministerial Authorization regime in 2001, CSE was not declared to be in violation of the law because, the Commissioner reported, the agency's extensive efforts to prevent such interceptions demonstrated that it did not intend to act unlawfully:
6: CSE Commissioners have also shown that they will not declare CSE in non-compliance as long as the government has promised to make amendments to the law to clarify that the activities in question are indeed authorized under the law—no matter how many years may go by with no evidence of the government actually taking steps to implement that promise.
See, for example, this statement:
What would it take to declare CSE in non-compliance?
Given the system in place, what would it take for a CSE Commissioner to actually declare CSE to be in non-compliance with the law?
Based on the model above, the Commissioner would have to choose to examine the activity, sufficient records would have to exist to support a compliance judgement, the Commissioner would have to conclude that the activity violates the law, CSE and the Department of Justice would have to agree with that conclusion, CSE would have to affirm, or the Commissioner would have to demonstrate, that the activity was authorized by the agency [or that it had been permitted to occur due to a lack of due diligence], CSE would have to declare that it intends to continue doing it, and the government would have to refuse to promise to amend the law (at some undefined point in the future) in order to permit the activity. If all those conditions were met, and the Commissioner subsequently reported the issue to the Attorney-General, and no promise (sincere or otherwise) to change either the activity or the law were forthcoming following that step, then and only then would he report to the public that CSE was not in compliance with the law.
In short, the likelihood that a CSE Commissioner will ever declare that CSE is not in compliance with the law, no matter how often those laws may be transgressed in practice, is practically nil.
[But never say never! In January 2016, the CSE Commissioner deviated dramatically from this "model" and did declare CSE to be in non-compliance even though the violation was deemed to have been unintentional and the activity had already been halted. There's no way to tell at this point whether that was a one-time event or it heralds a more permanent change in the Commissioners' approach to compliance assessment.
Until that picture becomes clearer, I won't make any change to the compliance flowchart—which was always a bit tongue-in-cheek anyway—that accompanies this article.]
I should probably make it clear at this point that I don’t believe CSE does intentionally break the law—as it and its Department of Justice advisors understand the law—as a normal part of its operations. I believe that compliance with the law is a fundamental part of CSE’s ethos, and I think the activities of the CSE Commissioner have done a lot to reinforce that ethos and ensure that it is followed in practice.
For me, a much bigger concern is the amount of information that can be collected, one way or another, without violating the law, and the potential for that information, although it may not be misused now, to be misused sometime in the future. Consider, for example, the fact that no laws were broken—according to the CSE Commissioner—by the extensive collection and analysis of Canadian communications metadata revealed in the “Airport Wi-Fi” story.
Whether or not you agree that legal compliance is ultimately not the key issue, however, know this:
While the Prime Minister and his ministers are no longer able (as of January 2016) to claim that all CSE Commissioners have always declared CSE’s activities to be in compliance with the law, they will undoubtedly reach for similar claims, such as "CSE has never intentionally broken the law" or, assuming there are clean reports in future years, "the most recent Commissioner's report has affirmed that all of CSE's activities were in compliance with the law."
But the reality of that assurance will always be a whole lot more hedged and contingent and qualified than the government would like you to think it is.
Update 29 January 2016: The conclusion to this post was amended and the comments in brackets added to the body of the post following the release of the CSE Commissioner's 2014-15 Annual Report.
