Political Football
- 1d
- 4 min read
I wanted to talk about the political football that is Bill C-22 in Canada, so I found a picture of a football, and -
What?
Wrong type of football?
Oh. Right. Sorry. So much soccer lately, and my main interest in the other type of football is the halftime show, particularly when it causes fascist heads to explode, like the 2026 show where Bad Bunny ended up collecting nine Emmy nominations for a performance that was really a full-on attack against Trump and everything he represents, while not mentioning him at all.
Or the 2025 show where Kendrick Lamar won five Grammy Awards for a performance that beautifully illustrated the racial and political issues in the US, while exposing a lot of people to music they knew very little about. And, as an added bonus, Lamar’s performance of Not Like Us was the rap equivalent of dropping his mic right on Drake’s head. Absolutely brilliant!
Disclaimer: While I am Canadian, I feel absolutely no need to support Drake. I consider him an overrated pop artist who sometimes cosplays as a rapper. A-minor!
Getting back to football, though, Bill C-22 was introduced in 1974, in an attempt to give the CFL (Canadian Football League) a government-protected monopoly over professional football in Canada...
Wait. Sorry again. Wrong Bill C-22, and still the wrong type of football... Sigh.
Let’s try this again.
I wanted to talk about privacy, which is a political football that has been back-and-forth and debated for years, but doesn’t often make much progress. And the C-22 part is also confusing, because it’s a designation that is only meaningful if you specify the parliamentary session to which it is tied.
For background, “C” refers to bills introduced in the House of Commons and “S” refers to bills introduced in the Senate, so the correct designation is actually C-22, of the 45th Parliament, 1st session, also known as “An Act respecting lawful access”, or the Lawful Access Act, 2026.
The provisions of Bill C-22 were originally part of Bill C-2 (Strong Borders Act), along with provisions for immigration reform. Eventually, though, Bill C-2 was split into Bill C-12 (Strengthening Canada’s Immigration System and Borders Act) and Bill C-22 (Lawful Access Act).
C-22 contains two main sections. The first grants law enforcement the authority to compel telecom providers to identify whether they have provided services to an individual, if they have “reasonable grounds to suspect” that they have committed a crime, or are about to. Without a warrant, only a yes/no response is required.
The second section is the Supporting Authorized Access to Information Act (SAAIA), and this is the problematic part, to the point that there is a push to split Bill C-22, in the same way that Bill C-2 was originally split.
Concerns about SAAIA have been raised by both companies and privacy advocates. In a review by law professor Michael Geist, he notes that companies including Signal, Windscribe, NordVPN, Apple, and Meta warned about the bill and its implications. C-22 defines electronic services in an extremely broad way, requires that companies retain metadata for a year, and leaves space for a lot of interpretation.
The response has been interesting, and varied. Signal, Windscribe, and NordVPN have stated that they would need to leave the Canadian market, since they explicitly and deliberately avoid retaining the metadata the bill requires. Apple and Meta raise concerns about the implications to end-to-end encryption, since the requirements of the bill would require that these companies begin retaining information that they are explicitly designed to avoid, or compromise their encryption in some way.
This does not fill one with confidence. US law does not have similar requirements, and the US market is vastly larger. It’s unclear how these companies would ultimately react if the bill is passed, but it raises issues in both the US and EU, since the bill would not apply to US-based competitors, and actually conflicts with EU privacy legislation.
Public Safety Minister Gary Anandasangaree is claiming that the companies are misinterpreting the bill, and that the vague wording of parts of the bill would never be used to compromise privacy. And big companies complain about this sort of thing all the time, so isn’t this more of the same? Is C-22 really a privacy concern? Or are companies just whining about accountability?
Sadly, not this time. As Michael Geist notes, “The companies aren’t bluffing and they aren’t misreading the bill. Rather, they are responding to an outlier approach that threatens the Canadian tech landscape with obligations that place the privacy and security of millions at risk.”
And it’s not just tech companies raising the alarm. Citizen Lab has also weighed in on the implications of the bill, and they’re the real deal – they have a long reputation for their InfoSec research and for investigating threats to human rights. For any non-techies, or others unfamiliar with them, one of their major areas of work is uncovering surveillance of journalists and activists – for example, they are the ones who revealed that NSO Group’s software was used to spy on the “inner circle” of Jamal Khashoggi, before his murder.
In their review, Citizen Lab notes the speed with which C-22 is being pushed, the limited review, the likely unconstitutionality of several provisions of the bill, and the fact that proponents are claiming that the bill will bring Canada more in line with our close allies when that is not true. They flag a number of weaknesses in the bill, and offer suggestions for revisions which could make it consistent with both the national security and privacy needs of Canada and its citizens.
Ultimately, C-22 is a seriously problematic bill and, in this particular situation, a political football which should probably be kicked down the street for further review and discussion.
Cheers!
