Drooid Logo
Back to story perspectives

Full Breakdown

Google, Meta, Apple warn Canada’s Bill C-22 could create surveillance infrastructure and weaken cybersecurity

5/26/2026, 4:40:07 AM

Bill C-22’s Core Provisions and Security Risks

Bill C-22 would require electronic service providers—phone companies, messaging apps and major tech firms—to modify their systems so police and the Canadian Security Intelligence Service can intercept data. The law gives the Minister of Public Safety authority to issue secret orders and defines providers broadly enough to cover almost any entity operating in Canada. It also mandates retention of telephone-number connections and location data for up to one year, while excluding e-mail, web-browsing, social-media activity and text-message content. CSIS argues Canada lags behind its Five-Eyes partners; the U.S. approach applies only to telecoms and does not require year-long metadata retention. Google warns the measures would create a surveillance infrastructure and could introduce systemic vulnerabilities that undermine encryption.

Stakeholder Positions and Government Response

Google, Meta and Apple submitted a brief urging amendments to protect encryption and narrow the definition of systemic vulnerability. The Canadian Telecommunications Association—representing Bell, Rogers, SaskTel and Nokia Canada—called for limits on the volume and sensitivity of data collected from individuals not suspected of wrongdoing. The Canadian Chamber of Commerce warned the bill could weaken cyber-defenses. Signal and other privacy groups threatened to leave Canada if forced to retain metadata. The federal government says the bill will not infringe Charter rights or enable mass surveillance. Public Safety Minister Gary Anandasangaree is preparing to accept amendments; Shannon Hiegel said the minister is “open for new ideas.”

Conflicting Interpretations of “Systemic Vulnerability”

Bill C-22 states providers need not comply with orders that would create a “systemic vulnerability.” Google counters that the bill’s definition of such vulnerability is “unduly narrow,” fearing it could be used to mandate backdoors that break end-to-end encryption.

Verbatim Quotes

  • “Secret Ministerial Orders would severely restrict companies’ ability to engage transparently with users, undermining the users’ trust and ability to hold companies accountable,” — Google
  • “The lack of explicit protection for end-to-end encryption may also undermine the ability of companies to deliver best-in-practice security controls and technologies to enterprises, including governments, small businesses, and critical infrastructure,” — Google
  • “Google has never built a backdoor or other mechanism to circumvent end-to-end encryption in our products. If we say a product is end-to-end encrypted, it is end-to-end encrypted,” — Google
  • “The most effective way to reduce risk is therefore to limit the amount of sensitive data that is collected and retained, and to ensure that retention periods are no longer than necessary.” — Canadian Telecommunications Association

Outlook

Senior officials say amendments will focus on limiting metadata-retention periods and preserving encryption. The final shape of Bill C-22 will decide whether Canada adopts a Five-Eyes-style surveillance regime or a more limited model.