Canada's Bill C-22: What Lawful Access Asks of VPNs, and Who Said They Would Leave
Canada is one chamber away from a law that five privacy companies have publicly said they would rather leave the country than obey. Bill C-22, the Lawful Access Act, 2026, passed the House of Commons on June 18 and sat at second reading in the Senate as of October 8. The latest company to reach for the exit is also the most symbolic one: Psiphon, the Toronto anti-censorship tool that grew out of the University of Toronto’s Citizen Lab, serves about 20 million people a month by its own count, and it told The Globe and Mail on October 4 that it has started drawing up plans to move out.
Most coverage of C-22 arrives one exit threat at a time. What it rarely shows is the machine those companies are reacting to. So this page does three things: it states exactly what each half of the bill lets the Canadian state demand, it keeps a dated ledger of every provider that has said it would leave, and it answers the question readers actually have, which is what any of this changes for a person in Canada who uses a VPN or an encrypted messenger.
One sentence carries the whole analysis: Bill C-22 is two laws in one envelope, a narrow warrantless question at the front, and a power at the back to order any online service, in secret, to rebuild itself so that authorized access becomes possible.
What Is Bill C-22 and Where Is It in Parliament Right Now?
Public Safety Minister Gary Anandasangaree introduced C-22 on March 12, 2026, after its substance was split out of the 2025 Strong Borders omnibus bill. The House public safety committee heard 106 witnesses and received 61 written briefs between May 5 and June 17. Then came the compression: committee report, report stage and third reading all landed on June 18, under a government motion that limited debate and blocked new amendments, with the final committee session running past midnight.
The Senate received the bill the same day and has been debating second reading since. As of October 8 it had not yet been referred to a Senate committee, which means the chamber’s detailed study, the stage where witnesses return and amendments get drafted, is still ahead. That is the window this page is written in.
What Can Police and CSIS Demand Without a Warrant Under Part 1?
Part 1’s headline power is new section 487.0121 of the Criminal Code, the confirmation-of-service demand. An officer who has reasonable grounds to suspect an offence may demand that a telecommunications service provider confirm “whether or not they provide or have provided telecommunication services” to a named subscriber, account or identifier. No judge signs it. The provider has at least 24 hours, may ask a judge to revoke it within five business days, faces a fine of up to $5,000 for refusing without lawful excuse, and can be gagged for up to one year.
Read that narrowly, because it is narrow: the compelled answer is yes or no. Who the subscriber is, what services they bought, when, on which devices, all of that still requires a production order from a court, though C-22 sets the threshold for that order at reasonable grounds to suspect, the lowest standard in the toolbox. A separate new power lets a judge authorize requests for subscriber information and transmission data directly to foreign providers.
The version nobody talks about is the CSIS one. New section 20.22 of the CSIS Act gives the intelligence service the same demand power with no stated suspicion threshold and a non-disclosure condition with no time limit. The government’s defence, in its Charter Statement, is that the demand reveals “basic information” and no communications content, and that reasonable suspicion guards against fishing expeditions. The Privacy Commissioner, appearing before the committee in May, called the demand more narrowly tailored than past attempts and then asked for six amendments, including a closed definition of subscriber information and a necessity and proportionality requirement.
What Could the Government Order a VPN or Messaging App to Build Under Part 2?
Part 2 enacts a new statute, the Supporting Authorized Access to Information Act, and this is the part the industry is reacting to. Its reach is set by one definition: an electronic service provider is anyone who provides an electronic service “to persons in Canada” or does business in Canada. A VPN provider with Canadian users qualifies. So does a messaging app, an email service, and a foreign company with no Canadian office.
For classes of providers that cabinet later designates as core providers, regulations can require building, testing and maintaining “operational and technical capabilities” that enable an authorized person to access information, and can require retaining categories of metadata for up to six months. For everyone else there is section 7: the minister may order any electronic service provider, core or not, to do anything those regulations could require. The order needs approval from the Intelligence Commissioner, a review body, not a court. It is exempt from the Statutory Instruments Act, so it is never published. And section 14 forbids the provider from disclosing the order’s existence, with fines up to $100,000 for individuals and $500,000 for companies. Administrative penalties reach $250,000 per violation, counted daily. The one transparency valve is an annual report that must state how many ministerial orders were made.
Citizen Lab’s analysis, written with the Canadian Civil Liberties Association, concluded that Part 2 is unsalvageable and should be withdrawn and that its indiscriminate metadata retention mechanism is “almost certainly unconstitutional”, quoting on the technical point the EFF’s warning that “there’s no security backdoor that’s only for the ‘good guys’”. The Canadian Bar Association reached for the Charter: both parts risk violating section 8’s protection against unreasonable search and seizure.
Which Providers Have Said They Would Leave Canada?
The dated record, company by company. Every entry links to the statement or to the outlet that carries the direct quote; no provider has publicly promised to stay and comply.
| Provider | What they said | When |
|---|---|---|
| Windscribe (Toronto) | Would "move HQ and take our taxes elsewhere" rather than change how its service works; in September, CEO Yegor Sak called C-22 "untenable" for tech companies in Canada | May 14, 2026 |
| Signal | "If we are ever forced to choose between betraying the people who rely on us and leaving a market, we will leave" (Udbhav Tiwari, VP Strategy and Global Affairs) | May to June 2026 |
| NordVPN | Would consider "all viable options, including limiting or, if necessary, removing our presence from Canadian jurisdiction" | May 15, 2026 |
| Proton VPN | Will not comply rather than exit: complying with foreign surveillance orders outside Swiss legal process "is a criminal offense. Not happening." (David Peterson, GM) | May 22, 2026 |
| DuckDuckGo | "Can confirm we'd remove our VPN service" from Canada | June 4, 2026 |
| Tailscale (Toronto) | Suggested restructuring international operations outside Canada; co-signed the September industry letter | June and September 2026 |
| Psiphon (Toronto) | Drawing up plans to move out if C-22 passes as is: "That is not lawful access. It is a published vulnerability." (Kenzie Elsworthy, VP) | October 4, 2026 |
Three of those companies are headquartered in Toronto, and Psiphon’s case carries an extra twist: the federal government gave it roughly $600,000 in funding in 2026, the same year its flagship bill pushed the company toward the door. Psiphon’s open-source argument is the sharpest technical one on the record: “You cannot build a secret backdoor into open-source code. Every line we ship is public.”
Around the ledger sits a wider front. Apple, Google and Meta all warned the committee about encryption; a coalition letter from 14 civil-society organizations and 15 scholars and legal experts demanded full withdrawal, calling the bill “the most expansive invasion of Canadian privacy rights in modern history”; and in September 23 companies and industry groups, Coinbase Canada among them, wrote to ministers that “a backdoor for law enforcement is a backdoor for everyone”. The government’s spokesperson answered the Psiphon story directly: a lawful-access framework “does not, on its own, make it impossible to operate a secure, privacy-protective service in Canada”. Canada’s big three telecoms, who would carry Part 1’s demands, have said nothing in public.
Does Bill C-22 Ban VPNs or Break Your Encryption?
Neither, and the honest version of each answer is worth spelling out.
On VPN use: every obligation in the bill lands on a company. No clause creates an offence for the person connecting through a VPN, in Canada or from it. The 22 percent of Canadian internet users who told CIRA’s 2026 survey they use a VPN to protect their personal data would wake up the day after Royal Assent committing no offence whatsoever. Where C-22 touches a VPN user is indirect: the provider side. A VPN company serving Canadians is an electronic service provider under Part 2, which means it can be ordered, secretly, to build access capabilities, exactly the scenario Psiphon, NordVPN and Windscribe are pricing in. What a VPN does and does not change under Part 1 is also mechanical: your ISP can still be asked to confirm you are its customer, because that fact sits in a billing database, not in your traffic.
On encryption: the House added section 2(4), which says no obligation compels a provider to decrypt information “encrypted by a person to whom the electronic service provider provides services”. Then comes the unless-clause: unless the provider supplied the encryption and holds the keys. End-to-end designs where users hold keys stay out of reach on paper; provider-managed encryption, which is most cloud storage and plenty of messaging, is compellable. The companion shield, that no order may force a provider to introduce a “systemic vulnerability”, was reworded at committee and now excludes risks confined to people under a warrant. A weakness built for targets only is, by definition, not systemic. Whether a weakness can ever stay confined to its targets is exactly what the security community disputes, and the minister’s assurance that the bill “was never meant to breach encryption” is the claim those amendments were written to support.
How Does C-22 Compare With the UK and Australia?
The government’s standard defence is that allies already have these tools. The comparison is real, and it cuts both ways.
| Canada: C-22 (SAAIA) | UK: Investigatory Powers Act 2016 | Australia: TOLA 2018 | |
|---|---|---|---|
| Who approves a capability order | Intelligence Commissioner (review body) | Judicial Commissioner, the "double lock" | Attorney-General for capability notices |
| Who can be ordered | Any "electronic service provider" serving persons in Canada | Telecom and postal operators, including overseas | "Designated communications providers", including foreign |
| Encryption wording | No compelled decryption of user-applied encryption, unless provider holds the keys | Expressly contemplates removal of operator-applied "electronic protection" | Statutory ban on compelled "systemic weakness", defined in the act |
| Secrecy | Orders unpublished, disclosure fined up to $500,000 | Notices secret; government neither confirms nor denies | Notices secret, with annual statistics published |
| Metadata retention | Up to 6 months by regulation | Up to 12 months | 2 years (separate 2015 regime) |
The UK column is not hypothetical. A reported technical capability notice against Apple led the company to withdraw Advanced Data Protection for UK users in February 2025; Apple filed a fresh Tribunal challenge against a rewritten order in July 2026, and British users still cannot enable the feature. That is what an exit threat looks like after it stops being a threat. Australia’s record points the other way: in TOLA’s first year, agencies used 7 voluntary assistance requests and zero compulsory capability notices, and the regime’s own independent reviewer recommended moving approvals to a judicial body, the safeguard C-22 lacks. Within the EU, no instrument currently in force imposes capability mandates of this kind on VPNs or messengers; the fight over scanning private messages is still running in trilogue, as we documented in our Chat Control reference.
Has Canada Tried This Before?
Seven times in two decades: Canadian privacy lawyer David Fraser catalogues five earlier attempts, in 2005, 2009, 2011, 2012 and 2013, before the lawful-access provisions buried in 2025’s border bill and now C-22. The one Canadians remember is 2012’s C-30, which died after the public safety minister told the House that critics could “either stand with us or with the child pornographers”; the government withdrew the bill within a year and dropped warrantless subscriber access with it. The one survivor, C-13, passed in 2014 only because it had been drafted without those powers. C-22 is the first attempt since then to bring both halves back, the warrantless question and the capability mandate, and the first ever to aim the mandate at every electronic service provider rather than telecoms alone.
What Happens Next?
Second reading in the Senate ends with a committee referral; the committee study brings the witnesses back; third reading and any amendments send the bill home to the House. Government house leader Steven MacKinnon said in June that the Senate would take the bill up when it returned in the fall; with second reading still open in mid-October and a committee study to come, December 2026 looks like the earliest realistic window for Royal Assent, and slippage into 2027 is plausible. The pressure points to watch are the ones the record already shows: whether the Senate writes the Privacy Commissioner’s six amendments into Part 1, whether the systemic-vulnerability definition gets a statutory floor the way Australia’s did, and whether any of the seven companies in the ledger moves from statement to action before the vote.
For the wider map this bill now joins, our ledger of countries that order VPN providers to block websites tracks the copyright-driven half of provider obligations, and our country-by-country VPN legality guide maps where use itself is restricted. For what the law looks like from inside Canada today, start with our Canada page: VPN use is legal, and this bill, whatever happens to it, does not change that.
About the author
Le VPN News Desk
The Le VPN Research Team is the news desk of the Le VPN blog. It tracks internet shutdowns, censorship, new privacy laws, and cybersecurity incidents as they unfold, and turns them into clear, sourced reporting. Every article is built from primary sources, fact-checked against them, and reviewed under Le VPN's editorial rules before it is published.
Articles by Le VPN Research Team →