The EU must act now to protect privacy and encryption from Canada’s overreaching Bill C-22

Access Now, alongside several European civil society organisations, is urging Ursula von der Leyen, President of the European Commission, European Union commissioners, and members of the European Parliament to push for changes to Canada’s Bill C-22, the Lawful Access Act.

The highly criticised Bill C-22, threatens end-to-end encryption, carries sweeping surveillance capabilities and blanket data retention mandates, and is not just a domestic privacy and data issue in Canada. Bill C-22 puts the privacy and data of millions of people in Europe, and elsewhere, at risk as it also applies to certain service providers and people outside of Canada. It allows Canadian authorities to compelEuropean-based companies to comply with demands relating to security and data of their customers based in Europe without oversight or transparency.

The European Commission cannot speak about Europe’s tech sovereignty and at the same moment, ignore Canada’s overreaching Bill C-22 threatening the privacy and security of people and businesses in Europe. The Commission must urgently initiate an honest dialogue with Canada and voice the serious concerns that academics and civil society on both sides of the Atlantic have raised regarding the bill. Marcel Kolaja, Policy and Advocacy Director — Europe at Access Now

Bill-C22 could become law as early as October, 2026, therefore, the European Union must act now.

Canada’s Bill C-22 could undermine years of work in the EU, and around the world, to protect privacy and end-to-end encryption. The bill threatens to normalise excessive surveillance powers as routine obligations for service providers, and convert devices that work for people into devices that work against them. Steps must be taken to prevent it from becoming law. Namrata Maheshwari, Global Encryption Policy Lead and Asia Pacific Policy Manager at Access Now.

The open letter calls on the European Commission to:

  • Call for the removal of Bill C-22’s sweeping surveillance capability and metadata retention mandates.
  • Call for the introduction of a provision that categorically prevents any measures that would, directly or indirectly, undermine or weaken end-to-end encryption.
  • Call for amendments to Bill C-22 to ensure alignment with the principles of necessity, proportionality, and strict access limitations, for data retention, storage, and use.
  • Raise Bill C-22 in the Digital Trade Agreement negotiations with Canada. A partner cannot credibly seek deeper digital integration while legislating the power to compel European providers to weaken their products in secret.
  • Initiate a review of Canada’s adequacy under Article 45(4) GDPR, and clarify what safeguards transfers to Canada would require should the bill pass as drafted. If no appropriate safeguards could be implemented, use the European Commission’s powers to suspend the adequacy pursuant to Article 45(5).
  • Support an oral question on Bill C-22’s implications for people in the EU addressed to the European Commission according to Rule 142 of the European Parliament’s Rules of Procedure with a resolution. 
  • State publicly that measures weakening encryption are incompatible with the EU’s own commitments to cybersecurity and fundamental rights and that Bill C-22 will not be treated as a precedent for policy-making.

Read the open letter.