Canada encryption policy

Canada's Lawful Access Act Trades Warrant Requirements for Speed—And Europe Is Right to Worry About the Export

Bill C-22 lets Canadian police demand subscriber data without a warrant and reaches EU firms, but its anti-backdoor clause shows the encryption panic is partly overstated.

Canada's Lawful Access Act, By the Numbers People of Internet Research · Canada 6 months Metadata retention ceiling Core providers may be compelled to… June 18, 2026 House passage date Bill C-22 passed third reading in … October 2026 Possible law date Senate study begins after Parliame… peopleofinternet.com
Canada's Lawful Access Act, By the Num… People of Internet Research · Canada 6 months Metadata retention ceiling June 18, 2026 House passage date October 2026 Possible law date peopleofinternet.com

Key Takeaways

A bill that moves faster than its critics

On September 14, 2026, Access Now and a coalition of European civil society groups wrote to European Commission President Ursula von der Leyen asking Brussels to intervene before Canada's Senate finishes work on Bill C-22, the Lawful Access Act, 2026 (Access Now). The bill passed the House of Commons at third reading on June 18, 2026, after the government invoked time allocation to limit debate (Parliament of Canada, LEGISinfo). The Senate resumes sitting on September 21 and begins its study shortly after — meaning C-22 could receive Royal Assent as early as October, giving Ottawa's upper chamber roughly three sitting weeks to do the scrutiny the Commons rushed.

What the bill actually does

Stripped of advocacy-group framing, the bill's operative text — available in full on Parliament's site — does three concrete things. First, it creates a "Confirmation of Service Demand": peace officers can require a telecom or internet provider to confirm whether it serves a given subscriber, without a warrant, on "reasonable grounds to suspect" an offence has been or will be committed (Parliament of Canada, third reading text). Reasonable suspicion is a materially lower bar than the probable-cause standard that governs most search warrants. Second, Part 2 of the bill — the Supporting Authorized Access to Information Act — lets regulators compel "core providers" to retain communications metadata for periods "not exceeding six months," though it explicitly excludes content, browsing history, and social media activity from that mandate. Third, on encryption specifically, the bill's text says obligations under the Act cannot be read as compelling a provider to decrypt anything unless the provider itself holds the decryption key — a carve-out added after the government's 2025 predecessor bill collapsed under similar criticism.

Steelmanning Ottawa's case

Before dismissing this as pure overreach, it's worth stating the government's argument on its own terms. Canadian police have long complained of a genuine "digital evidence" gap: investigators can spend weeks establishing which of dozens of possible providers even serves a suspect before they can seek a production order for content, by which point evidence has often been deleted or a suspect has moved on. A narrowly scoped, low-friction "does this provider serve this account" check — the kind other Five Eyes jurisdictions already permit — is a defensible response to that specific problem, especially for time-sensitive child-exploitation and trafficking cases where CSIS and the RCMP argue delay itself causes harm. That is a real and legitimate policy problem, and the encryption-preserving drafting is a genuine concession, not window dressing.

Where the bill overshoots

The defensible core doesn't justify the whole structure. Three features go well beyond the digital-evidence problem the government cites. The subscriber-confirmation power has no judicial authorization step at all — "reasonable suspicion," self-certified by the officer making the request, is not independent oversight, and Canada's own Supreme Court held in R. v. Spencer (2014) that subscriber identity carries a reasonable expectation of privacy precisely because it unlocks anonymity. A warrantless mechanism sits uneasily next to that precedent even if it targets identity rather than content. Second, the six-month metadata retention mandate applies broadly to "core providers" rather than being tied to an active investigation — a blanket retain-everything-just-in-case regime is the opposite of the data-minimization principle Canada's own privacy regulators have pushed providers toward for a decade. Third, and what actually triggered Monday's letter, is extraterritorial reach: the bill's demand powers apply to services used by people in Canada regardless of where the company is headquartered, meaning a European messaging or cloud provider with Canadian users can be compelled under a standard Brussels does not set and cannot review.

Why Brussels has real leverage here

"Bill C-22 is not just a domestic privacy and data issue in Canada... it puts the privacy and data of millions of people in Europe at risk." — Access Now

That's not just rhetoric. The EU's adequacy decision for Canada under GDPR Article 45 is a standing instrument the Commission can actually review, and Access Now's letter explicitly asks for that review alongside a public Commission statement during ongoing EU-Canada Digital Trade Agreement talks. If Brussels concludes C-22 lets Canadian authorities compel EU-serving companies to hand over subscriber data with no warrant and no notice to the data subject, an adequacy re-examination is a plausible, not hypothetical, response — and one Ottawa has strong commercial reasons to avoid.

The right fix is narrower, not louder

The encryption-apocalypse framing in some of this week's coverage overstates the bill as drafted; the anti-backdoor clause is real and meaningfully different from the UK's Investigatory Powers Act approach that EFF has (correctly) criticized elsewhere. But narrow, warrant-gated subscriber confirmation with a hard retention ceiling and no extraterritorial pull-through would solve the legitimate policing problem without the collateral damage. The Senate has three weeks and a genuine opening: amend the confirmation demand to require prior judicial sign-off, cut the six-month retention default, and clarify that compelled disclosure doesn't reach providers with no Canadian operations. That's a proportionate compromise — not the false binary between "police get nothing" and "police get a self-certifying data-retention regime with global reach" that this week's advocacy has, understandably, framed it as.

Sources & Citations

  1. Parliament of Canada — Bill C-22 (45-1), Lawful Access Act, 2026, Third Reading text
  2. Parliament of Canada — Bill C-22 third-reading text
  3. Access Now press release on letter to von der Leyen
  4. EFF — Canada's Bill C-22 analysis
  5. The Globe and Mail — What to know about Bill C-22