Canada's Bill C-22 and the Encryption Debate
Bill C-22, the Supporting Authorized Access to Information Act introduced in Canada in 2026, aims to modernize lawful access powers by mandating electronic service providers to retain specific metadata for up to one year. The retained metadata includes transmission data, device identifiers, routing details, and location information, while explicitly excluding content of communications, web browsing histories, and social media activities. Major tech firms Apple and Meta have opposed the bill, fearing that its provisions might compel them to weaken encryption by inserting backdoors, compromising user privacy and security. The Canadian government insists the bill is designed to update investigative tools for law enforcement while respecting constitutional rights.
On this page

Key Facts
- Bill C-22 is officially named the Supporting Authorized Access to Information Act (SAAIA), introduced in 2026.
- The bill mandates the retention of metadata by electronic service providers for up to one year, including transmission data, device identifiers, routing data, and location data.
- Communication content, web browsing histories, and social media activities are explicitly excluded from metadata retention.
- Apple and Meta have publicly opposed the bill over concerns that it could compel companies to weaken encryption, including by creating backdoors.
- Public Safety Minister Gary Anandasangaree states that the bill does not compel companies to weaken encryption or create systemic vulnerabilities.
- The bill broadens lawful access powers for Canadian law enforcement and the Canadian Security Intelligence Service (CSIS) but includes procedural safeguards and parliamentary oversight.
- Similar lawful access and encryption debates occurred previously in the United Kingdom, leading to the withdrawal of certain encrypted data protection features by Apple.
Background & Context
Bill C-22 emerged as a revised legislative framework following the government's earlier lawful access attempts described in Bill C-2, which faced significant opposition. The bill reinstates lawful access provisions with modifications addressing concerns over privacy, encryption, and constitutional rights. Key features include the regulation of electronic service providers and metadata retention policies designed to enable faster and effective investigation of security threats. Technology companies like Apple and Meta, which offer end-to-end encrypted communication services, argue that such lawful access requirements risk undermining encryption security, forcing them to implement technical capabilities that could create vulnerabilities. The Canadian government seeks to navigate between enabling law enforcement access and protecting privacy rights within the Canadian Charter of Rights and Freedoms framework.
Why This Matters for Exams / Exam Relevance
Bill C-22 represents a pertinent example of the intersection of technology, law, privacy, and national security. It illustrates ongoing global discussions on encryption, government access, and civil liberties. Understanding its provisions, stakeholder perspectives, and implications is important for competitive exams related to current affairs, cybersecurity, law, and constitutional studies. Questions may focus on the bill’s purpose, metadata versus content distinctions, opposition by major tech companies, and constitutional considerations.
Points to Remember
- Bill C-22 is also known as the Supporting Authorized Access to Information Act (SAAIA), introduced in Canada in 2026.
- It mandates metadata retention — including transmission, device, routing, and location data — for up to one year, excluding message content and web browsing history.
- Apple and Meta oppose the bill due to fears it could lead to encryption backdoors, weakening security.
- Public Safety Minister Gary Anandasangaree affirms the bill does not require weakening encryption.
- The bill includes accountability mechanisms, such as parliamentary review, and narrows some powers compared to earlier proposals.
- Similar debates and legislative attempts have occurred in countries like the UK, impacting related encrypted data protection services.
- The Canadian Charter of Rights and Freedoms serves as a constitutional backdrop to balance security and privacy concerns.
Sources & Further Reading
| Document / Website | Link |
|---|---|
| Canada’s Bill C-22 and Encryption Debate - GKToday | Open Canada’s Bill C-22 and Encryption Debate - GKToday ↗www.gktoday.in |
| Bill C‑22: The Lawful Access Act - Fasken | Open Bill C‑22: The Lawful Access Act - Fasken ↗www.fasken.com |
| Backgrounder – Supporting Authorized Access to Information Act (Bill C-22 – Part 2) - Canada.ca | Open Backgrounder – Supporting Authorized Access to Information Act (Bill C-22 – Part 2) - Canada.ca ↗www.canada.ca |
| Meta urges Canada to amend Bill C-22 over encryption and surveillance concerns | MEXC News | Open Meta urges Canada to amend Bill C-22 over encryption and surveillance concerns | MEXC News ↗www.mexc.com |
| Apple warns Canadian bill could force it to weaken device encryption | 9to5Mac | Open Apple warns Canadian bill could force it to weaken device encryption | 9to5Mac ↗9to5mac.com |