e-7416 · Parliament 45
Bill C-22: metadata and encryption
AI summary
Petitioners say Bill C-22 would authorize regulations requiring designated “core providers” to collect and retain metadata on all Canadians for up to one year and would allow the Minister of Public Safety to impose similar requirements on other electronic service providers. They argue the bill’s definitions are broad, could compel interception or technical measures that weaken encryption (which they say creates cybersecurity vulnerabilities, citing the 2024 Salt Typhoon attack on U.S. telecoms), and raises concerns under the Canadian Charter about suspicionless searches. The petition asks the House of Commons to withdraw or vote against Bill C-22, remove suspicionless bulk metadata retention from future lawful access laws, and explicitly prohibit any requirement to weaken encryption.
AI summaries describe petitioners’ requests and claims. Consult the official record for the full text.
Official petition
Petition to the House of Commons Bill C-22 authorizes regulations requiring designated "core providers" to collect and retain metadata on all Canadians for up to one year without any individual being under suspicion or investigation, and grants the Minister of Public Safety power to impose these same requirements on any electronic service provider by ministerial order. Such metadata can reveal highly sensitive information including patterns of movement, association, medical activity, religious participation, and political activity; The definition of electronic service provider is broad enough to include any online service, including encrypted messaging apps, VPNs, email providers, banking apps, and cloud storage services; Bill C-22 grants the Minister of Public Safety broad authority to compel any electronic service provider to implement interception capabilities or technical assistance measures that could weaken encrypted systems, with compliance being mandatory. This creates cybersecurity vulnerabilities exploitable by criminals and hostile foreign actors, as demonstrated by the 2024 Salt Typhoon attack on United States telecoms; Suspicionless, indiscriminate bulk metadata retention and interception capabilities raise serious concerns under the Canadian Charter of Rights and Freedoms, which protects Canadians against unreasonable search and seizure; and The government retains broad regulatory power to redefine key terms including "encryption" and "systemic vulnerability" without returning to Parliament, rendering the bill's stated privacy protections unreliable. We, the undersigned, citizens and residents of Canada, call upon the House of Commons to 1. Withdraw Bill C-22, An Act respecting lawful access, or vote against it at all stages; 2. Remove all suspicionless bulk metadata retention requirements from any future lawful access legislation; and 3. Explicitly prohibit any future lawful access legislation from requiring the weakening or breaking of encryption.
Government response
No government response is available yet.