The hook: a Canadian bill with European reach
On 14 September 2026, sixteen European civil society organisations, including Access Now, ARTICLE 19, Bits of Freedom and EDRi, sent an open letter to Commission President Ursula von der Leyen. They argue that Canada's Bill C-22, the Lawful Access Act, 2026, threatens end-to-end encryption and reaches European service providers. They ask Brussels to press for removal of the surveillance and metadata mandates, to raise the matter in Digital Trade Agreement talks, and to review Canada's GDPR adequacy status.
The timing is real. According to Parliament's LegisInfo record, the bill passed the House of Commons on 18 June 2026, and the Senate was still at second reading on 8 October 2026. Third reading has not yet been reached.
The strongest case for the bill
Canadian police and CSIS have a genuine problem. Investigators often cannot learn which provider serves a suspect, or get timely subscriber information, and foreign platforms frequently ignore domestic requests. Privacy Commissioner Philippe Dufresne told MPs in May that the current version improved on the government's earlier attempt, even though he still wanted amendments. A democracy is entitled to a lawful, court-supervised way to investigate serious crime, and a statute is better than ad hoc pressure on companies.
The bill text also contains protections that critics sometimes overlook. As reported out of the Commons, section 5(5) says a provider is not required to comply with an obligation if doing so would require it to introduce a "systemic vulnerability". A systemic vulnerability is one that creates a credible risk that secure information could be accessed by someone with no authority. Subsection 2(4) says nothing in the Act compels decryption unless the provider itself supplied the encryption and holds the means to decrypt.
Why those safeguards may not be enough
The open letter's central claim is that the bill "does not prohibit orders that defeat end-to-end encryption". That is a narrower and more defensible claim than "the bill bans encryption". The safeguards are drafted around the provider's own position. For a service that cannot read user content, the question is what the minister may demand short of decryption, and who decides whether a demanded change counts as a "systemic vulnerability". Techniques such as client-side scanning change the endpoint rather than the cipher, and may fall outside the text's protection.
Industry witnesses read it the same way. Apple's Erik Neuenschwander told the Commons committee the bill "allows the government of Canada to force companies to break encryption by inserting back doors". Google's Jeanette Patell said it goes well beyond lawful access regimes in other G7 democracies and called the ministerial powers "alarming, but also unnecessary". Signal's Udbhav Tiwari told a Senate gathering on 6 October that compliance "would fundamentally break Signal", and the company says it would leave Canada rather than comply.
When the most security-focused providers say the safeguard does not protect them, the safeguard needs to be tighter.
Metadata and the transatlantic problem
The bill allows regulations requiring core providers to retain categories of metadata for no more than six months. It excludes communication content, web browsing history and social media activity, and the Governor in Council must be satisfied that the categories are essential for effective and timely investigations. These are meaningful limits.
The European letter nonetheless argues that retention of traffic and location data across a population conflicts with EU law, citing established Court of Justice precedent. It also objects that secrecy attaches automatically to capability obligations, with minimal judicial oversight and no recourse for affected European users. Whether or not Brussels agrees, a provider serving both markets could face incompatible duties. One regime would require retention and secret capability-building. The other would prohibit general and indiscriminate retention.
Compliance conflicts of this kind are costly. They are usually resolved by the largest firms absorbing the burden and smaller, privacy-focused services withdrawing from the market. That is bad for innovation and bad for users.
What a proportionate fix looks like
We would not support the European groups' preferred remedy of treating Canada's GDPR adequacy as a bargaining chip. Adequacy decisions rest on whether the whole legal system gives essentially equivalent protection. Using them as leverage over one bill would politicise a mechanism that businesses rely on for ordinary data flows. Trade-agreement talks are a more suitable forum for raising interoperability concerns.
The better remedy sits in Ottawa, and the Senate has time to apply it:
- Add an explicit statement that no order may require weakening, bypassing or scanning around end-to-end encryption, rather than relying on a definition of "systemic vulnerability" that the minister's own office would apply.
- Require independent judicial authorisation, not only ministerial direction, before any technical capability order takes effect.
- Limit secrecy so that oversight bodies and, after a set period, the public can see how often capability orders are used.
- Require a sunset or a hard parliamentary review. The bill already provides for review in Part 3, and that review should have teeth and a fixed date.
The bottom line
C-22 is a better bill than its harshest critics claim, and a worse one than its sponsors suggest. It contains real limits on retention and an explicit anti-backdoor principle. It also leaves the central question, what a minister may demand of a provider that cannot read its users' messages, to executive discretion. Security researchers have long argued that a deliberately weakened system serves criminals as well as police. Canada can resolve that now, in the text, and avoid a trans-Atlantic dispute that Brussels should not have to settle for it.