The federal government’s proposed legislation on lawful access will enable criminals and other bad actor to more easily cyber-attack firms and organizations, tarnish Canada’s reputation as a safe business operating environment, and trigger some Internet services providers to leave the country, say industry and Internet experts.
Bill C-22, An Act respecting lawful access, which passed in the House of Commons and will now be reviewed by the Senate, is deeply flawed and should not become law as is, they said during a webinar by the Ottawa-based Centre for Canadian Innovation and Competitiveness.
Ottawa has said the intent of Bill-C22 is to update police powers for the digital age, to provide Canada law enforcement and intelligence agencies officials with the tools necessary to investigate and gather evidence of serious online crimes.
But Bill C-22 faces widespread opposition from a broad coalition of tech companies, civil liberties groups, privacy advocates and international observers due to its broad surveillance powers and potential impact on privacy.
Bill C-22 as worded undermines encryption and other tools that provide security online, “so to see a bill that could potentially create orders that undermine that security is very, very worrying,” said Natalie Campbell (photo at left), senior director of North American government and regulatory affairs for the Internet Society, based in Reston, Virginia and Geneva, Switzerland.
“Encryption is a tool that keeps us safe from crime,” she said. “I don’t think it’s feasible to try to prevent crime by making everyone more vulnerable to crime, which is what this bill does.”
The bill is much too large in scope, Campbell said, adding: “I think the part about the scope that surprises me is just the fact that it could apply to anyone. The Internet Society believes that this law shouldn't pass because of the threats to pose to Internet security and trustworthiness as a whole.”
Given Bill C-22’s scope, it could apply to any electronic service provider, including Canada’s 99 percent of SMEs “that are already struggling with cybersecurity,” Campbell said. “It's getting harder and it's getting more expensive to deal with breaches, and that number is going to absolutely ramp up under an environment where orders could come under C-22.”
The bill also applies to non-profits and other organizations that offer services online that might even be less equipped to be keeping up with cybersecurity norms, she said. “But also what happens when they get an order and they probably can't even consult an IT specialist or a lawyer to see if it even creates systemic vulnerability in the first place? The whole secrecy aspect of this is another layer of danger to the risk that this bill creates.”
Ulrike Bhar-Gedalia (photo at right), executive vice-president of public policy at Mississauga, Ont.-based TECHNATION, said Bill C-22 will create “back doors” to public and private online systems that criminals and other bad actors can walk through.
“There is no specific back door or guarantee that only the police can walk through,” she said. “I think any systemic vulnerability or encryption – let’s say weaknesses – puts companies at risk even in terms of their own reputation.”
“Who wants to do business or engage with companies where you know that your privacy and data is at stake?” Bhar-Gedalia said.
“And that's not only on a domestic level, that's also globally. As our global competitors or allies look to Canada, they would like to engage with companies and partners that respect privacy and security. So, [Bill C-22) has really almost a global, a broader impact, not only domestically.”
Bill C-22 goes further than legislation in other Five Eyes countries
The federal government has argued that Bill C-22 will align Canada with its Five Eyes allies (the U.S., U.K., Australia and New Zealand), all of which already have implemented lawful access regimes to modernize digital investigative tools.
But Michel Liboiron (photo at right), head of public policy and government relations at Shopify Inc., said Bill C-22 casts too wide a net and risks creating an expanded surveillance regime that could harm homegrown companies and jeopardize Canada’s push to improve productivity and economic growth.
In looking at the capabilities of what other Five Eyes countries actually have in their legislation, Bill C-22 “is not necessarily something to bring us at par to a standard that already exists or a convention that has been reached. It is far more about creating a new sphere, a new standard and a much broader system that exists in other Five Eye Nations,” Liboiron said.
For example, law professor Michael Geist, Canada Research Chair in Internet and E-commerce Law in the Faculty of Law at the University of Ottawa, has pointed out that, unlike the provision in Bill C-22, the U.S. has no federal law requiring mandatory retention of metadata, and the Court of Justice of the European Union struck down the EU Data Retention Director as being incompatible with fundamental rights.
Yet Bill C-22 requires retention of metadata – digital communication traces such as transmission data, location details and device identifiers, but not the email or text itself – for six months.
The stored metadata would amount to “a comprehensive surveillance map of virtually every Canadian,” Geist told the House of Commons Public Safety Committee.
Liboiron said that for Canada’s tech sector, doing business under Bill C-22 involves “weakening cybersecurity, and granting these or allowing for these backdoor accesses sends a signal to the rest of the world with whom we are competing with.”
If the current process for Canadian law enforcement and intelligence agencies to access data is too slow, the federal government should be focusing on speeding up that process and access to data where it already exists “and grant access to it through a lawful passageway, not a backdoor access that is creating vulnerabilities,” Liboiron said.
Several international technology and privacy companies operating in Canada have threatened to leave the Canadian market or pull specific services if Bill C-22 becomes law. They include encrypted messaging app Signal, virtual private network provider NordVPN, and privacy platform DuckDuckGo.
Apple, Google and Meta also oppose Bill C-22, warning that the bill creates severe cybersecurity vulnerabilities and back doors.
“If companies pull out of Canada, others might be thinking, ‘I wonder what's next?’” Gedalia said. “Because you don't know what other legislation might be coming our way, for companies to say, ‘Is Canada a safe market for me?’”
Gedalia said making Bill C-22 law also means there might be less competition going forward if some companies pull out of the online market or restrict their offerings, which means fewer offerings and services for end uses to choose from.
Liboiron said Shopify is arguing that “we need to be very forthcoming in the legislation and not give full discretion to the [regulations].” As it stands now, “nobody knows who’s in and who’s out” of Bill C-22.
Currently, there’s a mature tech sector in Canada with a lot of room for growth and a need for growth, he added.
But if Canadian and international tech companies aren’t seeing an ecosystem that allows them to thrive, “that's not a good look for Canada,” he said. “It’s a barrier to growth. It’s a barrier to growing your market share in other places in the world.”
Cyber-criminals using AI to more quickly exploit back doors into online systems
Campbell noted that cyber-criminal organizations around the world look for back doors into online systems and are now using AI to more quickly identify and exploit them.
“That attack window has collapsed from months to minutes and hours now. So these [back doors]could be exploited without services even knowing about them, and the repercussions can be pretty significant,” she said.
Canada shouldn’t overlook how devasting it could be for a small business to get hit by a cybersecurity breach enabled by Bill C-22, Campbell said. “Who's going to want to get products from Canada if we know that a regulatory environment exists that could have built-in systemic vulnerabilities into any one of those services?”
“That reputation is also going to spread among cybercriminal organizations who are going to be more and more looking at Canada for very juicy targets that they're definitely going to try and crack into. And having access to tools that can spot and exploit these in hours or even minutes just increases that landscape tremendously,” she said.
Law enforcement and intelligence agencies officials will be able to get secret orders to “to facilitate access to information in a way that creates backdoors into any part of the Internet ecosystem that touches Canada,” she said. “That is a significant vulnerability that puts everybody, everyday people on services, at greater risk of crime.”
The wording in Bill C-22 makes every online service on the Internet in scope, Campbell said. “And what's especially problematic is that it's one thing to think about services that we interact with very directly as users to be in scope, but there's a lot of services that exist on the Internet that we don't interact with directly that would also be in scope,” she said.
Those include services that have very specific functions as part of making the Internet function, “and we're never built to do things like collecting and retaining metadata nor facilitating surveillance mechanisms for law enforcement.”
The foundation of the Internet’s security relies on tools and technologies like encryption, essentially in every layer of the stack, Campbell said.
“It is very terrifying to think that there could be laws being passed that weaken protections that folks take for granted when we are doing things like online banking or online shopping that could be weakening those protections and introducing risk to everyday people without them even knowing it,” she said.
The Internet Society is very empathetic to the goal of supporting law enforcement to prevent cybersecurity crime, and there are ways to achieve that goal without breaking, undermining or circumventing encryption, she said.
“Unfortunately, Bill C-22 doesn't go at it that way and creates pretty significant risk for the Internet itself, which is very concerning, deeply, even at an individual level,” she added.
“So it's very irresponsible and reckless to be forcing services that we have no choice but to use [such as online banking] to be making that tough choice of whether to weaken security or perhaps even withdraw their services altogether because they're not willing to jeopardize the security of their users.”
Campbell noted that the Internet Society commissioned a study in 2022 that looked at the economic impact of laws that undermine encryption. One law examined was Australia’s Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018.
Australian tech companies said their reputation had taken a hit just by that legislation being passed, without any orders being issued under the law. Once company reported about $1 billion in losses, she noted.
Campbell said she thinks about the impact on reputation for Canada, which is investing in AI innovation and more homegrown talent to increase economic resilience.
Bill C-22 will hinder growth in not only in Canada’s tech sector but the country’s business sector as a whole, she said. “It's really disheartening. If I was in the shoes of any one of my colleagues here today, I couldn't imagine the potential losses that a company might be facing.”
Bill C-22 is opposed by civil rights and privacy organizations
The Canadian Civil Liberties Association joined other civil liberties organizations and researchers in a statement in June denouncing the government’s move to end debate on Bill C-22, calling the bill a controversial legislative proposal that will significantly expand surveillance in Canada for years to come.
A group of 25 civil rights and privacy organizations and experts signed an open letter to Prime Minister Mark Carney and every Member of Parliament calling for the full withdrawal of Bill C-22. Another group of privacy law scholars and lawyers signed an open letter calling for amendments to Bill C-22.
A significant majority of Canadians oppose or want constraints on surveillance powers like those proposed in Bill C-22, according to a survey by Public First, commissioned by the Center for Democracy and Technology.
The polling data reveals that Canadians generally believe the government should not be able to order a technology company to provide access to all their users’ information in order to investigate potential crimes (43 percent), or that such orders should at least be subject to some form of public disclosure or parliamentary oversight (29 percent).
Very few Canadians believe the government should be able to secretly issue such orders and prohibit technology companies from notifying the public when they receive them (10 percent).
A majority of Canadians believe the security risks to the public of allowing law enforcement access to encrypted messages outweigh the benefits to law enforcement, compared to a minority who believe the benefits to law enforcement outweigh the security risks (54 percent to 24 percent).
Canadians are overwhelmingly concerned that allowing law enforcement to access encrypted messages could potentially increase fraud, data leaks and cybercrime (83 percent).
Nearly three-quarters worry that government access to encrypted messages could discourage free speech or open communication across the country (73 percent). And many Canadians say they would change their own behavior if law enforcement had access to their encrypted messages without prior court approval.
Webinar moderator Lawrence Zhang (photo at right), head of policy for the Centre for Canadian Innovation and Competitiveness (which is affiliated with the Washington, D.C.-based Information Technology & Innovation Foundation), noted that it has been legal for decades to compel companies to hand over data they already hold, when a judge orders it.
However, requiring companies to build and maintain technical capability to produce communications when ordered is a different task, he said.
There are several Canadian virtual private networks (VPNs) that have spoken up against Bill C-22, including because its provisions will make them less competitive in the market for VPNs, Zhang said.
“What I think these companies have said essentially is, ‘I'm leaving, I'm out of here if this bill passes and I can't function properly as a VPN if this bill passes.’”
Liboiron said he would like the Senate to amend Bill C-22 to provide a guarantee that encryption will be protected and clearly spell out who the intended target is for the requirement to retain metadata.
Campbell said the House of Commons didn’t get sufficient time to study Bill C-22 before it was passed. The Senate now has the opportunity to slow down the process and take the time to study and understand “the basics and the risks that this bill creates,” she said.
“This is an opportunity to understand the gravity of risk that this bill will create, not just to services that get these orders, but to individual people, law-abiding citizens and others in Canada.”
R$