ExpressVPN has joined other VPN providers in criticizing Canada's proposed Bill C-22, a surveillance law that would require telecom companies to disclose customer data without a warrant in certain circumstances. The company's position is direct: no-logs architecture and encryption are non-negotiable, and the bill as proposed would undermine both.
What Bill C-22 Would Do
Bill C-22, also known as the proposed legislation to modernize investigative powers in Canada, has been controversial since it was introduced. Critics argue it would allow law enforcement to access subscriber information from telecom providers without the level of judicial oversight that Canadians have historically expected. The bill covers a range of surveillance powers, some of which have been piloted in other jurisdictions with mixed results.
The specific concern for VPN providers is the requirement that companies retain and disclose customer data in response to legal requests. If a VPN is operating under a no-logs model, there is nothing to disclose. But if the law creates pressure to log more data than a provider would normally keep, it effectively changes the security posture of the service from what users expect when they pay for it.
ExpressVPN's Position
ExpressVPN's statement frames the issue in terms of what its customers expect when they use the service. The company has built its reputation on not keeping logs of user activity. Any requirement to log more data would fundamentally change the product and would likely prompt questions from existing customers about whether the service they signed up for still exists in the form they signed up for it.
The company is not alone in this position. Multiple VPN providers have raised similar concerns, arguing that the bill would set a precedent for other jurisdictions to demand similar data retention requirements. The concern is not just about Canada but about the signal that Bill C-22 would send to governments in other countries that are considering similar legislation.
The Encryption Non-Negotiable
The framing of encryption as a non-negotiable is deliberate. Encryption that has a backdoor or that can be bypassed is not encryption in the meaningful sense. VPN providers argue that any requirement to compromise encryption for surveillance purposes would weaken the security of all users, not just the ones targeted by specific requests.
This is a well-established argument in the security community, and it has not stopped governments from trying to require backdoors. The difference in this case is that the bill appears to focus on data retention rather than encryption mandates, which is a slightly different approach. But VPN providers are concerned that the practical effect of mandatory data retention is the same as mandatory backdoors: a reduction in the security guarantees that the services claim to offer.
What This Means for Canadian Users
If Bill C-22 passes as currently drafted, the practical effect on VPN users in Canada would depend on how the law is implemented and how VPN providers choose to respond. Some providers might move their operations outside of Canada to avoid the requirements. Others might reduce the services they offer in Canada. Some might stay and comply, which would change the nature of the service for users who selected it specifically because of its no-logs policy.
None of these outcomes are good for users. The companies that have spoken up are making the argument that the bill creates a situation where there is no good outcome for anyone who cares about digital privacy. That is probably an overstatement, but it is not entirely wrong either.
The broader context is the global trend toward more surveillance infrastructure under the guise of security. Governments around the world have used the rhetoric of counterterrorism and crime prevention to expand their surveillance capabilities in ways that would have been politically impossible two decades ago. The VPN industry position is that this trend should be pushed back on whenever it appears, because each expansion normalizes the next one.
For Canadian VPN users specifically, the immediate question is whether their current provider's no-logs claim would remain valid if Bill C-22 passes. If the law requires logging of certain data, providers would either have to comply and change their privacy policy materially, or exit the Canadian market. Neither option is good for the user who selected a VPN based on its privacy guarantees.
The international angle is also worth considering. VPN providers operate across borders, and the legal landscape for data retention varies significantly between jurisdictions. A law that requires Canadian providers to log more data might affect providers that have users in other countries, even if those users are not Canadian. The cross-border nature of VPN services means that a single country's law can have effects that reach well beyond its borders, which is part of why VPN providers tend to be vocal about surveillance legislation in any country.
What the VPN providers are asking for is straightforward from a technical standpoint: do not pass laws that require data retention in ways that compromise the security properties that users depend on. Whether that ask will be heard is a political question, not a technical one. The history of surveillance legislation suggests that security concerns are often set aside in favor of law enforcement priorities, which is why the VPN industry is paying attention to Bill C-22 even though it is a Canadian law rather than a global one.
The legislative process is not finished, and there will be opportunities for public input before the bill becomes law in any form. VPN providers are encouraging their users to pay attention and contact their representatives, which is standard practice for issues that affect the industry. Whether that outreach translates into meaningful changes to the bill remains to be seen. The track record of surveillance legislation being meaningfully constrained by public opposition is not strong, which is probably why VPN providers are hedging their public statements with internal planning for various scenarios.
Sources
For more insights on digital privacy and security policy, visit XerAds Blog.







Komentar
Belum ada komentar. Jadilah yang pertama memulai obrolan.