Much of the discussion around the new lawful access bill (Bill C-22) has focused on provisions that improved upon Bill C-2, notably the decision to scrap the warrantless information demand power by requiring judicial oversight for access to subscriber information. Yet despite that improvement, there remain serious privacy concerns with the government’s latest iteration of lawful access. Buried in the second half of Bill C-22 is a provision granting the government the power to require “core providers” to retain categories of metadata, including transmission data, for up to one year. This is mandatory metadata retention that would require telecom and electronic service providers to store information about the communications of all their users, regardless of whether those users are suspected of anything. It is one of the most privacy invasive tools a government can deploy and the international experience suggests that there are major privacy risks.
Archive for March 17th, 2026

Law Bytes
Episode 278: Ben Waldman on Gander Social and the Challenges of Building a Sovereign Social Network
byMichael Geist

August 10, 2026
Michael Geist
Search Results placeholder
Michael Geist on Substack
Recent Posts
What If the U.S. Demanded This? The Cloud Provider Conditions Behind Canada’s EU Digital Pivot
Ontario is Done Waiting for Universities to Act on Campus Antisemitism
Is Compromise on Encryption Possible? Why Bill C-22’s “Minor Opening” Leaves the Central Question Unanswered
The Wrong Target: Why the CBC Should Be Asking About the Yom Kippur Protesters, Not the Journalist Who Reported on Them
Buried in Bill C-39: The Enabling Digital Trade Act Brings Canada Its First Federal Electronic Trade Documents Law

