To: 
Ursula von der Leyen
, President of the European Commission
Maroš Šefčovič
, Commissioner – Trade and Economic Security
Michael McGrath
, Commissioner – Democracy, Justice, the Rule of Law and Consumer Protection

Members of the European Parliament

We, the undersigned organisations and experts, write to urge you to act before Canada’s Senate completes its consideration of Bill C-22, the Lawful Access Act, and to press Canada to remove the bill’s surveillance capability mandates and its blanket data retention regime. The bill was referred to Canada’s Senate in June of this year, which is the bill’s second and final stage in Parliament before it becomes law. The Senate committee’s study of the legislation will commence after Parliament resumes its fall sitting dates in late September, and could be concluded as early as October of this year.

This is not a domestic Canadian matter. Bill C-22 reaches any provider whose services are used by people in Canada, any Canada-based provider whose services are used by people outside Canada, and to providers with no Canadian users at all, if they have a Canadian entity or are an entity belonging to a corporate group that carries out any business activity in Canada. It would allow a Canadian minister to order a European company, in secret, to weaken the security of products used across the EU, and to retain the metadata of European users. It would also do so as the EU and Canada negotiate a Digital Trade Agreement and deepen the integration of their digital economies. 

Bill C-22

has been
widely

criticised
, including by the

Internet Architecture Board
and members of the
Global Encryption Coalition
. Bipartisan members of the United States Congress have
written
directly to Canada’s Minister of Public Safety,
warning
that the bill would degrade cybersecurity. Europe should not stay silent.

The bill mandates capabilities that break security for everyone. It compels an unidentified class of “electronic servi

… [more]