Much of the discussion around the new lawful access bill (Bill C-22) has focused on provisions that improved upon Bill C-2, notably the decision to scrap the warrantless information demand power by requiring judicial oversight for access to subscriber information. Yet despite that improvement, there remain serious privacy concerns with the government’s latest iteration of lawful access. Buried in the second half of Bill C-22 is a provision granting the government the power to require “core providers” to retain categories of metadata, including transmission data, for up to one year. This is mandatory metadata retention that would require telecom and electronic service providers to store information about the communications of all their users, regardless of whether those users are suspected of anything. It is one of the most privacy invasive tools a government can deploy and the international experience suggests that there are major privacy risks.
Archive for March 17th, 2026

Law Bytes
Episode 277: Kate Robertson on the Risks That Lie Behind Canada's Unexpected Signing of the UN Cybercrime Convention
byMichael Geist

June 22, 2026
Michael Geist
Search Results placeholder
Michael Geist on Substack
Recent Posts
Why the Answers to Hateful Content Online are Hiding in the Platforms’ Own Rules
From CCH to ChatGPT: How Canadian Copyright Law Played the Key Role in Deciding a Leading AI Training Data Case in India
Starting Over: Court Filing Confirms the CRTC’s Streamer Contribution Decisions Are Dead With a Full Online Streaming Act Reset to Come
The Name on the Window Was Enough: The Attacks on Kiva’s and the Normalization of Antisemitic Violence in Canada
The Law Bytes Podcast, Episode 277: Kate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime Convention

