Norton Rose Fulbright Canada LLP

08/04/2026 | Press release | Archived content

Bill C-22 is coming: Are we ready for Canada's new lawful access regime

On March 12, the Government of Canada introduced Bill C-22, An Act respecting lawful access. Having now passed third reading in the House of Commons, it is awaiting Senate consideration and is likely to come into force soon, following royal assent.

If adopted, Bill C-22 will represent the most significant reform of Canada's lawful access framework in years.1

Bill C-22 introduces two interrelated sets of changes. First, it expands the powers available to law enforcement and national security agencies to obtain subscriber and service-related information. Second, it creates a new regulatory framework designed to ensure that organizations possess the operational and technical capabilities necessary to respond to those requests. Together, these measures signal a meaningful shift toward greater regulatory preparedness and compliance expectations for service providers.

The legislation is intended to modernize the tools available to law enforcement and national security agencies in an increasingly digital environment. To this end, Bill C-22 facilitates and expands their access to subscriber and service-related information from organizations providing telecommunications, electronic, and digital services to Canadians. It also creates an entirely new compliance framework requiring service providers to develop and maintain technical capabilities enabling them to respond effectively to authorized access requests.

The impact of Bill C-22 extends beyond traditional telecommunications companies. On the one hand, certain provisions apply broadly to organizations that provide services to the public and possess subscriber information, while, on the other hand, the proposed Supporting Authorized Access to Information Act would authorize the federal government to impose operational, technical, and data-retention requirements on a wide range of electronic service providers. As a result, many organizations that have never considered themselves part of Canada's lawful access ecosystem may soon be subject to new regulatory expectations.

New powers to obtain subscriber information

One of the most significant changes introduced by Bill C-22 is the expansion of the tools available to investigators seeking access to subscriber information.

The legislation would authorize peace officers and public officers to require a telecommunications service provider to confirm whether it provides services to a specified individual through a Confirmation of Service request. Unlike many traditional investigative tools, this mechanism would not require prior court authorization, although service providers would have a limited period to challenge the request.

Bill C-22 would also create a new court-authorized process enabling investigators to seek an Information Order requiring a person who provides services to the public to prepare and provide a document containing subscriber information. Such information may include a subscriber's name, address, telephone number, email address, account number, details regarding services provided, and information identifying devices or equipment associated with those services.

The scope of these powers deserves particular attention.

While Confirmation of Service requests are limited to telecommunications service providers, Information Orders may be directed to any person who provides services to the public. This broader language suggests the regime could extend far beyond traditional telecommunications providers and potentially apply to technology companies, cloud service providers, software platforms, digital service operators, online service providers, and other organizations maintaining customer account information.

For many organizations, this may represent a significant change. Businesses that have historically viewed lawful access obligations as primarily affecting telecommunications providers may find themselves receiving requests for subscriber information and needing to respond within prescribed timelines.

Bill C-22 also clarifies the legal immunity available to organizations that voluntarily disclose subscriber information where such disclosure is not otherwise prohibited by law. While this provides additional certainty, organizations will continue to need to assess their obligations under applicable privacy legislation and other legal frameworks.

From access powers to compliance obligations

The second major component of Bill C-22 may ultimately prove just as significant as the new access powers themselves.

To support the effectiveness of Information Orders, Bill C-22 creates the Supporting Authorized Access to Information Act (SAAIA), which would empower the governor-in-council and the minister to establish regulations or issue ministerial orders requiring electronic service providers to maintain the capability to produce information within prescribed timeframes.

Although many of the specific requirements will only become clear once regulations are adopted, the legislation already strongly indicates the government's intended direction. Future requirements may include the development, implementation, testing, and maintenance of operational and technical capabilities; the deployment and management of technologies that facilitate authorized access; and the retention of prescribed categories of metadata for specified periods.

These provisions represent a notable shift in approach.

Historically, organizations have focused primarily on how to respond once a lawful request is received. The SAAIA contemplates a framework in which regulators may also examine whether organizations have proactively developed the systems, governance structures, and operational processes necessary to respond effectively in the first place.

In other words, Bill C-22 is not solely about access. It is also about readiness.

The proposed regime would apply to a broad category of "electronic service providers," and certain organizations may ultimately be designated as "core providers" subject to enhanced obligations. Compliance will matter. The SAAIA contemplates inspections, audits, compliance orders, and significant administrative penalties for organizations that fail to meet their obligations.

Looking ahead

Bill C-22 follows a broader international trend. Governments in several jurisdictions have increasingly sought to ensure that investigative powers evolve alongside technological change, while placing greater emphasis on the ability of organizations to respond efficiently to authorized requests.

Canada now appears poised to move in the same direction.

Although Bill C-22 has not yet received royal assent, organizations providing telecommunications, electronic, or digital services should begin evaluating their readiness now. The operational and technical requirements contemplated by the legislation may require significant planning, governance, and implementation efforts.

Bill C-22 is more than a lawful access bill. It signals a broader evolution in the relationship between law enforcement authorities and the organizations that operate Canada's digital economy. By expanding access to subscriber information while establishing a framework for future technical and operational obligations, the legislation places a new emphasis on preparedness, governance, and institutional readiness.

For many organizations, the most important question may no longer be whether they can respond to a request when it arrives, but whether they can demonstrate they were ready long before it did.

Footnotes

1

Canada. Parliament. Bill C-22: An Act respecting lawful access. 1st Sess, 45th Parl, 2025. Online: LEGISinfo https://www.parl.ca/legisinfo/en/bill/45-1/c-22; Canada, Parliament, House of Commons, Bill C-22, An Act respecting lawful access, 3rd reading, 1st Sess, 45th Parl (2026), online: Parliament of Canada https://www.parl.ca/documentviewer/en/45-1/bill/C-22/third-reading, s.47.

Norton Rose Fulbright Canada LLP published this content on August 04, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 08, 2026 at 16:38 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]