Lawful Access Act, 2026

Summary#

Bill C-22, An Act respecting lawful access, would create the Supporting Authorized Access to Information Act and amend the Criminal Code, the Canadian Security Intelligence Service Act and other laws. Its stated goal is to help service providers facilitate access to information that authorities are already authorized to obtain. These are proposed provisions; the supplied material does not establish that they are in force.

  • Police and other public officers would gain new ways to seek subscriber information and transmission data, including by warrant, court order or, in some cases, a demand to confirm whether a provider serves a particular subscriber or account.
  • The bill would broaden some warrant powers, including searches of computer systems, covert tracking and transmission-data recording, and would set new rules for examining and giving notice about seized data.
  • The new Act would let the federal government require certain providers to build capabilities or retain specified metadata for up to six months. Separate orders could apply to any electronic service provider for up to two years.
  • Providers would have to assist with specified testing and comply with applicable orders. Inspectors could examine records and systems; compliance failures could lead to administrative penalties or criminal fines.
  • The Intelligence Commissioner would review certain provider-specific orders. The bill also provides for annual reporting and a parliamentary review after all provisions have been in force for a set period.

What it means for you#

  • Service providers: Some may have to confirm service, produce information under an order, retain specified metadata or build capabilities if regulations or orders require it. Providers can challenge some demands and orders. They are not required to introduce a systemic vulnerability or prevent its repair.
  • People whose information is sought: The bill would expand authorities’ legal tools, but it does not make access automatic: the new powers generally require specified grounds and, for many searches or production requests, judicial authorization. In some cases, notice about an examination warrant may be delayed or set aside.
  • People using online services: Regulations could require retention of certain metadata, but not communications content, web-browsing history or social-media activity. The Act would not generally require providers to decrypt user-encrypted information unless the provider supplied the encryption and has what it needs to decrypt it.
  • CSIS and law-enforcement bodies: They would gain new confirmation and information-gathering routes, subject to different rules and safeguards. The bill does not itself create a general right for the public to access information or a new front-line service.

Money#

No publicly available information on the bill’s total public or private cost.

  • The Minister may compensate providers for some or all costs of complying with certain provider-specific orders; the bill does not require compensation in every case.
  • Regulations may set fees for provider assistance. No fee amounts are set in the supplied material.
  • Providers may face costs for capabilities, data retention, assistance, audits and compliance. The bill gives no estimate.
  • The bill provides for government administration, inspections and enforcement, but the supplied material gives no staffing or budget estimate.
  • Administrative penalties can reach $50,000 for an individual and $250,000 for another person for a violation. Separate offences can carry fines up to $100,000 for an individual and $500,000 for another person.

What is unclear#

  • The supplied material does not show which provider classes are listed in the schedule, or what specific technical capabilities or metadata categories later regulations might require.
  • The bill gives the Minister and Governor in Council powers to make rules, but the content of future regulations, including fees and some enforcement details, is not supplied.
  • The supplied material does not give a commencement date for the new Act. Most Part 1 amendments would start 180 days after royal assent; a separate coordination rule applies to one amendment.
  • The material does not provide an overall cost estimate or explain how many providers, orders or government staff may be involved.

Case for#

  • A possible argument for the bill is that authorized access can be difficult if providers lack the ability to produce relevant information. Requiring some capabilities or limited metadata retention could help authorities use existing legal powers.
  • The bill includes limits: many access tools require judicial authorization, and provider-specific orders require Intelligence Commissioner approval.
  • The bill bars requirements that create a systemic vulnerability and rules requiring retention of content, browsing history or social-media activity.
  • Annual reports and a later parliamentary review could give oversight bodies information about how the powers are used.

Case against#

  • One concern is that building capabilities or retaining metadata could impose costs and create privacy or cybersecurity risks for providers and users, even with the bill’s limits.
  • The Minister could make provider-specific orders that are confidential, and providers would face inspection, audit and penalty powers. The balance between secrecy, oversight and a provider’s ability to challenge an order may matter in practice.
  • Many important details depend on future regulations, including which providers are covered and what capabilities or metadata they must retain. The bill does not yet show what those requirements would be.
Loading versions…Read this official publication

Summary matches the latest captured text

Summary version: As passed by the House of Commons · 2026-06-18

Last source check:

Read the latest official text

How the text changed

Loading versions…