Citizen Lab, the research group based at the University of Toronto, has published a submission analyzing Bill C-22, the Lawful Access Act. Its title, "(Un)forced Errors," signals the core message: the proposed surveillance law expansion contains problems that lawmakers can still fix. For anyone following the debate over Canada Bill C-22 lawful access encryption, the submission is a significant technical and legal voice to watch.
This post summarizes what the source material says about the bill and Citizen Lab's analysis. The summary of the submission is brief, so we stick to the issues it names and point to other publicly listed context only where it is clearly attributed.
What Bill C-22 would require
According to Citizen Lab, Bill C-22 would enact broad surveillance obligations and reforms in Canada. The bill's text, first read in Parliament on March 12, 2026, describes its purpose as ensuring that electronic service providers can facilitate the exercise of authorities to access information. In plain terms, companies that carry or store communications could be required to build in the ability to help police and security agencies carry out access requests.
Citizen Lab's first concern is the bill's sweeping scope. Obligations that reach many kinds of service providers can affect far more than the large telecom and technology firms people usually picture. The wider the definition, the more services, large and small, could fall under it.
Citizen Lab's constitutional and human rights concerns
The submission highlights two broad categories of risk beyond the technology itself.
Constitutional and human rights risks. Citizen Lab says the bill poses significant risks in these areas. Canadians' protection against unreasonable search and seizure, and their rights to privacy and expression, are the kinds of principles at stake whenever access powers expand.
Transparency and accountability deficits. The submission also points to gaps in how the powers would be overseen and reported. Surveillance authority tends to be most defensible when there are clear limits, independent review, and public reporting that lets citizens understand how the powers are used. Where those are weak, it is hard for the public, courts, or Parliament to check whether powers are used proportionately.
Citizen Lab is known for investigating digital surveillance, so its framing carries weight. It treats these as structural issues in the bill's design rather than matters of tone or intent.
Why encryption and privacy tools are at stake
The submission also names dangers to encryption. Encryption works because only the intended parties can read a message or file. Any requirement that forces a provider to maintain a way in for third parties raises the question of whether that way in can be limited to authorized use. Security researchers have long argued that it cannot be guaranteed, because a weakness built for one party can be found by others.
Other coverage of the bill shows how broad the debate has become. Public reporting from May 2026 described Apple arguing that the bill could put users' personal data at risk, and the Electronic Frontier Foundation described it as a threat to encryption. The Government of Canada's own lawful access page says the bill includes safeguards that would let providers refuse to implement a technical capability obligation if it creates a systemic weakness. Whether those safeguards are strong enough is exactly the kind of question Citizen Lab's analysis feeds into.
This is where VPNs and secure messaging services come in. These tools exist to protect the confidentiality of communications. If obligations reach them, or reach the infrastructure they depend on, the privacy promises they make could be affected. The source summary does not detail how any specific VPN would be treated, so readers should avoid assuming a particular outcome. The point is that the bill's scope and its encryption implications make these tools a relevant part of the conversation.
What This Means For You
Bill C-22 has not become a settled law in the material we reviewed, and the final text could change. For everyday users in Canada, nothing about your current tools changes because of a submission. But the debate affects which services you may be able to trust in the future.
- Encryption claims deserve scrutiny. End-to-end encrypted messaging and VPNs are only as protective as their design and the legal environment they operate in.
- Jurisdiction matters. Where a provider is based, and what laws can compel it, shape what it can promise.
- No-logs claims need evidence. A provider that does not keep data cannot hand over what it does not have, but that has to be verified, not just stated.
What Canadians and VPN users should watch next
Keep an eye on how Parliament handles amendments, particularly around the definition of covered providers, the limits on technical capability obligations, and the oversight and reporting mechanisms Citizen Lab says are lacking. Submissions from civil society, industry, and legal bodies will likely shape the debate, so reading them directly is worthwhile.
Key takeaways
Follow the bill's progress and read the primary documents rather than relying on summaries. When choosing any privacy provider, look for independent proof of its claims. A VPN security audit is an independent evaluation of a provider's code, infrastructure, and privacy claims by third-party experts, and it is one of the best ways to check whether a no-logs promise holds up. As the debate over Canada Bill C-22 lawful access encryption continues, informed users are best placed to judge which tools and which laws actually protect their privacy.




