Your browser is not supported

Your browser is too old. To use this website, please use Chrome or Firefox.

Greater Niagara Chamber of Commerce

ADVOCACY IN ACTION

Protect Cybersecurity and Encryption in Bill C-22

Issue icon

Issue:

Bill C-22, the Lawful Access Act, 2026, would update federal rules governing how law enforcement and national security agencies access digital information during investigations. The bill contains measures intended to provide lawful access for legitimate investigations. In practical terms, critics warn that such access points could function as “backdoors”: vulnerabilities created for lawful use that could also be discovered, exploited, or repurposed by hackers, organized crime, hostile states, or other malicious actors.

The GNCC shares the concerns raised by the Canadian Chamber of Commerce that parts of Bill C-22 could weaken cybersecurity safeguards, undermine encryption, increase data-retention risks, and create uncertainty for businesses operating in Canada’s digital economy.

Why It Matters icon

Why It Matters:

Businesses of every size rely on secure digital systems. Measures that weaken encryption, expand data-retention obligations, or create broad access powers could increase cybersecurity risks for businesses and customers alike. Small and medium-sized enterprises often lack the resources to absorb new compliance burdens, respond to expanded data obligations, or recover from cyber incidents.

Creating technical access points in secure digital systems can undermine cybersecurity for everyone. Once a lawful-access pathway exists, it becomes something malicious actors can search for, exploit, or steal. For Canadian businesses, this could increase cyber risk rather than reduce it.

If lawful access rules are seen as weakening security or creating unpredictable obligations for service providers, they could discourage investment and make Canada a less attractive place to grow digital businesses.

Facts & Context icon

Facts & Context:

Bill C-22 was introduced in 2026 after earlier lawful-access provisions appeared in Bill C-2, the Strong Borders Act. Industry engagement helped resolve many concerns with Part I of Bill C-22, but significant concerns remain with Part II.

Statistics Canada reported that 16% of Canadian businesses were affected by cybersecurity incidents in 2023. That was down from 18% in 2021 and 21% in 2019, but the costs became more severe: business spending on recovery from cybersecurity incidents doubled from about $600 million in 2021 to $1.2 billion in 2023.

The Auditor General of Canada found in 2024 that the RCMP, CSE and CRTC did not have the capacity and tools to effectively enforce laws intended to protect Canadians from cyberattacks and address the growing volume and sophistication of cybercrime. The report also noted that the Canadian Anti-Fraud Centre estimated only 5% to 10% of cybercrimes are reported.

Policy Position icon

Policy Position:

The GNCC supports measures that help law enforcement address crime and national security threats. However, these measures must not weaken encryption, create new vulnerabilities for businesses and consumers, or impose disproportionate compliance burdens on Canadian companies.

The GNCC urges the federal government to work closely with the Canadian Chamber of Commerce, industry, cybersecurity experts, digital service providers, and civil society to amend Bill C-22 before final passage. The Canadian Chamber has recommended that the federal government split the bill, allow the less contentious Part I measures to proceed, and take more time to refine Part II in consultation with industry and technical experts.

2026-ongoing