Drooid Logo
Back to story perspectives

Full Breakdown

Canada’s Lawful Access Bill C-22 Faces Encryption and Metadata Scrutiny

5/29/2026, 5:16:30 AM

Bill C-22: Proposed Lawful-Access Reforms

The Liberal government intends to amend Bill C-22, its lawful-access legislation, to “clarify” how encrypted data and retained metadata may be accessed by police and intelligence agencies. The amendments would define the scope of metadata that can be kept for up to one year and would add language intended to protect end-to-end encryption. The public safety minister, Gary Anandasangaree, has said the bill “was never meant to breach encryption” and that the changes are “reasonable” and aligned with Five Eyes partners.

Legislative Background and Five-Eyes Alignment

Bill C-22 is the second attempt to modernise Canada’s lawful-access regime after an earlier version was withdrawn following public backlash. The government argues that Canada lags behind its Five Eyes allies—Australia, the United Kingdom, the United States and New Zealand—in providing law-enforcement tools for digital investigations. Australia, for example, already permits a one-year metadata retention period, a benchmark the minister cites as justification for the proposed Canadian timeline.

Key Stakeholders

  • Gary Anandasangaree – Minister of Public Safety and Bill sponsor.
  • Apple – represented by Erik Neuenchwander, senior director of user privacy and child safety.
  • Google Canada – represented by Jeanette Patell, director of government affairs and public policy, and Katherine Charlet, senior director of privacy, safety and security.
  • Federal Privacy Commissioner – Philippe Dufresne.
  • Canadian Telecommunications Association – Vice-president Eric Smith.
  • Law-enforcement and intelligence agencies – Royal Canadian Mounted Police, Canadian Security Intelligence Service (CSIS).
  • Opposition parties – Conservative leader Pierre Poilievre, NDP leader Avi Lewis, Green Party leader, and Bloc Québécois.

Data Retention Requirements

The bill would require “core” telecommunications and internet providers to retain metadata—such as call-log records, device-to-device connection data, IP addresses and location information—for up to one year. The legislation explicitly excludes the content of emails, web-browsing histories, social-media activity and text messages. Under current law, police may obtain a warrant to retain a specific person’s metadata for a limited period (typically 30 days or 90 days).

Government Position

Anandasangaree has pledged to amend the bill to ensure “encryption will not be compromised” and to align metadata language with U.S. counterparts. He framed the measures as “modest” steps that other Five Eyes nations already employ, emphasizing that investigators would still need a judicial warrant. The minister also warned that “misinformation” from tech firms hampers the legislative process.

Industry and Privacy Opposition

Apple and Google argue that the bill’s language on “systemic vulnerability” is overly broad and could force the creation of backdoors, exposing users to cyber-attacks. Google described the powers as “boundless” and unnecessary, noting that Canada already has a court-based assistance order system. Privacy commissioner Dufresne warned that longer retention “increases the risk of a privacy breach.” Legal scholars, such as Michel Marchand, contend that the “reasonable suspicion” threshold for accessing metadata is too low, potentially allowing sweeping surveillance.

Conflicting Reports & Gaps

  • Backdoor claim: The Communications Security Establishment (CSE) asserts the bill does not create backdoors, while tech companies maintain it could compel such vulnerabilities.
  • Definition of “systemic vulnerability”: Critics say it is vague; the government says it will tighten the wording.
  • Indemnification: The bill contains no provision to compensate companies if a mandated change leads to a cyber-attack, a point highlighted by U.S. congressional letters.
  • Threshold for access: Law-enforcement advocates accept “reasonable suspicion,” whereas privacy experts argue for a higher standard.

Verbatim Quotes

  • “To be very clear, the encryption issue is one we will clarify, because this bill was never meant to breach encryption,” — Gary Anandasangaree, Public Safety Minister
  • “In other words, when you build a backdoor into an encrypted device, anyone can walk through.” — Erik Neuenchwander, Apple senior director of user privacy and child safety
  • “Ministerial orders are not only alarming, but also unnecessary,” — Jeanette Patell, Director of Government Affairs, Google Canada
  • “The longer you keep information, the more there is a risk of a privacy breach, and the more there is an impact if there’s a privacy breach,” — Philippe Dufresne, Federal Privacy Commissioner
  • “(Spencer Colby/The Canadian Press) "Canadians want to know that their end-to-end encryption won't be targeted," he said.” — Frank Caputo, Conservative MP

What’s Next

Amendments to Bill C-22 are due by the following Wednesday, after which the government hopes to secure passage before Parliament’s summer recess. Opposition parties have called for extended debate and additional scrutiny, while the public safety minister has indicated openness to further changes if they address identified privacy and cybersecurity concerns.