Hold the North

A Lecture From Washington, A Silence At Home

Michael Geist - House of Commons
Michael Geist - House of Commons

Bill C-22 has Apple, Signal, NordVPN, the Canadian Chamber of Commerce, and now two U.S. congressional committees warning the Carney government its surveillance bill goes too far. Most Canadians still haven’t been told what is in it.

Hold the North | Politics

Most Canadians have not heard of Bill C-22.

Most Canadians, if asked, could not name the agency that would enforce it, the companies that have already said they would leave the country rather than comply with it, or the foreign legislature that has formally written to Ottawa to express concern about it.

That is not an accident. It is the architecture of how this kind of law moves through Canadian politics now. Quietly. Renumbered. Defended with the line that the critics are confused. Passed before the public has been asked.

The bill is real. The stakes are not theoretical. And under the current government’s timetable, it is on track to become law.

Michael Geist - House of Commons
Michael Geist testifying before the Standing Committee on Public Safety and National Security on Bill C-22, May 7, 2026. Source: Michael Geist / YouTube.

What the bill actually does

Bill C-22, the Lawful Access Act, was introduced in the House of Commons on March 12, 2026 by Public Safety Minister Gary Anandasangaree. It is the second life of a regime that first appeared inside Bill C-2, the Strong Borders Act, in June 2025. That earlier version provoked enough opposition โ€” from civil liberties groups, the legal community, opposition parties, and the country’s own Privacy Commissioner โ€” that the government split the bill in two. The border, customs and immigration pieces were repackaged as Bill C-12 and moved through Parliament. The surveillance pieces were rebuilt and reintroduced as Bill C-22.

The bill has two parts.

Part 1 amends the Criminal Code and the CSIS Act. It creates a new power for police and the Canadian Security Intelligence Service to demand that telecommunications providers confirm whether someone is their customer. Crucially, it lowers the evidentiary standard for judicial production orders to obtain subscriber information from “reasonable grounds to believe” โ€” the standard that has governed this for a decade โ€” to “reasonable grounds to suspect,” the lowest investigative threshold in Canadian criminal law.

Part 2 is the part that has set off an international fight. It creates the Supporting Authorized Access to Information Act, or SAAIA. Under SAAIA, the Public Safety Minister can issue ministerial orders compelling “electronic service providers” โ€” a broad category that includes telecoms, social media platforms, cloud providers, AI tools, and any “smart” device โ€” to build technical capabilities that allow government access to user information.

The bill also allows for regulations requiring service providers to retain metadata โ€” the digital traces of every communication, including who contacted whom and from where โ€” for up to a year.

That is the law. In plain language. Without softening.

What the government says it doesn’t do

Public Safety Canada says the bill is encryption-neutral. The department insists nothing in Bill C-22 requires companies to weaken encryption. Minister Anandasangaree, facing days of mounting backlash, told reporters in mid-May that tech companies were “misinterpreting” the bill.

The companies disagree. So do the cryptographers. So does the country’s own intelligence oversight body. So does the United States Congress.

Apple, which secures everything from iMessage to financial information on iPhones, issued a written statement warning the legislation could be used to force a backdoor into its products โ€” “something Apple will never do.”

Meta said Bill C-22 could force providers to install government spyware directly on their systems and warned the bill would turn tech companies into a surveillance arm of government. Signal, the encrypted messaging service used by journalists, lawyers, doctors, and Members of Parliament, told the government it would withdraw from the Canadian market rather than comply. NordVPN said the same on May 15. ExpressVPN joined the warning list days later. Windscribe, a Canadian-founded VPN company, has indicated it would consider leaving its own home country rather than build the architecture the bill requires.

The Canadian Chamber of Commerce, in a letter to Anandasangaree and Justice Minister Sean Fraser, warned the bill threatens encryption and would deter investment in Canada.

That is not a fringe coalition. That is Apple, Meta, Signal, the Chamber of Commerce, and a list of privacy infrastructure companies the Canadian government cannot replace. All saying the same thing. All being told they are confused.

A rebuke from Washington

On May 7, 2026, the chairs of two American congressional committees โ€” Jim Jordan of House Judiciary and Brian Mast of House Foreign Affairs, both Trump-aligned Republicans โ€” sent a joint letter to Public Safety Minister Anandasangaree. They warned that Bill C-22 would drastically expand Canada’s surveillance powers in ways that pose cross-border risks to American security and privacy. They warned it could force American companies into a choice between compromising the security of their entire user base โ€” including U.S. citizens โ€” and being shut out of the Canadian market.

The diplomatic awkwardness here is hard to overstate.

The Carney government is in the middle of an active trade fight with Washington. The same legislators now publicly correcting its surveillance bill belong to the congressional majority allied with the administration that imposed the tariffs Canada is fighting. The relationship between the two governments is, by any honest measure, the worst it has been in a generation.

And on Bill C-22 โ€” on a question of basic encryption integrity and cross-border data security โ€” Washington is right. Ottawa is being told its own domestic surveillance law is reckless by the chairs of foreign committees whose job is to protect their own citizens from exactly the kind of risks Canadian legislation is now creating.

For a prime minister whose international brand was built on competence and steady stewardship, that is a snub. For a country that prides itself on punching above its weight on rule-of-law questions, it is an embarrassment. And the response so far has been to insist the critics, including the foreign legislature, are misreading the bill.

letter from washington
Letter from House Judiciary Committee chair Jim Jordan and House Foreign Affairs Committee chair Brian Mast to Public Safety Minister Gary Anandasangaree, May 7, 2026. Source: U.S. House of Representatives.

A backdoor for Ottawa is a backdoor for everyone

There is a piece of this story that gets lost in the legal and political back-and-forth, and it is the part Canadians most need to understand. It is not legal. It is engineering.

There is no such thing as a backdoor that only lets in the good guys. Cryptography does not work that way. The mathematical key that allows the RCMP to read an encrypted message is the same mathematical key that, once it exists, can be stolen, leaked, subpoenaed under foreign law, or eventually discovered by a sufficiently skilled adversary. Every cryptographer who has ever testified on this question, in any democracy, has said the same thing. There is no clever engineering workaround. The hole is the hole.

That principle is why the U.S. congressional letter framed Bill C-22 as a national security threat to Americans, not just a privacy concern. The same access point Canadian law enforcement walks through is the access point anyone else can eventually walk through. Once a Canadian telecom is required to maintain interception capability for CSIS, that telecom is also maintaining a target for China’s state-aligned hacking groups, for Russia’s military intelligence cyber units, for North Korean cyber operations, and for the rapidly growing private market in stolen system access.

The historical record is unforgiving. The U.S. Office of Personnel Management database, containing the security clearance files of over 22 million Americans, was breached by Chinese state actors in 2015. The NSA’s own offensive cybersecurity toolkit was stolen by the Shadow Brokers group in 2016 and weaponized worldwide, powering the WannaCry and NotPetya attacks that crippled hospitals, shipping companies, and government systems on three continents. Australia’s signals intelligence agency has lost contractor data on multiple occasions. Every major surveillance database built in the past two decades has eventually been breached. The defenders have to be right every time. The attackers have to be right once.

Bill C-22 does not just expose Canadians to that risk in the abstract. It would mandate the construction of new repositories โ€” metadata, subscriber information, location data โ€” that do not currently exist in a single accessible form, and that would be required to remain accessible for up to a year. That is a purpose-built target inventory.

And then there is the United States.

The Citizen Lab, the University of Toronto research group whose technical analyses on this file have been more thorough than anything in mainstream Canadian press, has documented that Canada has been quietly negotiating a bilateral data-sharing agreement with the U.S. under the American CLOUD Act since 2022. The CLOUD Act allows U.S. law enforcement to demand data directly from providers in partner countries, bypassing local courts. The lawful access provisions in Bill C-22 read like the domestic legal scaffolding Canada would need to ratify the Second Additional Protocol to the Budapest Convention โ€” a foreign-state data-sharing treaty most Canadians have never heard of, but which Justice Canada officials confirmed at a technical briefing in June 2025 is part of the actual policy intent behind some of these provisions.

In plain English: the same surveillance architecture being built for Canadian law enforcement creates the legal and technical infrastructure for the United States government โ€” the same government Canada is currently in a trade war with, led by an administration openly antagonistic to Canadian sovereignty โ€” to access Canadian data directly. Citizen Lab researchers Cynthia Khoo and Kate Robertson have warned in writing that such an agreement would extend the reach of U.S. law enforcement into Canada’s digital terrain to an unprecedented extent.

That is the part of the story Canadians have not been told. Not the part about parliamentary procedure. Not the part about which committee voted on what amendment. The part about whether the country is about to build, under its own legislation, the access path through which it can most efficiently be surveilled โ€” by allies, by adversaries, and by ordinary criminals โ€” and to keep that path open by law.

The Five Eyes argument, examined

The government’s defence of Bill C-22 rests largely on a single line. Canada is behind its Five Eyes partners โ€” the United States, United Kingdom, Australia, and New Zealand โ€” and needs to catch up.

The line is misleading.

Michael Geist, the University of Ottawa’s Canada Research Chair in Internet and E-commerce Law, has been picking at it for months. Geist is arguably the country’s most prolific independent voice on this file, writing extensively on his own site at michaelgeist.ca. After the US congressional letter landed, his verdict was that the government’s claims “ring hollow.”

The reasoning is straightforward.

The United Kingdom passed the Investigatory Powers Act in 2016 โ€” the so-called Snoopers’ Charter โ€” and its use has included reportedly issuing a secret order to Apple to weaken iCloud encryption. It is the regime no privacy-respecting democracy wants to copy. Australia passed its Telecommunications and Other Legislation Amendment (Assistance and Access) Act in 2018; its own independent monitor has repeatedly recommended reform, the Law Council of Australia has documented its harms, and Australian tech companies have restructured or relocated to escape its reach.

New Zealand has not gone the encryption-backdoor route. The United States has FISA, CALEA, and the CLOUD Act โ€” but no law forcing American companies to insert backdoors. Apple, Signal, and Meta operate inside the US with end-to-end encryption intact.

When Anandasangaree says Canada is behind the Five Eyes, the honest version is narrower. Canada is behind the UK and Australia โ€” the two countries whose own experts are now telling Canada not to repeat their mistake. Last year, France and Sweden abandoned similar proposals. The European Union, in its agreement on online safety, guaranteed robust encryption protections.

Canada is not catching up. Canada is being asked to go further than most of its democratic peers.

Geist has likened the government’s dismissive response to its handling of the Online News Act โ€” the playbook that ended with Meta blocking Canadian news links on Facebook and Instagram and never restoring them. Dismiss the critics. Insist the bill is misread. Refuse to amend. Watch the consequences happen anyway.

What is and isn’t on the public record

Bill C-22 is going through Parliament. It will be voted on at second reading, sent to committee, and voted on again. That is how Canadian bills become law.

What has not happened is the public conversation that should accompany a law of this scope.

The original lawful access provisions were buried inside an omnibus border bill where most Canadians would never have read them. The standalone Bill C-22 was introduced quietly in March, with no prime-time press conference explaining to households that their iPhone, their Signal app, their VPN, and their cloud backups may all be reshaped by a law most of them have never heard of.

Committee hearings have been compressed. The minister’s response to substantive expert objections โ€” from Apple’s cryptographers, from the Citizen Lab, from the National Security and Intelligence Review Agency, from the Canadian Chamber of Commerce, from two US House committee chairs โ€” has been to say they are misinterpreting his bill.

No broad-based public consultation. No referendum. No household-level explanation. Most Canadians cannot tell you what Bill C-22 does because no one in authority has tried to tell them.

That is what is wrong with this picture.

The question Canadians have not yet been asked

If Bill C-22 passes in its current form, several outcomes are now visibly on the table. Some of the world’s most privacy-protective services may leave the Canadian market, leaving Canadians on a tier of digital security that does not exist in any other peer democracy. Mandatory metadata retention will create new repositories of personal data that hackers, foreign adversaries, and ordinary cybercriminals will treat as a target. American technology companies, under pressure from their own Congress, will weigh whether the Canadian market is worth the compliance cost. Constitutional challenges will follow.

None of that is alarmism. It is what the people who design encryption, the companies that operate the services, the country’s own intelligence oversight body, and a foreign legislature have all said, in writing, in the past six weeks.

The question Canadians have not yet been asked, in plain language, is whether this is the country they want to live in.

It would be useful to ask them. While the bill is still on the floor. Before the silence becomes law.


Sources and further reading: Michael Geist, michaelgeist.ca (multiple posts, Marchโ€“May 2026); National Security and Intelligence Review Agency submission to SECU, April 17, 2026; Centre for Free Expression letter to the Prime Minister, April 2026; Globe and Mail reporting by Anja Karadeglija, May 2026; CBC News reporting by Catharine Tunney, May 2026; The Hill Times, May 22, 2026; joint letter from U.S. House Judiciary and Foreign Affairs Committees, May 7, 2026; Public Safety Canada statements; Apple, Meta, Signal, NordVPN, ExpressVPN, Windscribe, and Canadian Chamber of Commerce public statements.

Leave a Reply

Your email address will not be published. Required fields are marked *