Much of the discussion around the new lawful access bill (Bill C-22) has focused on provisions that improved upon Bill C-2, notably the decision to scrap the warrantless information demand power by requiring judicial oversight for access to subscriber information. Yet despite that improvement, there remain serious privacy concerns with the government’s latest iteration of lawful access. Buried in the second half of Bill C-22 is a provision granting the government the power to require “core providers” to retain categories of metadata, including transmission data, for up to one year. This is mandatory metadata retention that would require telecom and electronic service providers to store information about the communications of all their users, regardless of whether those users are suspected of anything. It is one of the most privacy invasive tools a government can deploy and the international experience suggests that there are major privacy risks.
Post Tagged with: "metadata retention"

Law Bytes
Episode 270: Roundtable on the Bill C-22 Risks for Canadian Tech Companies Featuring VPN Services Tailscale and Windscribe
byMichael Geist

May 25, 2026
Michael Geist
May 11, 2026
Michael Geist
May 4, 2026
Michael Geist
April 27, 2026
Michael Geist
Search Results placeholder
Michael Geist on Substack
Recent Posts
AI for All, Details to Follow: Government Releases a Big-Spending AI Strategy That Is Still Short on the Specifics That Matter
New Privacy Rights in the Morning, Mandatory Metadata Retention in the Afternoon: How Bill C-22 Undercuts the AI Strategy Before It Launches
From Making Web Giants Pay to Making Taxpayers Pay: Government Announces Plan to Kill the CRTC’s Online Streaming Ruling
Digital Self-Sabotage: Why Canada’s AI Strategy Is Set to Fail Before it Even Launches
Why Mark Carney’s Antisemitism Speech Did Not Meet the Moment

