Bay Street Wire
Tech & BusinessOpinion

Encryption Deadlock: Why Bill C-22 is Alienating Canada's Tech Sector

Portrait of Diana Vasquez
Diana Vasqueztech policy & regulationSep 28AI
Encryption Deadlock: Why Bill C-22 is Alienating Canada's Tech Sector

AI-generated image · Bay Street Wire

Pushback from firms like Tailscale and Windscribe suggests the government's 'lawful access' framework fails to reconcile national security needs with technical realities.

**Analysis: The Rules of the Game**

Canada is currently attempting to rewrite the rules of digital surveillance, but the resulting friction with the tech industry suggests a fundamental disconnect between legislative ambition and technical feasibility. Bill C-22, the proposed "lawful access" legislation currently under review in the Senate, seeks to expand the powers of CSIS and law enforcement to access digital information from service providers. However, as BetaKit first reported, the industry's reaction indicates that the government has failed to find a middle ground that protects national security without compromising the integrity of secure systems.

**Opinion:** In my view, the government is attempting to treat encryption and user privacy as adjustable dials rather than binary technical realities. By pushing for expanded access, they are not merely requesting data; they are asking companies to undermine the very security architectures that make their products viable. The pushback from specialized security firms signals that the government's approach is viewed not as a balanced compromise, but as a threat to the technical viability of the industry.

According to BetaKit, a coalition of European and Canadian companies recently sent an open letter to the ministers of public safety and industry. The signatories—which include Toronto-based Tailscale, Toronto-based Windscribe, Fredericton-based Beauceron Security, logistics firm Gobolt, and the Canadian subsidiary of Coinbase—argue that the bill would weaken Canada's competitive landscape and erode trust in the domestic tech sector.

Tailscale CEO and co-founder Avery Pennarun explicitly highlighted the technical risk, stating that Canada must support investigations without making secure systems easier to attack or hindering the global competitiveness of Canadian firms seeking to provide trusted, sovereign infrastructure. For these companies, the "lawful access" the government seeks is viewed as a vulnerability that could be exploited by malicious actors.

The stakes are not merely rhetorical; they are operational. BetaKit reports that Windscribe and the messaging platform Signal have threatened to move their operations out of Canada entirely to avoid compliance. Similarly, Tailscale informed The Globe and Mail that it would be forced to seek corporate structures to separate its international operations from its Canadian presence.

Windscribe CEO Yegor Sak has gone further, asserting that the legislation would render Canada an "untenable" environment for both domestic and foreign tech companies. This suggests that the bill's reach—which applies to any provider with Canadian subscribers regardless of the company's origin—creates a jurisdictional conflict that many firms are unwilling to navigate.

While the government has attempted some concessions, such as reducing the mandatory metadata storage period from one year to six months, these tweaks do not address the core conflict: the tension between state surveillance and end-to-end security. As BetaKit notes, while the government is simultaneously moving through Bill C-36 to update privacy laws and give citizens more control, that legislation has only completed its first reading. Meanwhile, the more controversial Bill C-22 is racing toward passage, leaving the tech industry to warn that the cost of "lawful access" may be the exodus of the very companies Canada needs to build a secure digital future.

Sources

More from Diana Vasquez