(LifeSiteNews) — Major privacy-focused tech companies are threatening to leave Canada if Bill C-22 (the “Lawful Access Act”) becomes law in Canada. The legislation has drawn sharp criticism from opposition parties, cybersecurity experts, and technology firms due to its loose requirements on data retention and overall security concerns.
Online platform Signal, which prides itself on end-to-end encryption, told The Globe and Mail that they would “rather pull out of the country than be compelled to compromise on the privacy promises we have made to our users.” Udbhav Tiwari, Signal’s vice president of strategy and global affairs, emphasized that end-to-end encryption is incompatible with the types of exceptional access the bill could demand.
DuckDuckGo, known for its privacy-oriented search engine, confirmed through CEO Gabriel Weinberg that it would also withdraw its VPN service from Canada if the bill passes in its current form.
NordVPN, one of the largest VPN providers in the entire world, also responded to the legislation in an X post, stating that they “will consider all viable options,” including “limiting, or if necessary removing” their presence from Canadian jurisdiction.
Hello, Johnny. We are actively reviewing draft Bill C-22 and will participate in any relevant consultation process available to us. However, should Bill C-22 pass in its current form and if we are subjected to mandatory obligations, there isn’t a scenario in which we would…
— NordVPN (@NordVPN) May 15, 2026
Introduced in March 2026 by Public Safety Minister Gary Anandasangaree, Bill C-22 attempts to update lawful access rules for police and the Canadian Security Intelligence Service (CSIS). The bill is divided into two main parts. Part 1 updates existing provisions in the Criminal Code and other statutes to facilitate timelier access to basic subscriber information and data during investigations, including new mechanisms like “confirmation of service” demands.
Part 2, the “Supporting Authorized Access to Information Act,” goes further by imposing obligations on a broad range of “electronic service providers” (including messaging apps, VPNs, search engines, and cloud services). These include requirements to develop and maintain technical capabilities that authorize government access to information, as well as potential regulations that would mandate the retention of specified metadata categories — such as communication patterns, locations, and timestamps — for up to one year.
READ: Google warns Canadian internet bill would lead to ‘surveillance infrastructure’
The government has justified its actions by stating that the bill includes safeguards to respect Charter rights, does not mandate backdoors into encrypted services, and is needed to modernize tools for addressing serious crime and national security threats in line with other G7 countries. However, critics — including major tech companies, privacy experts, and civil liberties organizations — warn that the bill’s vague language surrounding “technical capabilities,” combined with its broad metadata retention requirements, risks undermining end-to-end encryption, while imposing heavy compliance costs and new security vulnerabilities on both service providers and ordinary Canadian users.
As a result of this, the bill has prompted sharp responses from several technology firms. Apple has expressed reservations about possible impacts on user data security. Other companies, including Meta, Google, and Canadian VPN providers such as Windscribe, have also voiced a multitude of concerns.
The bill has also managed to unite Canadian political parties against it, from one end of the spectrum to the other. The Conservative Party and its leader, Pierre Poilievre, have come out strongly against the legislation. Poilievre declared that the bill is a Liberal attempt to “try to turn the entire tech sector into a gigantic surveillance arm of the state.”
On Bill C-22, Poilievre states: “Here we have another bill where they [Liberals] try to turn the entire tech sector into a gigantic surveillance arm of the state.” pic.twitter.com/pHOwMx5aeM
— Juno News (@junonewscom) May 27, 2026
Poilievre describes the legislation as the Liberals “going after the good guys,” comparing it to their attempt to increase gun control on law-abiding citizens, along with an increase of government censorship that targets non-criminal, free speech-exercising citizens.
On the other side of the political spectrum, the Green Party, specifically leader Elizabeth May, has also expressed disdain for the bill and vowed not to support it.
Asked if she supports Bill C-22, Elizabeth May replied: “Not a chance.”
She calls the bill “appalling,” warning it could force tech companies to insert spyware for police, and said it needs major amendments.
The Public Safety Minister then says, “we need to get you a briefing.” pic.twitter.com/YnTftKzCVi
— Juno News (@junonewscom) May 27, 2026
May called the spyware bill “appalling,” stating that “we are basically setting it up for tech companies to insert spyware to report on us to the police.” The Green Party leader went on to say that the bill would need “lots of amendments, at a minimum.” The aforementioned public safety minister, as well as Secretary of State Ruby Sahota, followed up May’s statement by laughing and stating that “we need to get you a briefing.”
Bill C-22 passed second reading on April 20 and has been under study by the House of Commons Standing Committee on Public Safety and National Security (SECU). Committee hearings featuring testimony from tech companies (such as Apple), privacy experts, and other stakeholders wrapped up in late May, with discussions around possible amendments, particularly on encryption and metadata issues.
As of early June, the bill remains at the committee stage, with no report yet tabled for consideration at report stage or third reading. The government has indicated potential openness to some amendments while aiming to advance the legislation before the summer break.
