Last year, the government pushed Bill C-2, which would erode Canadian digital rights in the name of “border security.” The bill was so bad it didn’t even make it to committee because of the backlash from the privacy community. Now, the spring’s worst sequel, C-22, aka The Lawful A
What the Documents Show
According to the Electronic Frontier Foundation, this legislative persistence reveals a fundamental lack of responsiveness to legitimate public concern about government overreach in the name of border security. The bill's machinery is straightforward and sweeping: it would force digital services—including telecoms, messaging apps, and others—to record and retain metadata about their users for a full year. The government frames this as necessary for security, but metadata reveals intimate details about our lives: who we communicate with, where we go, and when we do so. Once stored, this information becomes a target. Expanding metadata collection creates expanded incentive for bad actors to breach company systems and steal that data.
Follow the Money
The mainstream press has largely treated this as a technical policy debate, missing that the bill essentially mandates companies become repositories of surveillance gold. Most alarming is C-22's mechanism for creating backdoors into encrypted services. The bill allows the Minister of Public Safety to demand that companies weaken their security, provided these demands don't introduce a "systemic vulnerability." This language is the escape hatch that swallows the rule. Canadian officials have publicly stated they believe surveillance can be added to encrypted services without creating systemic vulnerabilities—a claim that contradicts basic cryptography. Surveillance of encrypted communications *is* a systemic vulnerability by definition. The definitions of both "systemic vulnerabilities" and "encryption" in the bill remain deliberately vague, giving government room to reinterpret them as needed.
What Else We Know
The bill also dramatically expands information sharing with foreign governments, including the United States, while simultaneously banning companies from publicly disclosing that they've received these surveillance orders. This silencing provision means users have no way of knowing their communications are being monitored. Meanwhile, the overbroad definitions could extend these backdoor demands to apps and operating systems, far beyond the border security justifications offered in public debates. For ordinary Canadians, the implications are concrete. More stored data means more security breaches. More backdoors mean less functional encryption.
Primary Sources
- Source: EFF
- Category: Surveillance State
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.
This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a FOIA release, an agency's own policy or procurement document, court filings from surveillance litigation, or the wire reporting linked in the body) and reports what that source states, attributed to it — it does not allege intent behind a surveillance program beyond what the record shows. Part of our Surveillance State hub. Found an error? Tell us.
