Lawful Access v. Access to EU Markets - Part 1 (Five Laws)
#Privacy #Cybersecurity #Sovereignty #Governance #DataProvenance #Ethics #PrivacyBriefing
Bill C-22 and the Risk to Our Burgeoning Relationship with the European Union
THE PRIVACY BRIEFING Reforming Canada's Privacy Regime — Article 1
On March 12, 2026, the federal government introduced Bill C-22 — the Lawful Access Act, 2026 — after its predecessor Bill C-2 collapsed under near-universal criticism for its warrantless access provisions. The bill has two operative parts. Part 1 modernizes Criminal Code tools for law enforcement to compel subscriber information and transmission data, subject to judicial oversight. Part 2 establishes the Supporting Authorized Access to Information Act — the SAAIA — requiring electronic service providers to build and maintain technical infrastructure enabling law enforcement and CSIS to intercept communications and access data. Its current status is that it is in first reading in the Senate - so there is time to address changes, if the federal government wants to.
Part 1 is a genuine improvement. The broad warrantless demand power is gone, replaced with a narrower "confirmation of service demand" limited to whether a telecommunications provider has served a specific person. Production orders require judicial authorization.
Part 2 is where organizations need to pay attention, so I wanted to lay out the impacts for organizations, and conclude with how this bill undermines Canada's efforts to diversify its trade with the European Union.
Bill C-22's Threat to Adequacy with the EU
As someone who worries about our adequacy arrangements with the European Union - a vital component, should anyone forget, of the trade arrangements we have with the EU - this bill presents a real possibility of losing that status. I don't have to speculate - EU based groups have already raised their concerns. They see Bill C-22 not only weakening encryption, but also that the extensive retention requirements of metadata relating to their customers’ activities as “irreconcilable with EU law.”
A further consideration is the sharing of information with the United States. It seems like this is legislation by nostalgia, that the provisions of a bill drafted before the current political climate evolved should continue to be carried forward by our government. This requires a good hard look at whether Canadian citizens (and by extension, EU citizens), can adequately protected through agreements with the US.
Your Organization Might Be in Scope
The SAAIA defines electronic service provider as any entity offering services involving the creation, recording, storage, processing, transmission, reception, or making available of information in electronic or digital form. If your organization provides a digital service in Canada, you are likely caught — whether you are a telecommunications carrier, a cloud provider, a SaaS platform, a health information system, a legal technology provider, an e-commerce company, or a university running a learning management system.
The bill distinguishes "core providers" — designated by regulation — from the broader class. Core providers face the heaviest obligations: developing and maintaining interception capabilities, installing devices enabling authorized access, retaining metadata for up to twelve months. But Section 7 gives the Minister power to extend those same obligations to any electronic service provider by order. No sector-specific carve-outs. No proportionality test tied to what your organization can actually do to assist an investigation.
For organizations navigating PIPEDA's consent-based framework, this creates a direct tension. Section 7(3)(c.1) permits voluntary disclosure to law enforcement without consent — but that was designed for targeted, case-by-case cooperation, not for standing surveillance infrastructure as a condition of doing business.
The Infrastructure You Build Becomes the Target
Michael Geist has provided the most comprehensive analysis of C-22's architecture — the metadata retention requirements, the lowered evidentiary standards, the international production order mechanism, and the systemic vulnerability contradiction. David Fraser and Robert Diab added further detail through the Law Bytes roundtable. The statutory critique has been provided, and I don't think I can improve on it here. What follows is the exposure it creates for organizations' data governance.
The SAAIA's capability requirements create standing surveillance infrastructure that exists whether or not anyone is under investigation. That infrastructure is a permanent attack surface. In late 2024, Chinese state-sponsored hackers known as Salt Typhoon exploited the lawful intercept systems US carriers were required to maintain under CALEA, compromising nine major carriers. They obtained metadata on over a million users, real-time call recordings involving senior political figures, and nearly complete lists of phone numbers under active law enforcement surveillance. The infrastructure built to catch criminals became the instrument through which a foreign intelligence service identified who was being watched.
When the UK Home Office issued Apple a secret technical capability notice demanding access to all iCloud data worldwide, Apple withdrew the service entirely. Australia's Assistance and Access Act, despite including a systemic vulnerability exception, has drawn sustained criticism from its own Information Commissioner. The SAAIA's core provider obligations under ss. 5(2)(a) and (b) are functionally the Canadian equivalent.
The Safeguard That Contradicts Itself
C-22 includes what looks like a safeguard: a provider is not required to comply if compliance would introduce a "systemic vulnerability." But the enforcement framework says the opposite. Sections 5(5) and 7(5) say you are "not required to comply." Section 12 says you "must comply" with a ministerial order. Section 13 gives orders primacy over regulations.
There is no mechanism to resolve this. No accessible process for challenging an order you believe would compromise your systems. The definition of "systemic vulnerability" is vague enough to be litigated for years. And the entire framework — including ministerial orders — must be kept secret.
The Data Ends Up on Foreign Infrastructure
There is a dimension to the retention obligation that gets less attention: where the data will actually sit. Canadian telecommunications providers and digital service companies do not, for the most part, operate their own data centres. They run on AWS, Azure, and Google Cloud — infrastructure controlled by US-headquartered companies, subject to the US CLOUD Act, accessible to US law enforcement through processes requiring neither notice to Canadian authorities nor review by Canadian courts.
A twelve-month mandatory metadata retention obligation does not produce a Canadian-controlled data store. It produces a repository parked where a foreign government can search it without a Canadian warrant. For organizations with cross-border data obligations — GDPR compliance, contractual data residency commitments — the bill creates a compliance conflict it does not acknowledge. As mentioned above, this very legal infrastructure threatens our ability to commit that the protections of our privacy regime retain adequacy with the requirements of GDPR.
The cost falls unevenly. Global platforms absorb compliance costs across worldwide operations. A mid-sized Canadian telecom or SaaS provider cannot. The effect accelerates concentration of Canadian communications infrastructure in foreign-controlled hands.
The Window for Action
The bill is at first reading in the Senate, while the regulatory framework is still unwritten. This is the window of opportunity, and the consequences of failing to revise the bill should be understood.
Organizations caught by the ESP definition — which is most organizations providing digital services — should be mapping the data they hold that could be subject to retention obligations and identifying where it sits and under whose legal jurisdiction. The designation of core providers, the terms of ministerial orders, and the definition of systemic vulnerability will all be determined by regulation. Organizations that participate in that consultation shape the framework; organizations that wait inherit it.
The structural reform that matters is replacing mandatory mass retention with expedited preservation — the model the Budapest Convention already establishes in Articles 16 and 17. Preservation operates on specified data, for a defined period, on judicial authorization. Retention warehouses everything in advance of any suspicion. Tying the ESP definition to communications infrastructure control, requiring judicial authorization for capability mandates, establishing tiered data categories, and bringing transparency to the regulatory conversation — these are the reforms that make lawful access workable without turning every digital service provider into an instrument of state surveillance. And, importantly, this helps us retain our adequacy.
For organizations already operating under PIPEDA, the SAAIA will layer a mandatory retention and capability regime on top of a consent-based framework that was never designed to accommodate it. Businesses need to review privacy notices, data retention schedules, and vendor agreements now and identify where mandatory retention conflicts with existing data minimization commitments and contractual obligations to clients — before the regulations are written, not after.
Bill C-22 inverts the logic of R v Spencer and R v Marakah, which established that Canadians hold a reasonable expectation of privacy in communications metadata because of what that data reveals. You cannot solve a pre-collection problem with post-collection oversight.
The architecture our federal government needs to build — targeted preservation, judicial oversight, proportionate capability requirements, transparency — is the one that works, is consistent with our values, and helps to preserve our increasingly valuable relationship with the EU.
About the Author
Constantine Karbaliotis is the principal of Privacy
• Legal™ (privacylegal.ca), a Canadian privacy, AI governance, and cybersecurity law practice. He is the author of
The Governance Gap: AI, Privacy, and the Accountability Imperative, the positioning paper that anchors
The Privacy Briefing series.
© 2026 Privacy • Legal™ | All rights reserved.
Recent Posts






