Drooid Logo
Back to story perspectives

Full Breakdown

Canada’s Bill C-22 Faces U.S. Tech and Congressional Pushback

5/15/2026, 11:19:00 PM

Bill C-22: Proposed Lawful Access Measures

Bill C-22, the Liberal government’s second attempt at lawful-access legislation, would require telecommunications, internet and social-media providers to modify their systems so police and the Canadian Security Intelligence Service (CSIS) can obtain data with a warrant. It also mandates core providers to retain metadata for up to one year.

Background & Context

The proposal follows a series of contentious digital-policy moves, including the scrapped digital services tax that had targeted U.S. firms such as Amazon, Apple and Meta. Earlier U.S. trade pressure on Canada’s Online Streaming Act signaled a broader pattern of American concern over Canadian regulations that affect cross-border data flows.

Key Stakeholders

  • Gary Anandasangaree – Public Safety Minister and bill sponsor.
  • Jim Jordan (Chair, U.S. Judiciary Committee) and Brian Mast (Chair, Foreign Affairs Committee) – authors of a congressional letter.
  • Apple, Meta (Facebook, Instagram, WhatsApp) and Signal – companies warning of encryption risks.
  • Michael Geist – University of Ottawa internet-law professor and vocal critic.
  • Monique St. Germain – General counsel, Canadian Centre for Child Protection, supporting the bill.
  • Police chiefs and CSIS – endorsing the need for updated investigative tools.

Data & Statistics

  • The bill’s metadata-retention clause covers up to 12 months of user-location and connection data.
  • The Canadian Centre for Child Protection reports 141 million takedown notices of child-sexual-abuse material since 2017, a figure used to argue for stronger investigative powers.

Why It Matters

U.S. officials argue the bill could “drastically expand Canada’s surveillance and data-access powers” and create “significant cross-border risks to the security and data privacy of Americans.” Tech firms warn that compliance may force back-doors, exposing all users—including U.S. citizens—to hacking and state-level intrusion. The dispute threatens market access for Apple and Meta in Canada and adds strain to an already tense Canada-U.S. relationship.

Official Statements & Responses

Anandasangaree contends that “tech giants are misinterpreting some of the safeguards already built in, including ensuring that encryption is not interrupted.” Apple’s statement says the bill “would undermine our ability to offer the powerful privacy and security features users expect.” Meta’s Rachel Curran described the legislation as “conscript[ing] private companies into service as an arm of the government’s surveillance apparatus.” The Centre for Child Protection emphasized that delaying the bill “poses higher risks to children and Canadians.”

Criticism & Opposition

Michael Geist warned that the bill would create “a surveillance map” vulnerable to hackers. Congressional letters labeled the proposal a threat to U.S. national security and economic interests. Privacy advocates argue the definition of “systemic vulnerability” is vague, leaving room for forced weakening of encryption.

Verbatim Quotes

  • “drastically expand Canada’s surveillance and data-access powers in ways that create significant cross-border risks to the security and data privacy of Americans.” — Jim Jordan, Chair, U.S. Judiciary Committee
  • “If we're starting to mess with the privacy and security of Americans, it shouldn't surprise anyone to see congressional leaders say, 'Hold on a second, Canada, we're uncomfortable with where this legislation is headed,'” — Michael Geist, University of Ottawa
  • “conscript private companies into service as an arm of the government’s surveillance apparatus.” — Rachel Curran, Meta, head of public policy in Canada
  • “At a time of rising and pervasive threats from malicious actors seeking access to user information, Bill C-22, as drafted, would undermine our ability to offer the powerful privacy and security features users expect from Apple.” — Apple spokesperson
  • “Tech giants are misinterpreting some of the safeguards that are already built in, including on ensuring that encryption is not in any way interrupted as part of Bill-22,” — Gary Anandasangaree, Public Safety Minister

Conflicting Reports & Gaps

The bill states providers are not required to comply if a “systemic vulnerability” would be created, yet critics argue the language is insufficiently precise to prevent mandated back-doors. No definitive guidance exists on how encryption-break requirements would be evaluated, leaving a gap between the government’s claim of built-in safeguards and industry’s fear of forced weakening.

What’s Next

Parliamentary committees are reviewing amendments to clarify the systemic-vulnerability clause. U.S. congressional pressure is expected to continue, and Apple and Meta have signaled possible withdrawal of certain privacy services if the bill passes unchanged. The government has pledged further public education on the bill’s safeguards while seeking a compromise that satisfies law-enforcement needs without compromising cross-border data security.