EU encryption policy

Canada's Bill C-22 Already Bars Encryption Backdoors — the EU Coalition's Real Fight Is Over Retention and Leverage

European civil society wants Brussels to threaten Canada's GDPR adequacy over Bill C-22, but the bill's text already protects encryption more than critics acknowledge.

Canada's Bill C-22: What the EU Letter Gets Right an… People of Internet Research · EU 16 groups EU letter signatories 16 European civil society organisa… 6 months Metadata retention window Amendments cut the original 12-mon… June 18, 2026 House passage date Bill C-22 cleared the House of Com… 23 years Years since first adequacy review The Commission's Feb 2024 report w… peopleofinternet.com
Canada's Bill C-22: What the EU Letter… People of Internet Research · EU 16 groups EU letter signatories 6 months Metadata retention window June 18, 2026 House passage date 23 years Years since first adequacy review peopleofinternet.com

Key Takeaways

The Letter and the Ask

On September 14, 2026, sixteen European civil society organisations — including Access Now, ARTICLE 19, Bits of Freedom, and Digitalcourage — sent an open letter to Commission President Ursula von der Leyen, Trade Commissioner Maroš Šefčovič, and Justice Commissioner Michael McGrath. Their ask is specific: press Canada to strip Bill C-22's surveillance and metadata-retention mandates, get Brussels to declare that encryption-weakening measures are incompatible with EU cybersecurity commitments, raise the bill inside the emerging EU-Canada Digital Trade Agreement talks, and — most consequentially — open a review of Canada's GDPR adequacy status under Article 45(4), with suspension under Article 45(5) on the table if the bill passes unamended.

The bill in question, the Lawful Access Act, cleared Canada's House of Commons on June 18, 2026, and its Senate committee study began as Parliament returned this fall. It compels "core" electronic service providers to build technical capabilities for law-enforcement and CSIS access to communications data and to retain certain metadata categories.

What the Bill Actually Says About Encryption

Here the letter overstates its case. Bill C-22's text is explicit: providers cannot be compelled to decrypt information "unless the encryption was provided by the electronic service provider and the provider possesses the information necessary to decrypt." A separate clause exempts providers from compliance where it would create or fail to fix a "systemic vulnerability." That is not nothing — it is a narrower obligation than the UK's Investigatory Powers Act framework that forced Apple to withdraw Advanced Data Protection in 2025, and narrower than what critics feared from C-22's predecessor, the failed Bill C-2. Canada's own Privacy Commissioner, Philippe Dufresne, told the House committee in May that C-2's confirmation-of-service demands had been narrowed and oversight strengthened in C-22 — while still pushing for the "systemic vulnerability" definition to be tightened further so it cannot be read around.

So when the European letter asks Ottawa to "categorically prevent any measures that would, directly or indirectly, undermine end-to-end encryption," it is asking for something close to what the statutory text already claims to do. The real question — one the letter buries under the encryption framing — is whether the exemption is drafted tightly enough to survive ministerial reinterpretation, not whether it exists.

The Actual Fight Is Retention and Leverage

Where the critics have a stronger case is metadata retention. Amendments this summer cut the original 12-month mandate to six months, per the Globe and Mail's reporting — but the bill still lacks hard limits on which agencies can query retained metadata, how long query results persist, or what happens to data after the retention window closes. The Electronic Frontier Foundation makes the sharper technical point: mandating retained metadata pools and access infrastructure creates the same attack surface regardless of whether content is encrypted — the 2024 Salt Typhoon breach of US telecom wiretap systems is the cautionary case study. That's a legitimate, evidence-based objection, and Canada's Senate should take it seriously on the merits.

Steelmanning the Adequacy Threat

The EU coalition's adequacy leverage isn't frivolous, either. GDPR Article 45 conditions data-flow permissions on a partner country maintaining protections "essentially equivalent" to the EU's own, and the Commission's own February 2024 review — its first since the original 2001 decision — was explicit that continued adequacy depends on Canada's framework not eroding. If C-22's retention regime meaningfully weakens safeguards around EU citizens' data once it transits Canadian infrastructure, a review is the correct institutional response, not an overreach. Digital rights groups invoking adequacy review is exactly how the mechanism is supposed to work.

Where the Letter Overplays Its Hand

But treating Article 45(5) suspension as leverage in a live legislative debate — before the Senate has even finished its study — is premature and counterproductive. Adequacy suspension is a blunt instrument that would disrupt commercial data flows for thousands of firms with no connection to lawful-access policy, and threatening it mid-negotiation reads less like principled rights advocacy and more like an attempt to use trade-agreement leverage to rewrite a foreign legislature's criminal-procedure bill. It also elides the genuine, text-level encryption protections Bill C-22 already contains, which undercuts the coalition's credibility on the retention concerns that are actually well-founded.

The better path for Brussels is the one Dufresne is already modeling domestically: push for the "systemic vulnerability" and retention-use provisions to be tightened during Senate study — where Canadian civil society already has standing and momentum — rather than reaching for adequacy suspension as a first move. The EU-Canada Digital Trade Agreement talks are a legitimate venue for raising interoperability concerns about lawful-access regimes generally; a live suspension threat is not proportionate to a bill whose most alarming provision, correctly read, is already off the table.

Sources & Citations

  1. Access Now — Open letter on Bill C-22
  2. Parliament of Canada — Bill C-22, Third Reading
  3. Office of the Privacy Commissioner of Canada — Statement on Bill C-22
  4. The Globe and Mail — EU letter and digital trade talks
  5. EFF — Bill C-22 analysis
  6. Gowling WLG — EU Commission's 2024 Canada adequacy review