Yesterday I wrote about the EU's Tech Sovereignty Package — policy moving in the direction of autonomy. Today the Canadian story, which is moving the other way.
What Bill C-22 Does
Bill C-22, the Lawful Access Act, 2026, was introduced March 12. It was fast-tracked through the House of Commons and passed third reading on June 18, the day Parliament rose for summer. It's now in the Senate awaiting first reading.
The bill has two parts. Part 1 amends the Criminal Code and CSIS Act to modernize lawful access powers. Part 2 enacts the Supporting Authorized Access to Information Act (SAAIA), which establishes a framework requiring electronic service providers to have the technical means to comply with judicial authorizations.
The government says ESPs remain in control of their systems and law enforcement won't access them directly. That's technically true and practically misleading. The obligation is to build the capability to comply — which means retention, interception infrastructure, and metadata logging that didn't exist before.
The Definition Problem
The bill defines "electronic service provider" as any person who, individually or as part of an organization, provides a service involving the creation, recording, storage, processing, or transmission of electronic data.
Michael Geist, Canada Research Chair in Internet and E-commerce Law, wrote in May that this definition "captures any service involving the creation, recording, storage, processing" of data. The Canadian Bar Association's submission noted the definitions remain "broadly drafted."
This is not a definition scoped to telcos and hyperscalers. It's a definition that, read literally, captures a community organization running a Nextcloud instance for its members. A fire hall with a shared file server. A community center hosting a Matrix homeserver. Anyone providing electronic services to others.
The government has not cited specific investigations hindered by current technical limits. The CBA noted this in their submission: the case for mandatory capability hasn't been made.
Who's Pushing Back
Apple told the House committee the bill "could allow the Canadian government to force companies to break encryption by inserting backdoors into their products." Google and Meta raised similar concerns. The Privacy Commissioner's reform recommendations weren't distributed to MPs before the hearings.
NordVPN and Windscribe — a Canadian VPN company — both said they'd leave Canada if the bill passes as drafted. Signal, already not headquartered in Canada, would go. Tailscale published a blog post arguing the bill would "push secure services to collect more data, retain more metadata, and build access systems" — the opposite of what security requires.
Citizen Lab published a detailed analysis on June 2 identifying "sweeping scope, significant constitutional and human rights risks, transparency and accountability deficits." Policy Options ran a piece on June 16 warning that C-22's foreign data-sharing provisions could pave the way for a CLOUD Act executive agreement letting US agencies request Canadian data directly from providers.
The CLOUD Act Connection
Since March 2022, Canada has been negotiating a bilateral CLOUD Act executive agreement with the United States. Over three years later, no agreement has been signed. But Bill C-22's Part 2 amends the Mutual Legal Assistance in Criminal Matters Act to allow Canada to enforce foreign decisions — the legal plumbing a CLOUD Act agreement would use.
The Balsillie Papers and Citizen Lab have both documented the risk: a CLOUD Act agreement would let US law enforcement request data directly from Canadian providers, bypassing Canadian courts. The agreement would nominally restrict targeting to US persons, but Canadian data caught in incidental collection would have no meaningful protection.
The Hub reported on July 6 that the Carney government is "assembling" these powers — C-22, the CLOUD Act negotiations, and other measures — into an expanding surveillance framework.
What This Means for Community Infrastructure
Here's the part that matters for the work we do.
When your community runs its infrastructure on a hyperscaler — AWS, Azure, Google Cloud — the data is stored in Canada, maybe. But the provider is a US company subject to the CLOUD Act today, and subject to whatever C-22 becomes tomorrow. The legal jurisdiction follows the provider, not the server location. Balsillie Papers made this point clearly: "The CLOUD Act compels disclosure based on who controls the data, not where it is stored."
When your community runs its own infrastructure — Proxmox cluster, Nextcloud, Matrix, Keycloak — the provider is you. You control the architecture. You decide what metadata is collected, what's retained, what's logged, and what interception capability exists.
Bill C-22's broad ESP definition means a community operator could theoretically be captured. But the structural position is completely different:
-
Minimal retention by design. A properly configured Nextcloud or Matrix deployment doesn't retain metadata it doesn't need. Hyperscalers retain everything by default because their business model requires it. A community operator can architect for minimal collection from the start.
-
No foreign corporate parent. A community-owned Proxmox cluster has no US corporate entity the CLOUD Act can compel. The legal attack surface is narrower.
-
Local accountability. If a community infrastructure operator receives a lawful access demand, the demand comes through Canadian courts and Canadian law. The community can see it, challenge it, and organize around it. A demand served on a US provider's Canadian subsidiary is invisible to the community.
-
FOSS auditability. When you run Nextcloud, Matrix, or Keycloak from source, you can verify what the software actually does. When a vendor ships a closed-source update that adds interception capability, you find out when someone reverse-engineers it.
This isn't about evading lawful access. It's about structural control over what your infrastructure is built to do. The question C-22 forces is: did you design your systems to collect and retain, or did you design them to serve your community? Hyperscalers chose the former. Community-owned infrastructure can choose the latter.
The Practical Takeaway
For Canadian communities — fire halls, town offices, community centers, small businesses — Bill C-22 is now an argument you can use in a room where "sovereignty" sounded abstract before.
If your town council is debating whether to move to Microsoft 365 or self-host on a Proxmox cluster, the conversation just changed. Microsoft is a US provider subject to the CLOUD Act and, if C-22 passes as drafted, subject to Canadian lawful access mandates that Apple says could force encryption backdoors. A Proxmox cluster you own and operate has a different legal posture entirely.
The Senate will take up C-22 when Parliament resumes. The bill could pass, stall, or be amended. The CLOUD Act agreement could be signed this year or never. But the direction is clear: the Canadian government is building a framework that treats data collection and retention capability as mandatory infrastructure, and it's defining "service provider" broadly enough to capture anyone running services for others.
The communities that own their infrastructure will be in a structurally different position than the ones that rent it. That's the whole argument. It just got legislative backing — from the other direction.