Apple and Google push for judicial oversight of C-22

๐กBig Tech vs. Government: A critical fight over encryption and device security.
โก 30-Second TL;DR
What Changed
Apple and Google formally oppose aspects of Canada's Bill C-22
Why It Matters
This regulatory battle sets a precedent for how tech giants handle government requests for access to encrypted AI-powered devices.
What To Do Next
Review your data privacy architecture to ensure compliance with evolving global encryption regulations.
Key Points
- โขApple and Google formally oppose aspects of Canada's Bill C-22
- โขConcerns center on secret orders compelling encryption backdoors
- โขCompanies demand judicial oversight for lawful-access requests
- โขPotential impact on software and hardware security architecture
๐ง Deep Insight
Web-grounded analysis with 14 cited sources.
๐ Enhanced Key Takeaways
- โขBill C-22 is a reintroduction of lawful access provisions initially contained within the broader Bill C-2 (Strong Borders Act), which was split into separate legislation in late 2025 following significant public and civil liberties backlash.
- โขBeyond Apple and Google, other major tech entities like Meta, encrypted messaging service Signal, and VPN providers such as NordVPN and Windscribe have also voiced strong opposition, with some threatening to withdraw services from the Canadian market if the bill passes in its current form.
- โขThe legislation mandates that 'core providers' retain metadata, including call logs and location data, for up to one year, and it lowers the threshold for law enforcement to access subscriber information without a warrant.
- โขUS lawmakers, specifically the chairs of the House Judiciary and Foreign Affairs Committees, have formally warned Canada's Public Safety Minister that Bill C-22 poses risks to US national security and the integrity of cross-border data flows.
- โขThe Canadian government, through the Communications Security Establishment (CSE), maintains that Bill C-22 does not create 'backdoors' but rather aims to facilitate access to 'limited and specific information' under controlled, authorized requests without undermining cybersecurity.
๐ ๏ธ Technical Deep Dive
- The bill broadly defines 'electronic service providers' (ESPs) to include a wide range of online services such as messaging apps, VPNs, email providers, banking apps, and cloud storage services, requiring them to develop and maintain technical capabilities for government access.
- While the government asserts the bill includes a safeguard allowing ESPs to refuse obligations if they create a 'systemic vulnerability' (including weakening encryption), critics argue that the definition of 'systemic vulnerability' is insufficiently clear, leaving room for interpretation that could still compromise encryption.
- Apple's Senior Director of User Privacy and Child Safety, Erik Neuenschwander, explicitly stated that creating a backdoor for lawful access inherently creates a vulnerability exploitable by malicious actors, citing the 2024 Salt Typhoon cyberattack on US government systems as an example where lawful access points were exploited.
- Google's Director of Government Affairs and Public Policy in Canada, Jeanette Patell, warned that the bill's broad language could compel companies to dismantle critical privacy architecture, such as breaking encryption or overriding user data deletion controls, potentially facilitating foreign interference.
๐ฎ Future ImplicationsAI analysis grounded in cited sources
โณ Timeline
๐ Sources (14)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events โ
๐Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Next Web (TNW) โ
