Canada's surveillance bill reaches everyone, everywhere
Surveillance control · 14.09.2026
Canada is quietly passing a surveillance law that concerns literally everyone — including you, even if you've never been to Canada and know nothing about it.
Bill C-22, aka the Lawful Access Act, has passed first reading and is now on the home stretch in the Senate: hearings begin in late September, and the law could be adopted as early as October. Here's what's inside.
The law requires providers — messaging apps, cloud storage, connected cars, cameras, fitness trackers — to build in "any form of technical capability" for government access. Formally, there's an exception for "systemic vulnerabilities." But non-systemic ones? Fair game. And who decides what counts as systemic? The government. Convenient.
A separate masterpiece: the government refused to explicitly ban measures that circumvent the whole point of encryption. They agreed to ban direct decryption, but client-side scanning, hidden accounts in encrypted chats, and zero-click spyware-style backdoors were all left on the table. Encryption stays formally untouched — they just make it so it's effectively not there.
Next up — unrestricted metadata collection: which agencies get access, what they'll do with the data, where it goes after the retention period expires — none of it is specified. For comparison: the European Court of Justice has three times ruled that mass, indiscriminate metadata collection is incompatible with the EU Charter, and in Opinion 1/15 rejected the EU-Canada PNR agreement precisely because of the lack of safeguards in Canadian law. Nothing has changed since then — Canada's basic privacy law dates back to 2000.
And the cherry on top: secrecy by default. A company that receives a secret order must first notify the minister and wait 15 days before it can even challenge it — and must comply the entire time. There's no independent judicial authorization, only after-the-fact review, and often a limited one.
Formally, this story concerns the EU directly too: the law reaches any provider with Canadian users or business in Canada. That means a European company could receive a secret order to weaken a product's protection for all its European users — and wouldn't be allowed to say a word about it.
Human rights organizations, including EDRi, Access Now, and Article 19, are demanding the European Commission stop staying silent: raise the issue in digital trade talks with Canada, review the data adequacy status, and state clearly that weakening encryption is incompatible with the EU's cybersecurity commitments.
The Senate is the last chance to fix anything. After that, it'll be too late to explain why yet another "anti-terrorism" law turned out to be a tool for surveilling everyone, once again.
Source: https://www.accessnow.org/press-release/the-eu-must-act-now-canadas-overreaching-bill-c-22/
Post #178
147