Chasing Surveillance Powers, Canada Risks the CLOUD Act Deal It Needs
Bill C-22’s anti-security powers could cost Canada the tool it needs most to modernize investigations for the cloud era.
Some officials in Canada are again chasing new electronic surveillance powers, as they have episodically for decades, most recently repackaged in Bill C-22, entitled “An Act respecting lawful access.” The proposals have changed names over time, but the pattern remains familiar. New powers are said to be necessary, while the public case for them rests mostly on overgeneralized anecdotes. There is, however, one real problem that is long-standing, demonstrable, and acute. As information has become increasingly digital and increasingly held by U.S. providers, Canadian law enforcement and security agencies have had to rely on slow and limited diplomatic mechanisms with the United States to secure important evidence.
More than any new surveillance tool, Canadian authorities need a faster, direct, and more comprehensive way to obtain digital evidence from U.S. providers in the most serious cases, with rules that require independent oversight and protect Canadians and Americans alike. What Canadian authorities need is a Canada-U.S. CLOUD Act agreement.
A joint framework with the United States would allow Canadian officials, in appropriate circumstances, to seek electronic evidence directly from U.S.-based providers. The United Kingdom’s experience under its CLOUD Act agreement with the United States confirms what Canadian law enforcement and intelligence services already know: A CLOUD Act agreement is a “critical tool” for combating serious crime, including terrorism, fraud, threats, and extortion. Canada and the United States began formal negotiations in 2022, but no agreement has been reached. Securing a Canada-U.S. CLOUD Act agreement should be the primary goal of any Canadian policymaker seriously concerned with effective law enforcement and national security.
Yet many of the changes Canada is considering could put a CLOUD Act agreement with the United States out of reach. The legally dubious catalog of “lawful-access” powers proposed in Part 2 of Bill C-22 rests on premises discredited by decades of technical analysis and experience, chiefly that a provider can build access for one government without weakening security for everyone. Those powers pose serious cybersecurity threats, alarming security professionals, academics, service providers, civil society, and some Canadian lawmakers. The alarm should sound loudest inside the agencies Bill C-22 is supposed to help, because the same surveillance powers that threaten cybersecurity also threaten a CLOUD Act agreement that would give those agencies the cross-border evidence tool they need most.
The United States has made clear that cybersecurity is a national interest. A country cannot expect a CLOUD Act agreement while simultaneously claiming or exercising authority to undermine the security of products and services offered by U.S. providers or the data they hold. Adopting Bill C-22’s proposals would amount to an own goal, putting an invaluable agreement at risk for questionable powers with, at best, marginal operational value, as discussed below. It would squander a massive opportunity for the governments of both Canada and the United States and for the people they are charged to protect.
The Cross-Border Evidence Problem and the Canada-U.S. CLOUD Act Solution
U.S. providers have built an extraordinary and dynamic array of products and services that people around the world rely on every day to communicate, work, store memories, and manage their lives. Protecting that data from a wide range of malicious cyber actors is a top priority for the providers, as well as for the United States and its allies whose national security and economic prosperity depend on those providers’ ability to protect their users and data. The success of these services also means that evidence needed to investigate serious crimes may be in the hands of U.S. companies.
Evidence Held by U.S. Providers
For investigators outside the United States, it can be difficult to obtain evidence from a U.S. provider. Traditionally, a government obtains evidence from another jurisdiction through diplomatic, government-to-government processes, such as a mutual legal assistance treaty (MLAT). For many years, this process worked well enough. Starting in the early 2000s, as more and more evidence migrated to cloud services operated by U.S. providers, the U.S. MLAT system at the Department of Justice became overburdened and slow. Efforts to improve U.S. MLAT response, including through better resourcing in 2015, have still not caught up with the backlog. A 2021 Department of Justice Inspector General audit found the process still slowed by chronic understaffing and outdated systems. Canada’s experience reflects those continued delays, with requests taking roughly three to six months.
Attempts by agencies outside the United States to request data directly from U.S. providers, to avoid the slow diplomatic arrangements, are often thwarted by U.S. blocking statutes. These are laws that prohibit a provider from disclosing data directly, including to an investigating government outside the United States, absent an express exception. Blocking statutes serve legitimate national interests. They prevent U.S. providers from becoming instruments of demands that would violate civil liberties, human rights, or other public values the United States has reason to protect.
Slow diplomatic channels and blocking statutes together have created a situation ripe for conflicts between jurisdictions, however. Investigating officials in countries with democratically elected governments that robustly protect individual liberties and privacy need a faster and more complete avenue to obtain evidence held by U.S. providers. Meanwhile, the United States has legitimate interests of its own, including protecting its cybersecurity. At times, however, blocking statutes can prevent disclosure in important investigations in which the production of requested information by a U.S. provider would not be contrary to the interests of the United States.
The CLOUD Act Response
The United States can face the same problem when providers outside of the United States hold evidence, but the problem is far less acute. Many of the world’s major communications and cloud providers are based in the United States, so the cross-border evidence problem most often runs at U.S. providers rather than at providers elsewhere.
For the United States, the more serious consequence is the reaction its slow diplomatic processes and its blocking statutes may provoke. Governments frustrated that their investigations are hindered may grasp for unilateral measures, including technical capability mandates, requirements to defeat or withhold security features, data localization rules, extraterritorial surveillance laws, data retention mandates, and secrecy obligations.
These sorts of requirements imposed on U.S. providers by another country to satisfy its own surveillance appetite can make American technology and user data more vulnerable to exploitation by governments hostile to the United States, criminals, and other adversaries. Those measures directly conflict with the U.S. national interest in protecting people, the data they entrust to U.S. providers, and the products and services they rely on against demands that would compromise security or subvert the public values served by U.S. blocking statutes.
The U.S. Congress responded to this conundrum by passing the CLOUD Act in 2018. (The CLOUD Act has two distinct parts, one addressing the reach of U.S. legal process and the other, discussed here, authorizing bilateral agreements.) The act preserves the protective function of U.S. blocking statutes while creating a new path for governments that satisfy the act’s requirements to obtain evidence directly from U.S. providers. That path is a bilateral executive agreement, commonly called a CLOUD Act agreement. A CLOUD Act agreement does two things at once. It gives each country a direct process to send qualifying requests to providers in the other, and it removes the blocking-law barrier that would otherwise prevent those providers from responding. The request still has to satisfy the issuing country’s law. It also has to comply with the agreement’s safeguards. The result is a faster route to evidence without turning direct requests into a general bypass of blocking statutes.
Requests must be in connection with investigations of serious crimes, identify specific accounts or other identifiers, and be subject to review and oversight. A CLOUD Act agreement cannot be used for bulk collection. Nor can it be used to target the other country’s people or people located there, including by using a permitted target as a workaround to obtain information about those people. They also cannot require providers to decrypt data, maintain the ability to decrypt data, or change their encryption practices. After disclosure, the CLOUD Act agreements impose limits on the retention, use, dissemination, and onward sharing of the data obtained.
That structure is the answer to the jurisdictional conflict. It gives investigating authorities in one jurisdiction a quicker and more complete route to evidence in defined cases, while preserving the interests of the other jurisdiction. For the United States, it also offers a way to relieve pressure for unilateral measures that undermine cybersecurity by giving other governments a lawful path to the evidence they need.
Canada Needs a CLOUD Act Agreement
The United Kingdom and Australia have each reached and implemented CLOUD Act agreements with the United States. Canada should too.
Canada’s police and intelligence services, the Royal Canadian Mounted Police and the Canadian Security Intelligence Service, told Canada’s National Security and Intelligence Committee of Parliamentarians (NSICOP) that the U.S. blocking statutes present “significant jurisdictional challenges and delays,” with the problem more acute for intelligence services because even the slow diplomatic process available to law enforcement is unavailable to them. Both the police and the intelligence service see an answer in a Canada-U.S. CLOUD Act agreement. NSICOP agreed, emphasizing that “Canada stands to gain a lot from this agreement” and recommending that the government prioritize signing and implementing an agreement.
The United Kingdom’s experience shows that a CLOUD Act agreement provides a practical and very valuable path to obtaining evidence in the most important cases. The U.K. Home Office described its agreement with the U.S., which has been in place since 2022, as a “critical tool” whose impact has been “transformative,” giving U.K. law enforcement and intelligence agencies “more data, more quickly than ever before.”
The Justice Department’s first report to Congress about the agreement supports that assessment. As of October 2024, U.K. authorities had transmitted 20,142 orders to U.S. providers under the agreement, many involving real-time interception. Information obtained under the agreement has supported arrests, drug and firearms seizures, recovery of funds, and the identification of threats to life or of physical harm. Those results came through a process designed to avoid the delays of ordinary diplomatic channels. As expected, the United States used the agreement far less frequently to obtain information from U.K. providers. With its smaller population, Canada would likely use a CLOUD Act agreement less than the United Kingdom. The U.K.’s experience nonetheless demonstrates the practical value such an agreement would have for Canadian law enforcement and intelligence services.
This is the setting in which Bill C-22 should be judged. Canada has a real problem obtaining, in a timely fashion, evidence held by U.S. providers. It also has a path toward a reciprocal, rights-protective agreement that would address the real problem with a real solution.
Bill C-22 Puts Any Canada-U.S. CLOUD Act Agreement in Jeopardy
Bill C-22 threatens to put a Canada-U.S. CLOUD Act agreement out of reach. Canada should be doing everything it can to secure the agreement that would do the most to modernize how it obtains digital evidence from U.S. providers. Many of the proposed surveillance powers in Bill C-22 would deliver far less practical value than the 20,000 U.K. orders suggest a CLOUD Act agreement can. Worse, they would jeopardize Canada’s best path to the evidence its law enforcement and security agencies need, all while weakening cybersecurity.
Cybersecurity and Qualifying for a CLOUD Act Agreement
Cybersecurity is a national interest of the United States. President Trump recently reaffirmed that it is the policy of the United States to work with industry to identify and patch vulnerabilities, harden government and private-sector information systems against attacks, and ensure that the most secure technology is deployed rapidly to confront threats to the country. Secretary of Defense Pete Hegseth framed the imperative in starker terms, declaring that the United States is “bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities.” That cybersecurity interest is also reflected in U.S. policy on network security, and in the text and history of the CLOUD Act. Taken together, these authorities leave little room for doubt that “safeguard[ing] software and networks in the 21st century” is a national priority.
That priority bears directly on whether a country qualifies for a CLOUD Act agreement. Any country seeking a CLOUD Act agreement is asking the United States to set aside protective legal guardrails that otherwise prevent U.S. providers from disclosing data directly. Before granting that benefit, the attorney general, with the concurrence of the secretary of state, must certify to Congress that the other government’s laws and practices afford robust protections for privacy and civil liberties. To make that certification, the attorney general must determine, among other things, that the other government respects the rule of law, human rights, and free expression and demonstrates a commitment to promote and protect the global free flow of information and the open, distributed, and interconnected nature of the internet.
A country whose laws and practices threaten U.S. national interest cannot count on receiving that certification or that an agreement will survive congressional review. The United States has already confronted that conflict under the U.S.-U.K. CLOUD Act agreement. After that reckoning, it is clear that a government cannot reasonably ask the United States to lift protective legal barriers while reserving authority to require U.S. providers to weaken security protections, create vulnerabilities, or place globally deployed services and user data at greater risk.
The episode revolved around reports in early 2025 that the U.K. Home Office had secretly issued a Technical Capability Notice (TCN) to Apple directed at its Advanced Data Protection service. According to those reports, the TCN would have required Apple to build a technical capability to enable the government to obtain readable iCloud data despite the service’s end-to-end encryption. The reported secret mandate, if obeyed, would have weakened the security features protecting Apple users worldwide.
When word of the mandate leaked, it immediately became apparent that the United States had a serious cybersecurity problem and CLOUD Act problem. The reaction in Washington was both swift and bipartisan.
Sen. Ron Wyden (D-Ore.) and Rep. Andy Biggs (R-Ariz.) wrote to then-Director of National Intelligence Tulsi Gabbard about the U.K. mandate, pointing to the CLOUD Act agreement and asking her to protect Americans’ communications. Gabbard responded that the demand, if accurately reported, would be a clear and egregious violation of Americans’ privacy and civil liberties and would create a serious vulnerability for adversaries to exploit. She said U.S. officials were examining its implications for the U.S.-U.K. agreement. Sen. Alex Padilla (D-Calif.) and Rep. Zoe Lofgren (D-Calif.) asked the Department of Justice to investigate whether the U.K. had breached the agreement and to reevaluate the U.K.’s eligibility under the CLOUD Act, tying the encryption issue to statutory criteria including privacy, security, human rights, transparency, and congressional oversight.
Congress and Trump also pressed the United Kingdom directly. On March 13, 2025, a bipartisan group of lawmakers asked the U.K.’s Investigatory Powers Tribunal to lift the secrecy surrounding the reported Apple proceeding, warning that secret surveillance backdoors threatened Americans’ security and impeded congressional oversight. On May 7, 2025, the chairs of the House Judiciary and Foreign Affairs committees wrote to the U.K. home secretary, describing the reported order as a threat to Americans’ security, privacy, and constitutional rights and asking that Apple be allowed to disclose any such order to the Department of Justice. Trump raised concerns publicly and directly with then-Prime Minister Keir Starmer.
A subcommittee of the U.S. House Judiciary Committee held a hearing on June 5, 2025, focused on the U.S.-U.K. CLOUD Act agreement, the reported secret order directed at Apple, and the cybersecurity consequences of government demands to weaken encrypted services. Witnesses, including this article’s author, explained that mandates designed to facilitate government surveillance can become cybersecurity threats, creating or exposing vulnerabilities that hostile actors can exploit. The danger to U.S. cybersecurity interests is magnified when a government outside the United States coerces a U.S. provider to weaken security protections for users worldwide through secret legal proceedings whose existence and outcomes may remain unknown even to the U.S. government. The hearing also examined how Congress and the executive branch should respond to anti-security mandates imposed on U.S. providers and how they could prevent similar mandates in the future.
The issue still seems to be alive. However the TCN matter with the United Kingdom shakes out, one lesson is clear. A country seeking a new or renewed agreement, or the continued benefits of an existing one, can expect forceful resistance from both Congress and the executive branch if it enacts or exercises surveillance powers that put U.S. cybersecurity interests at risk.
Bill C-22’s Own Goal
By pursuing Bill C-22’s anti-security powers, Canada would score against itself, undermining its own bid for the CLOUD Act agreement it needs. Part 2 of the bill contains the same kind of corrosive surveillance authorities that made possible the U.K. TCN that was so alarming to U.S. officials in the administration and bipartisan members of Congress. Unsurprisingly, officials in the United States greeted Bill C-22 with the same alarm.
In a May 7 public letter expressly invoking the U.K. episode, key members of Congress conveyed to Canada’s public safety minister that Bill C-22 would seriously degrade cybersecurity protections and jeopardize Canada’s prospects for an indispensable CLOUD Act agreement. Wyden separately urged the Trump administration to ensure that any CLOUD Act agreement with Canada establishes “ironclad, explicit prohibitions against” the “extraterritorial technical and prospective engineering mandates” in Bill C-22.
The timing of these warnings underscores the gravity of the cybersecurity concerns while allowing for hope that Canada will change course. Parliament has not passed the bill, no mandate has been issued to a U.S. provider, and no Canada-U.S. CLOUD Act agreement is in place or even being considered by Congress. Clearly, the United States is unwilling to take a wait-and-see approach, even with a close ally, when the security of services offered by U.S. providers is at stake. Critically, this timing gives Canada an opportunity to salvage the agreement it needs.
The cybersecurity threat in Canada’s lawful-access ambitions is concentrated in Part 2 of Bill C-22. In broad terms, that part would authorize Canadian authorities to require “electronic service providers,” including providers outside Canada that offer services in Canada, to build and maintain surveillance capabilities for government use. Regulations or orders made under Bill C-22’s statutory authority could require providers to incorporate government or third-party spyware into their systems, or install government-controlled surveillance equipment in their networks. They could also limit future implementation of encryption.
The bill also includes mandatory retention of metadata, creating a massive, artificial store of sensitive data that providers would not otherwise keep. That resulting store presents a tempting target for attackers. All of this in the hope that some vanishingly small fraction of it might prove useful to law enforcement later. Compounding matters, the bill permits ministerial orders to be issued and enforced in secret, potentially without the U.S. government ever learning of them.
Together, these authorities would create a surveillance-readiness regime that reaches directly into the security architecture and practices of modern services designed to protect users and their data. These are exactly the kinds of powers that implicate U.S. cybersecurity interests and could sink a CLOUD Act agreement.
The House of Commons has hurriedly added ambiguous language in the latest version of Bill C-22 limiting the government’s authority to create a “systemic vulnerability” and precluding orders mandating “decryption.” While welcome, those changes solve little. The definition of “systemic vulnerability” remains flawed and would leave room for mandates that undermine encryption. Further, an agency may characterize a mandate as tied to authorized access for a particular investigation, while the provider may have no practical means to comply with the mandate without a change that undermines security across the service.
Other vague definitions and imprecise terms in Bill C-22, including “core providers” and “electronic service providers,” create a substantial risk that the regime will be applied unpredictably and far beyond what Parliament likely intends, with little oversight to detect and correct resulting problems. Exacerbating matters, such mandates can chill investment in security or dissuade providers from implementing enhancements, for fear those security improvements will later have to be modified or undone by government fiat.
Without a CLOUD Act agreement, Canada can stockpile increasingly intrusive tools and still face the same cross-border evidence problem as before. Trading away that agreement for questionable surveillance powers would be a loss for Canada, the United States, and the people their governments are responsible for protecting.
Salvaging the Agreement
Canada still has time to salvage the agreement it needs. Doing so will require more than trimming Bill C-22 around the edges or making vague assurances. The United States has already identified the bill’s anti-security surveillance powers as a threat to a Canada-U.S. CLOUD Act agreement. Parliament must thoroughly address those powers.
Providers, cybersecurity experts, civil society organizations, lawyers, and academics have suggested a range of changes to an earlier version of the bill. The bill’s sponsors reacted with an unbecoming mix of name-calling and revisions that would not fix the bill’s central defects. The sponsors then rushed the bill through the House of Commons without debate. Michael Geist, who followed the amendment process closely, called the bill’s final days in the House of Commons “a genuine abrogation of democratic norms” and wrote that the government spent those days ensuring it would never have to answer the substantive criticism.
Those tactics leave the bill’s cybersecurity flaws uncorrected. The Senate is now the last chance to fix them before they cost Canada a CLOUD Act agreement.
Across the proposals and commentary, calls for Parliament to act cluster around three cybersecurity issues.
First, Parliament should prohibit anti-security surveillance mandates. The government should not, in the name of surveillance, weaken or hinder a provider’s adoption or use of cybersecurity measures. Cybersecurity measures should be understood broadly to include technical and nontechnical steps that protect or promote the resilience, privacy, confidentiality, integrity, or availability of data, or the processing, devices, systems, or services associated with the provider.
The prohibition should reach the practical ways the government could force a provider to make its services less secure. It should bar demands to disable or suppress security features such as encryption, build or preserve exceptional-access capabilities, or add surveillance functionality, including government or third-party software or equipment. It should also protect security updates and vulnerability remediation from government delay or interference. Assistance should be confined to capabilities the provider already possesses and can use without weakening or hindering cybersecurity measures.
The House of Commons amended the bill to relieve a provider from complying with a requirement that would create a “systemic vulnerability.” It then largely withdrew that protection by defining the term to exclude a risk confined to information concerning a particular surveillance target. This exclusion swamps the rule. A capability built to compromise one user’s security can become a reusable weakness against others. An order may identify a permissible target, but the resulting vulnerability remains a threat to all.
Second, Parliament should eliminate secret executive fiat over product design and technical capabilities. The bill permits the government to impose secret ministerial orders on providers. Although the framework requires intelligence commissioner approval, that approval does not substitute for prior authorization by a court. The provider’s only recourse is judicial review, which provides no automatic relief. Unless the provider persuades a court to grant a stay, it must comply with the mandate while litigating its legality or face penalties for refusing. Parliament should remove the framework in its entirety.
If the law retains any individualized technical-order authority, each mandate should require prior judicial authorization. A provider should be able to file a legal challenge that automatically stays the order and any penalties for noncompliance. If the government wants to keep an order secret, it should have to satisfy a judge, based on particularized facts, that secrecy is necessary, and secrecy should last only as long as necessary.
The bill should also provide the United States with the transparency needed for a Canada-U.S. CLOUD Act agreement. When Canada imposes or attempts to impose a surveillance-related mandate on a U.S. provider, or seeks information from a provider under the agreement, no secrecy requirement should prevent that provider from notifying the U.S. government. Without that protection, Canada could conceal conduct the United States may need to consider in determining whether Canada qualifies for the agreement and remains qualified to use it.
Third, Parliament should eliminate the blanket data-retention requirement. The requirement undermines data minimization and deletion practices, both cybersecurity measures that protect user privacy and confidentiality and limit the harm from a breach. The government should not force a provider to collect or retain broad categories of sensitive information across its user base when the provider has no independent business or security reason to do so. Such a mandate would result in stockpiles of revealing information about people unconnected to any investigation, creating attractive targets for attackers even though almost none of the information will ever be sought by investigators. Canada already has the targeted preservation tools it needs for information connected to particular investigations.
These are minimum repairs. Together, they would address the cybersecurity defects now threatening Canada’s prospects for an agreement.
* * *
Canada’s law enforcement and security agencies know what they need most from legal modernization in the age of the cloud. They need a Canada-U.S. CLOUD Act agreement. Parliament should clear the path to that attainable agreement by holding hearings on the agreement’s status and what it will take to complete negotiations, and by enacting the provisions Canada needs to implement it. Part 2 of Bill C-22 would instead block the only road there. Canadians are left stranded with intrusive surveillance authorities of little public safety value, providers with less secure offerings, and the government with the same cross-border evidence problem it has today.
