On 12 March 2026, the Canadian government introduced Bill C-22, the Lawful Access Act. The bill has since cleared the House of Commons and is now under Senate scrutiny. If it passes in its current form, it would require telecoms and electronic service providers to build surveillance and monitoring capabilities directly into their systems—available on demand to police and the Canadian Security Intelligence Service (CSIS).
That alone would be significant. But the bill's reach extends further: critics warn it could compel providers to retain user metadata for up to six months, creating a mandatory database of who communicated with whom, when, and from where—regardless of whether those users are ever suspected of anything.
The reaction from the privacy and security community has been sharp. Most notably, Toronto-based Psiphon—a censorship-circumvention tool used by roughly 20 million people every month—told The Globe and Mail on 5 October 2026 that it has begun drawing up plans to relocate its operations out of Canada if the bill passes unchanged. That is a remarkable statement from a Canadian-founded organisation, and it illustrates something important about why surveillance backdoor legislation tends to backfire.
What Bill C-22 Actually Requires
The bill's core obligation is straightforward in principle and deeply problematic in practice. Electronic service providers operating in Canada would need to ensure their systems are capable of intercepting communications and handing them over to authorities when legally required. This is the "lawful access" concept—giving law enforcement a technical pathway into encrypted or otherwise protected services.
The metadata retention requirement adds a second layer. Providers would need to log connection data—IP addresses, timestamps, identifiers—and hold it for up to six months. This is not content; it is the envelope rather than the letter. But metadata is remarkably revealing. A six-month log of who you contacted, when, and from which location can paint a detailed picture of a person's relationships, movements, health concerns, and political views.
A tech industry open letter responding to the bill warned that mandatory metadata retention would create a high-value "honeypot" target for hackers. Centralised stores of sensitive data are attractive targets precisely because of their breadth. A breach does not expose one person's records—it exposes millions.
The same letter noted that Bill C-22 goes considerably further than the lawful-access frameworks adopted by Canada's G7 peers. That is a meaningful data point. Other democratic governments have wrestled with the same tension between investigative powers and civil liberties, and Canada's proposed approach is evidently more expansive than what comparable countries have legislated.
Why Psiphon Cannot Simply Comply
Psiphon's situation makes the practical problem concrete. The tool exists to help people in heavily censored countries—Iran, Russia, China—access the open internet. Its user base of around 20 million monthly users is not primarily Canadian; it is people in countries where connecting to the wrong service can carry serious personal risk.
Psiphon's vice-president Kenzie Elsworthy explained to The Globe and Mail why compliance is not really an option: Psiphon's code is fully open-source. Every line of it is publicly readable. If the company were ordered to insert a surveillance backdoor, it would effectively be publishing a vulnerability for anyone in the world to find and exploit. A secret backdoor in open-source software is not secret. It is a flaw.
This is not a loophole or a convenient excuse. It reflects something fundamental about how surveillance mandates interact with security architecture. A backdoor is, by definition, a weakening of a system's integrity. In closed-source software, that weakness can at least be obscured temporarily. In open-source code, it cannot be hidden at all. The moment the change is committed, it is visible.
So Psiphon faces a binary choice: comply and destroy the security model that makes the tool useful, or leave. It is, apparently, preparing to leave.
The Honeypot Problem
Set aside open-source software for a moment and consider the metadata retention requirement on its own terms. The argument for it is that retained metadata helps investigators reconstruct timelines and identify connections after a crime has occurred. The argument against it is that you cannot build a large, mandatory database of sensitive information without creating a target.
Security professionals use the term "honeypot" to describe a system that attracts attackers because of what it contains. A six-month rolling log of connection metadata for millions of Canadian internet users would be exactly that. Attackers—whether criminal groups, foreign intelligence services, or opportunistic hackers—would have clear knowledge of what the database holds and strong incentives to get into it.
The irony is that surveillance infrastructure, designed to make the state safer, can make ordinary citizens less safe if it is breached. The data collected on innocent people to enable investigations into a small number of suspects becomes a liability for everyone once it leaks.
What This Means for VPNs and Encryption Tools
Psiphon is the most prominent example so far, but the bill's implications extend to any privacy or security tool with Canadian operations. A VPN provider based in Canada would face the same structural problem: build in surveillance access, or face legal consequences.
This is why the location of a VPN provider's operations—and the legal jurisdiction it operates under—genuinely matters. A provider subject to a lawful-access law with backdoor requirements cannot credibly offer a no-logs policy, because the legal framework would require it to do the opposite of what that policy promises.
PremierVPN is UK-based. The UK has its own complex relationship with surveillance law—the Investigatory Powers Act is not a straightforward framework—but it does not impose a blanket requirement to engineer backdoors into encrypted systems in the way Bill C-22 proposes. The distinction matters when evaluating what a provider can and cannot commit to on paper.
If you are using a VPN specifically because you want your traffic to be private, it is worth understanding what the provider's jurisdiction actually requires of it. What a VPN does technically is only one part of the picture; what its legal environment obliges it to disclose is the other.
Backdoors and the Encryption Debate
Bill C-22 is part of a longer argument that governments have been having with the security community for decades. Law enforcement agencies argue that end-to-end encryption and privacy tools make their work impossible—that they cannot investigate serious crimes if suspects can communicate without any possibility of interception. The security community's counterargument is that there is no such thing as a backdoor that only authorised parties can use.
This is not a theoretical position. Every serious cryptographer and security researcher who has studied the question has reached roughly the same conclusion: a system designed to allow authorised access under controlled conditions will eventually be accessed under uncontrolled conditions. The vulnerability exists whether or not the right people are using it.
Psiphon's open-source situation makes this unusually visible, but the principle applies to closed-source systems too. Mandated backdoors in encryption tools do not make those tools selectively permeable to law enforcement—they make them weaker, for everyone, against everyone.
What Happens Next
Bill C-22 is now in the Senate, where it faces scrutiny from a chamber that has historically been willing to amend or delay legislation it finds constitutionally or practically problematic. Privacy advocates, security researchers, and organisations like Psiphon will be pressing for significant changes—particularly to the metadata retention requirement and any provision that could be read as requiring backdoor access.
Whether the Senate makes meaningful amendments remains to be seen. What is already clear is that the bill, as drafted, is prompting organisations to reconsider whether Canada is a viable home for privacy-preserving technology. That is a significant consequence regardless of how the legislation ultimately resolves.
For users who rely on tools like Psiphon—particularly those in Iran, Russia, or China, where the stakes of a compromised tool are not abstract—the uncertainty itself is a problem. And for anyone using any privacy tool, the Canadian situation is a useful reminder that the legal environment a provider operates in shapes what it can actually guarantee.
Practical Steps for Users
If you are evaluating privacy tools in light of this kind of legislation, a few things are worth checking:
- Where is the provider incorporated? The jurisdiction determines which laws apply and what authorities can demand.
- What does the no-logs policy actually cover? A policy is only meaningful if the legal environment allows the provider to honour it. Review how a no-logs policy works in practice.
- Has the provider's code or infrastructure been audited? Third-party audits provide some evidence that policies match reality.
- What protocol does the VPN use, and how is it implemented? For users in restrictive environments, protocol choice matters significantly—PremierVPN's VLESS+REALITY protocol, available via PremierVPN X, is specifically designed to resist deep packet inspection in countries like Iran and China.
Bill C-22 has not passed yet, and the Senate may yet change it substantially. But the fact that a 20-million-user privacy organisation is already planning to leave Canada over it tells you something about how the security community reads the bill's intent. Surveillance infrastructure built into privacy tools does not protect users—it exposes them. That is true whether the legislation is well-intentioned or not.