openmedia.org Civil Society Urges Parliament to Withdraw Bill C-22 Amid Privacy Concerns
Article Content
- •Bill C-22 mandates digital services to retain user metadata for up to a year.
- •The bill is criticized for creating surveillance backdoors that could be exploited by malicious actors.
- •25 organizations, including privacy experts, are advocating for the bill's withdrawal.
On April 21, 2026, 25 rights and privacy organizations, including prominent experts, delivered an open letter to Prime Minister Mark Carney and all Members of Parliament, demanding the withdrawal of Bill C-22, the Lawful Access Act. The bill proposes extensive surveillance powers that would require digital services to retain detailed metadata for up to a year on all users in Canada and abroad. Critics argue that these provisions would create surveillance backdoors in digital products, significantly compromising privacy rights. The letter highlights that the bill's mass surveillance capabilities echo vulnerabilities exposed in the 2024 Salt Typhoon attack, which targeted government-mandated backdoors. While some improvements over the previous Bill C-2 are noted, they do not resolve the fundamental issues raised against C-22. The letter calls for MPs to reject the bill and for the government to engage in meaningful public consultation before future proposals. The bill is currently under detailed study by the House of Commons Standing Committee on Public Safety and National Security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Salt Typhoon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…