More than 20 technology and privacy companies, including Toronto-based Tailscale and Windscribe, asked federal officials on Sept. 25 to make further changes to Bill C-22, the lawful access bill now before the Senate, warning it could weaken security and push firms out of Canada, according to BetaKit.
The bill passed the House of Commons in June and applies to any “electronic service provider” with Canadian subscribers, wherever the company is based. According to Windscribe’s summary of the letter, it would let the government require providers to build access capabilities and install monitoring equipment, retain user metadata, and comply with confidential ministerial orders that can last up to two years. “The order expires, but the secrecy doesn’t,” Windscribe wrote.
Ottawa has already made concessions. The government wrote explicit protection for end-to-end encryption into the bill and cut the proposed metadata retention period from one year to six months, according to iPhone in Canada. The signatories say that does not go far enough. Their letter asks the government to preserve encryption without forced backdoors, bar mandatory storage of data companies do not need to operate, and end secret orders with an undefined scope. “A backdoor for law enforcement is a backdoor for everyone,” the letter warns, as quoted by iPhone in Canada.
Tailscale chief executive Avery Pennarun said in the company’s statement, as reported by BetaKit, that “Canada should be able to support legitimate investigations without making secure systems easier to attack.” In a blog post, Tailscale argued that “the safest database is the one you never created,” and called for independent oversight, transparency reporting and sunset clauses. Windscribe chief executive Yegor Sak said the bill would make Canada an “untenable” place for most technology companies to operate, foreign and domestic.
The coalition is not limited to Canadian firms. Windscribe lists Nord Security, Kape Technologies (owner of ExpressVPN and Private Internet Access), Coinbase Canada, Tuta and easyDNS among the signatories, and iPhone in Canada reports that Proton and DuckDuckGo have also voiced opposition. Reports differ on the size of the group, with counts of 20 and 23 companies, and on how far the retention change goes: Tailscale’s blog describes a regime of up to one year, while other accounts say the six-month limit is now in the bill.
The stakes for Canadian businesses reach past the VPN sector. Because the definition of service provider is broad, software-as-a-service firms, messaging apps, cloud platforms and crypto exchanges with Canadian users could all fall within scope. Pennarun told BetaKit that about 40 per cent of Tailscale’s staff are in Canada, which underscores the dilemma for homegrown companies: comply with obligations they say create new attack surfaces, or restructure operations.
The timing matters. Amendments made in the Senate would send the bill back to the House, while a bill passed unchanged would move toward royal assent, after which many details would be set by regulation. That makes the Senate study the most realistic window for the changes the industry wants. This article could not independently review the bill text, and the government’s response to this latest letter was not available in the sources consulted.
For Canadian startups, the debate lands as early-stage funding is under pressure. RBCx reported in June that Canadian seed-stage fundraising fell 40 per cent year over year in the first quarter of 2026. Firms that sell privacy and security as a product now face the prospect of regulatory uncertainty at home on top of a tighter capital market.










