Canadas Bill C-22 Mandates Encryption Backdoors and Metadata Retention with Five Eyes Data Sharing Implications
The Electronic Frontier Foundation reports that Canada's
Joint opposition from House Judiciary and Foreign Affairs committee chairs turns C-22 into a bilateral security liability, undercutting Ottawa's argument that the bill aligns Canada with Five Eyes partners. The "systemic vulnerability" carve-out is vague by design, but that vagueness undermines enforceability. The UK Apple precedent and the 2024 Salt Typhoon breach establish that companies will exit privacy features rather than engineer backdoors. Ottawa may calculate that US Congressional objections reflect tech-industry lobbying rather than a durable national security concern and that Five Eyes interoperability arguments neutralize domestic resistance, though internal government deliberation is thinly sourced. Passage with backdoor provisions intact by end of 2026 is
4 sources
- Canadas Bill C-22 Is a Repackaged Version of Last Years Surveillance Nightmare -
Electronic Frontier Foundation - U.S. Congress warns Ottawas lawful-access bill could weaken defences against hackers -
The Globe and Mail - House GOP warns Canada its new cybersecurity bill could pose privacy risks to Americans -
House Judiciary Committee - Canadian Government Proposes Legislation To Enable Encryption Backdoors -
Center for Democracy and Technology