What the Bill Authorizes

Bill C-22, the Lawful Access Act, 2026, was introduced in the House of Commons on March 12, 2026. It does two things. [1]

First, it creates a metadata retention framework. The Governor in Council may make regulations requiring core telecommunications providers to retain prescribed categories of metadata for up to one year. The bill names transmission data explicitly; other categories are left to regulation. Critics argue the breadth of "prescribed categories" could sweep in location-linked records and device identifiers, depending on how the regulations are drafted. The retention applies to every subscriber, not only those under investigation. The Minister of Public Safety may then extend that obligation to other electronic service providers by order, subject to the approval of the intelligence commissioner. [1] [3]

Second, it creates a "confirmation of service" demand. A police officer or CSIS agent may ask a telecom provider whether a specific person is a subscriber. The provider must answer. Any further information requires a warrant. [1]

The bill also creates a new warrant mechanism allowing Canadian judges to issue production orders for data held by foreign companies. These orders would not legally bind the foreign company but would provide a formal basis for cross-border data requests. [1]

What the bill does not do, according to its text, is require the interception of private communications or the decryption of end-to-end encrypted content. The government's position is that the bill respects encryption. [4]


What the Government Says This Is For

The government's case rests on a real operational gap. Public Safety Canada's backgrounder on C-22 says Part 2 does not create new access authorities. It is designed to ensure that telecommunications providers can comply with existing production orders and warrants under the Criminal Code and the CSIS Act. [8]

The problem, in the government's telling, is that metadata is often deleted before police can obtain a warrant to request it. A kidnapping investigation that depends on historical transmission data may fail if the provider purged the records a week earlier. The retention framework is meant to close that gap by ensuring the data exists when a warrant arrives. [8]

The backgrounder also positions C-22 as a narrower successor to the lawful access provisions in Bill C-2, the Strong Borders Act. Public Safety says C-22 replaces C-2's broader ministerial order mechanism with one that requires intelligence commissioner approval and limits the categories of data that can be retained by regulation. [8]

This framing is coherent. The question is whether the bill's operative provisions stay within it.


What the Companies Say

Google's submission to the Standing Committee on Public Safety, dated May 13, 2026, warned that the bill's metadata retention requirement "may result in the extensive retention of metadata about users who are not reasonably believed to be associated with criminal activity." Google argued that creating new surveillance infrastructure risks compromising cybersecurity in ways that could facilitate foreign interference. [2]

On encryption, Google was direct. The bill's definition of "systemic vulnerability" is too narrow, the company argued, and the breadth of ministerial order-making power could be used to compel changes to product architecture that undermine security without technically ordering decryption. Google stated it would not build backdoors and asked the government to scrap the secret ministerial orders, remove the metadata retention framework, and rewrite the bill to explicitly prohibit orders that weaken encryption or alter how products work. [2] [4]

Google is not alone. Apple told Parliament it cannot hand over end-to-end encrypted data because it does not hold the keys. Meta raised concerns about the bill's effect on encryption. Signal warned it would leave Canada entirely. [3] [9]

On the VPN side, Toronto-headquartered Windscribe said it would relocate out of Canada. NordVPN warned it would consider following suit. Proton VPN, based in Switzerland, stated that complying with foreign surveillance orders without Swiss legal process would be a criminal offence under Swiss law. [3] [10]

The Information Technology Industry Council, a U.S. lobby group representing Amazon, Google, and Nvidia, submitted a trade warning that C-22 would have "extraterritorial reach and increase conflict of law issues for global technology companies." [10]


What the Precedent Shows

Canada is not the first jurisdiction to build this architecture. The European Union tried it first.

The EU Data Retention Directive, adopted in 2006, required member states to mandate the retention of telecommunications metadata for between six and twenty-four months. In 2014, the EU Court of Justice struck it down in Digital Rights Ireland, ruling that general and indiscriminate retention of all users' metadata constituted a disproportionate interference with the fundamental rights to privacy and data protection. [5]

The court's reasoning was structural: building the database first and searching it later reverses the presumption of innocence. The retention obligation applied to all subscribers regardless of suspicion, which the court found could not be justified by any legitimate law enforcement objective. Canada's Charter Statement for C-22 discusses Part 2 generally and the non-disclosure regime, but does not appear to directly analyze the regulation-making power that most closely resembles the architecture the EU court struck down. [5] [7]

In the United States, the Communications Assistance for Law Enforcement Act (CALEA) required telecom providers to build lawful intercept capabilities into their networks. In 2024, the Salt Typhoon operation, attributed to Chinese state actors, reportedly compromised U.S. telecom infrastructure including CALEA-compliant lawful-intercept systems. The infrastructure built for lawful access became the reported entry point for foreign intelligence. [11]

On May 7, 2026, the chairs of the U.S. House Judiciary and Foreign Affairs Committees warned that C-22 could create "significant cross-border risks" to American security and privacy and could "weaken our collective defenses against malicious actors." [6]