European digital rights groups call on EU to address Canada’s encryption bill

Sixteen European civil society organisations are calling on EU institutions to oppose surveillance and data retention provisions in Canada’s Bill C-22, warning that the legislation could affect European providers and users.

European digital rights groups call on EU to address Canada’s encryption bill

Sixteen European civil society organisations in an open letter have urged the European Commission and European Parliament to intervene before Canada’s Senate completes its consideration of Bill C-22, the Lawful Access Act. The bill was referred to the Senate in June and is expected to resume committee consideration after Parliament returns in late September.

The organisations argue that the legislation could have implications beyond Canada because it would apply to certain service providers connected to Canada, including providers whose services are used by people in Canada or whose corporate groups conduct business there. They warn that the bill could allow Canadian authorities to require European companies to weaken the security of their products or retain metadata.

The letter focuses on the bill’s proposed surveillance capabilities. According to the organisations, Bill C-22 would require certain electronic service providers to develop technical capabilities and host equipment that would enable government access. They argue that such capabilities could create reusable weaknesses affecting other users and potentially facilitate broader surveillance.

The organisations also object to the absence of an explicit prohibition on measures that undermine end-to-end encryption. They point to techniques including client-side scanning, hidden accounts in encrypted groups, and engineered entry points as measures that could weaken encrypted communications without directly requiring decryption.

The letter also raises concerns about the bill’s proposed metadata retention regime. The organisations argue that it lacks sufficient restrictions on which authorities could access retained information, how providers could use it, and what happens to the data after the retention period. They say this could conflict with EU data protection requirements and potentially affect Canada’s adequacy status for EU data transfers.

Another concern is the level of secrecy surrounding surveillance capability orders. The organisations say obligations would generally remain confidential and that providers would have limited opportunities to challenge them. They also argue that affected European users and institutions would have limited avenues for legal remedy when Canadian authorities target European providers or data.

The signatories are calling for the removal of the bill’s surveillance capability and metadata retention provisions, as well as a categorical prohibition on measures that directly or indirectly weaken end-to-end encryption. They also call for safeguards based on necessity and proportionality, and for the issue to be raised in EU-Canada Digital Trade Agreement negotiations.

The organisations further ask the European Commission to review Canada’s adequacy status under Article 45 of the GDPR if the bill passes in its current form, and to clarify the safeguards that would apply to transfers of European data to Canada. They also call on EU institutions to publicly state that measures weakening encryption are incompatible with commitments to cybersecurity and fundamental rights.

The letter was signed by organisations including Access Now, ARTICLE 19, Bits of Freedom, Digitalcourage, Electronic Frontier Norway, European Digital Rights (EDRi), Open Rights Group, SHARE Foundation, and Stop

Go to Top