Bill C-22, the government’s lawful access legislation, is awaiting Senate consideration this fall with the encryption provisions likely to be the centre of attention given diametrically opposing views from law enforcement and technology companies and experts. Public Safety Minister Gary Anandasangaree told the Toronto Star earlier this month that the bill strikes “the right balance” on encryption, claiming that cracking encryption is “off limits” except in “extenuating circumstances” where there is a “minor opening,” and that “everybody has had to have some water in their wine.” The government’s approach follows the typical legislative playbook of seeking a middle ground that stakeholders can (sometimes reluctantly) live with. Yet the past few weeks have produced an unusual situation in which both sides say no viable middle ground exists. Police claim the bill’s encryption provisions do little to change what they can obtain under existing law. Nearly two dozen technology companies and industry groups argue the same provisions leave every user at risk since even partial weakening of encryption undermines its effectiveness.
The government’s own position on the encryption rules has been somewhat inconsistent. For most of the year, officials insisted there was no need for compromise, arguing the bill was “encryption neutral.” The Minister added that the bill “was never meant to breach encryption,” and dismissed warnings from Apple, Meta, Google and civil liberties groups as misinformation. Nevertheless, the bill was amended to add that nothing in the Act compels a provider to decrypt information unless it supplied the encryption and holds the key. The government also changed the “systemic vulnerability” definition by linking it to “recognized international technical standards.” However, a carve-out excludes information about persons already subject to a warrant or other lawful authority.
Law enforcement initially avoided demanding access to encrypted messaging. The Canadian Association of Chiefs of Police’s March statement supporting Bill C-22 pointed to criminals “using digital platforms or encrypted communications” and their committee testimony emphasized “going dark” rather than decryption. That began to change in May when the RCMP told the House committee that law enforcement wanted the bill because it would provide access to encrypted communications, and OPP Commissioner Thomas Carrique has since told the Star that encryption remains “a significant sticking point,” and that the bill will leave police “hindered in our ability to prevent and solve crime.” In other words, the exception isn’t enough for law enforcement, which wants a decryption mandate.
The technology sector’s position, set out in a recent public letter, is that even after the amendments the bill “could still require us to weaken encryption or build interception capabilities,” and that “a backdoor for law enforcement is a backdoor for everyone.” This reflects longstanding security views on weakening encryption. Apple warned the Australian Parliament in 2018 that “any process that weakens the mathematical models that protect user data for anyone will by extension weaken the protections for everyone,” and that the notion of access created “just for only those sworn to uphold the public good” is “a false premise.” The risk comes from building the capability at all, since once it exists, there is no assurance it will be used only under legislative exceptions or that others won’t find and exploit it.
Where does that leave Bill C-22? If the bill covers only data already held by providers, then the police are right that it does not deliver the access to otherwise unreadable encrypted communications they are seeking. If it reaches the targeted capability the new carve-out appears to permit, it touches encryption for everyone and the companies are right that the damage cannot be limited to the target.
The Senate should draw the obvious lesson that these hearings should not be about whether the bill has struck the right compromise. Rather, the legislation has to pick a side. Senators need answers from law enforcement about the implications of excluding a decryption mandate from the bill, given that police can often obtain metadata, subscriber information, cloud backups, and device content with judicial authorization. Conversely, they should ask the technology and security witnesses about the impact of decryption capabilities in light of the risk that Canada could follow the UK’s experience of Apple withdrawing Advanced Data Protection and Canadian companies suggesting they may be forced to leave the market.
Parliament can modernize lawful access while expressly protecting end-to-end encryption, or it can compel access to encrypted communications and accept the security and economic consequences. The House of Commons tried to avoid that choice with a “minor opening” fix that does not work. My testimony before the House makes it clear that I think weakening encryption is a bad idea, given the security risks and the UK experience, which suggests companies warning they may exit Canada are not bluffing. The fix is not complicated: remove the carve-out for warrant targets from the systemic vulnerability definition and adopt the Privacy Commissioner’s recommendation, based on Australia’s law, that the definition include any action that would render systemic methods of authentication or encryption less effective.












PAB Learn Lead & Grow provides online MBA guidance and career counselling for students, graduates, and working professionals. Get support with program selection, eligibility, documentation, and the admission process.