Canada’s Bill C-22 Targets Encrypted Services
Coverage from Michael Geist, EFF, and others

Canada’s Bill C-22 would revise lawful-access rules while allowing regulations that could require certain communications providers to support access capabilities and retain categories of metadata for up to one year.
The government says the proposal excludes communication content and browsing history and adds oversight, while technology companies, privacy advocates, and some U.S. policymakers warn that retention and technical-assistance requirements could weaken security, expose sensitive location patterns, and affect services operating across borders. The legislation remains contested as it advances through Parliament.
The story has shifted from general warnings about Bill C-22 to a more specific parliamentary status update, with the House reportedly passing it and Senate approval still pending. The current version also clarifies the bill’s narrower exclusions and adds a broader sovereignty/data-protection framing.
The story is now framed more explicitly as a cross-border issue, with U.S. officials and lawmakers joining the opposition to Bill C-22. The updated version also sharpens the list of major corporate critics and adds the claim that the bill’s metadata rules could create economic and competitiveness costs.
The core Bill C-22 controversy is unchanged, but the story now broadens beyond surveillance concerns into a more explicit competitiveness and infrastructure question. New material emphasizes that critics see potential spillovers for cross-border data governance, foreign-provider access, and even Canadian digital investment decisions.
Canada's Bill C-22 is driving debate over mandatory metadata retention, subscriber-data access, and possible encryption workarounds. The strongest signal is opposition from privacy advocates, VPN providers, and major tech firms warning about surveillance expansion, secrecy orders, and cross-border risk.
