Post 1.
Canada’s Dangerous Drift Towards a Surveillance State: The Hidden Costs of Bill C-22
16th June 2026
In the shadow of ballooning national debt, a punishing housing crisis, and persistent concerns over violent crime and economic stagnation, the Carney government has chosen to prioritise expanded digital surveillance powers. Bill C-22, formally the Lawful Access Act, represents one of the most sweeping attempts in recent Canadian history to compel technology companies to redesign their systems for easier government access to Canadians’ private data. Fast-tracked through Parliament with limited debate, this legislation risks trading fundamental privacy and security for illusory gains in law enforcement efficiency.
At its core, Bill C-22 seeks to modernise “lawful access” rules for police and the Canadian Security Intelligence Service (CSIS). It would require electronic service providers, from telecom giants to app developers, to build and maintain technical capabilities enabling timely access to communications and information. This includes obligations for metadata retention, potentially up to one year, covering details such as who communicated with whom, when, and from where. While the bill explicitly avoids mandating retention of message content or browsing history in its current text, critics rightly note that metadata itself paints an intimate portrait of daily life: location patterns, social connections, and routines that reveal far more than many realise.
Encryption at Risk
Particularly alarming is the legislation’s potential to undermine encryption, the very technology that protects banking transactions, health records, private messages, and critical infrastructure. Apple’s senior director for user privacy and child safety, Erik Neuenschwander, warned Parliament’s public safety committee that vague language in the bill could effectively force companies to insert backdoors into encrypted products. “When you build a backdoor into an encrypted device,” he cautioned, “anyone can walk through it.” Google echoed these concerns, highlighting risks of creating systemic vulnerabilities that foreign adversaries or cybercriminals could exploit.
Similar warnings have come from Signal, the encrypted messaging service trusted by journalists, activists, and ordinary Canadians seeking privacy. Executives have indicated they may withdraw from the Canadian market rather than compromise their core security model. Civil liberties organisations, privacy scholars, and cybersecurity experts, more than two dozen in a joint open letter, have described the bill as potentially “the most expansive invasion of Canadian privacy rights in modern history.” They argue it could expose users to heightened data breaches, foreign interference, and a chilling effect on free expression.
The government insists the measures are “encryption neutral” and include safeguards against systemic vulnerabilities. Yet history shows that once capabilities are mandated, mission creep often follows. Earlier iterations of similar proposals collapsed under scrutiny; this version, reintroduced after initial pushback, still carries the same fundamental flaws despite promised amendments. Rushed committee processes and time allocation motions have limited thorough examination, sidelining expert testimony and public input at a moment when digital policy demands careful deliberation.