Psiphon Considers Leaving Canada Over Lawful Access Bill
Canadian VPN provider raises concerns about Bill C-22 as Ottawa seeks greater access to digital information for law-enforcement and national-security investigations

By: Ebenezer Adugyamfi & Emmanuel Ayiku for GhanaianNewsCanada
October 5, 2026
Canadian VPN provider Psiphon is considering leaving Canada over concerns about the federal government’s controversial lawful-access legislation, adding its name to a growing group of technology and privacy companies questioning the potential impact of Bill C-22.
The legislation, formally known as the Lawful Access Act, 2026, is designed to give Canadian law-enforcement and national-security agencies greater technical ability to obtain information from electronic service providers when they already have legal authority to do so.
The bill has attracted opposition from privacy advocates and technology companies, who argue that some of its requirements could force service providers to alter their systems in ways that could weaken privacy or create cybersecurity risks.
The House of Commons passed the legislation in June after the government fast-tracked committee consideration. It is now before the Senate.
For Psiphon, a company whose service is specifically designed to help people access the open internet in countries where online access is restricted or monitored, the debate has particular significance.
Why Psiphon is concerned
Psiphon is an Ontario-based Canadian corporation that provides a VPN and anti-censorship service.
The company’s stated mission is to help people access information where internet access is restricted, monitored or blocked.
Its current privacy policy says the company does not log users’ IP addresses, websites they visit or the content of their internet traffic. Psiphon says it instead collects aggregate information about how its network is being used, including connection counts, data volumes and network performance.
That privacy model is central to the company’s concerns about the proposed legislation.
Psiphon is among technology providers that have raised concerns that the requirements contained in Bill C-22 could create obligations that conflict with their existing privacy architecture.
If the company were required to maintain technical capabilities that could facilitate access to information it does not currently retain or cannot access, the issue could become particularly significant for its business model.
What Bill C-22 would do
Bill C-22 was introduced by the federal government in March 2026 and received second reading in the House of Commons in April.
The legislation has two principal components.
The first would amend existing laws to facilitate the timely gathering and production of certain information during investigations.
The second would establish the Supporting Authorized Access to Information Act, creating a regulatory framework requiring certain electronic service providers to maintain technical capabilities that allow them to comply with legally authorized requests.
The government argues that these measures are necessary because technology has changed faster than Canada’s lawful-access framework.
Public Safety Canada says investigators can sometimes obtain a warrant or production order but still be unable to obtain the information because a service provider does not have the technical capability to provide it.
The government says this can result in lost evidence, delayed investigations or investigations being abandoned.
Ottawa has also argued that Canada is behind other members of the Five Eyes intelligence partnership and other jurisdictions in requiring electronic service providers to maintain lawful-access capabilities.
Government says the bill does not create new access powers
The federal government’s position is that Bill C-22 does not simply give police or intelligence agencies unrestricted access to Canadians’ private information.
Instead, Ottawa says the legislation is primarily intended to ensure that service providers can comply with existing legal authorities.
The Department of Justice’s Charter Statement says the bill would not grant new authorities to lawfully access information or expand existing authorities for such access.
Instead, it would establish requirements for certain electronic service providers to develop and maintain capabilities needed to give effect to existing authorities under laws including the Criminal Code and the CSIS Act.
The government has therefore presented the legislation as a technical modernization of Canada’s investigative framework rather than a new system of unrestricted surveillance.
Privacy advocates see broader risks
That explanation has not eliminated concerns from privacy organizations.
Canada’s Privacy Commissioner, Philippe Dufresne, appeared before the House of Commons Standing Committee on Public Safety and National Security in May to discuss Bill C-22.
Dufresne acknowledged that the revised legislation included improvements compared with its predecessor, including changes to confirmation-of-service demands and requirements to consider privacy and cybersecurity impacts.
However, his office also called for additional amendments to strengthen privacy protections.
The Canadian Civil Liberties Association and the University of Toronto’s Citizen Lab have also examined the legislation and raised concerns about the potential consequences of secret government orders and technical requirements imposed on service providers.
Privacy advocates have argued that even when access to information is legally authorized, requiring companies to build or maintain technical capabilities could create broader cybersecurity risks.
Encryption has become a major point of debate
Encryption is one of the most contentious issues surrounding the legislation.
Technology companies have expressed concern that governments could eventually require systems to be modified in ways that make encrypted communications more accessible.
Apple and Meta have previously warned that aspects of Canada’s proposed lawful-access framework could create pressure to weaken encryption.
The Canadian government, however, has argued that Bill C-22 should not be interpreted as a requirement to introduce systemic weaknesses into encrypted systems.
Following amendments passed by the House, the legislation also states that nothing in the bill should be interpreted as compelling an electronic service provider to decrypt encrypted user information.
That amendment was intended to address concerns from companies and privacy advocates, although critics continue to argue that other provisions remain too broad.
Other technology companies have raised similar concerns
Psiphon’s position comes amid wider resistance from VPN and technology companies.
NordVPN previously warned that it could consider limiting or removing its presence in Canada if the legislation required it to compromise its no-logs architecture or encryption protections.
Other technology companies and privacy-focused services have also warned that they could reconsider their Canadian operations depending on how the legislation is ultimately implemented.
Windscribe, another Canadian VPN provider, has separately said it would not change its logging or privacy policies because of Bill C-22 and has discussed the possibility of relocating its headquarters if necessary.
The debate therefore extends beyond one company.
It raises a broader question about whether Canadian technology companies can continue operating under privacy models that deliberately limit the information they collect if federal regulations require them to maintain additional technical capabilities.
What Psiphon’s departure could mean
If Psiphon ultimately leaves Canada, the immediate effect would be a change in the company’s corporate presence and potentially where its operations are legally based.
It would not necessarily mean that Canadians could no longer access Psiphon’s services.
VPN companies can operate infrastructure and serve customers across international jurisdictions, and the precise consequences would depend on how the company structures its operations and how Bill C-22 is ultimately implemented.
The larger significance would be symbolic and regulatory.
Psiphon is a Canadian company whose stated purpose is closely connected to online privacy and access to information. Its potential departure would therefore add to concerns that Canada’s regulatory environment could make it more difficult for privacy-focused technology companies to maintain their existing business models.
Ottawa argues that public safety requires modernization
The federal government maintains that the legislation is needed because criminals and other threat actors increasingly use digital services to communicate and organize activities.
Public Safety Canada identifies investigations involving drug trafficking, money laundering, extortion, smuggling, child sexual exploitation, murder, terrorism, espionage and foreign interference among the areas where lawful access can be relevant.
CSIS has similarly argued that outdated technical capabilities can make it difficult to act on information obtained through judicially authorized investigations.
The government has also pointed to international cooperation.
Canadian authorities frequently work with foreign law-enforcement and intelligence agencies, and Ottawa argues that maintaining comparable technical capabilities is important for Canada’s ability to participate effectively in those investigations.
Bill now moves to the Senate
With the House of Commons having passed Bill C-22, the next major stage is consideration by the Senate.
The Senate process could provide another opportunity for parliamentarians, technology companies, civil-liberties organizations and privacy experts to debate the legislation and propose further changes.
The exact regulatory requirements that will eventually apply to different categories of electronic service providers will also be important.
The legislation establishes a framework under which regulations can determine specific technical and operational requirements, meaning that some details will depend on regulations developed after the bill becomes law.
That uncertainty is one reason technology companies continue to monitor the legislation closely.
A broader debate over privacy and security
The dispute over Psiphon and Bill C-22 reflects a larger international debate.
Governments argue that law-enforcement agencies need modern tools to investigate serious crimes and national-security threats in an increasingly digital world.
Technology companies and privacy advocates, meanwhile, argue that creating technical access capabilities can introduce risks that extend beyond the individual investigation for which access was originally authorized.
The central issue is therefore not simply whether police should be able to access information when they have lawful authority.
It is also about what companies should be required to build, retain or maintain so that such access is technically possible.
For Psiphon, that distinction is particularly important because its business model is built around minimizing the information available about its users.
As Bill C-22 moves through the Senate, the government’s ability to balance investigative requirements with privacy, encryption and cybersecurity concerns will remain under scrutiny.
And if Psiphon ultimately decides that remaining in Canada is incompatible with its privacy model, it would become one of the most visible examples yet of the potential business consequences of Canada’s new approach to lawful digital access.


