Table of Contents Canada’s Telecommunications and Internet Legislation, 2022–2026 A Critical Charter and Common-Law Analysis Prepared July 2026. Covers Bills C-11 and C-18 (44th Parliament, now in force) and Bills C-8, C-9, C- 22, and C-34 (45th Parliament). A note on scope and structure before we start Two housekeeping points, because precision matters if this is going into anything resembling a legal or advocacy document. First, bill numbers are recycled every Parliament. “C-22,” “C-34,” “C-8,” and “C-9” in the 45th Parliament (2025–present) are unrelated to any bills with those numbers in earlier Parliaments. I’ve treated them as the current bills, per the status you gave me (C-8/C-9 in force last month, C-22 through the House, C-34 at first reading). Second, C-9 is not telecommunications legislation. It’s a Criminal Code amendment (hate propaganda, hate crime, access to religious/cultural sites). It touches “the internet” only incidentally — one new offence covers public display of hate/terror symbols, which could theoretically capture online display, but the Act is not a telecom or platform statute the way the other five are. I’ve included it as asked, flagged clearly, and you should decide whether it belongs in a telecom-focused critique or a separate one. On structure: this document walks through the six bills in chronological/parliamentary order — C-11 and C-18 from the last Parliament first, then C-8, C-9, C-22, and C-34 from the current one, each with its own summary, critical read, and penalty list. Two focused comparisons sit directly under the bill they belong to: the FBI National Security Letter/Nicholas Merrill comparison follows C-8, and the SORM comparison (with a plain-language explainer of what SORM actually is) follows C-22. After all six bills, the document steps back for three cross- cutting sections that only make sense once you’ve seen all six: the third-party doctrine analysis, the compelled-infrastructure/small-provider analysis, a penalty summary table, and a closing “combined ramifications” section. With that, in order: A quick primer: what is an “Administrative Monetary Penalty” (AMP)? You’ll see this term — usually just the acronym “AMP” — in almost every penalty section below, so it’s worth explaining once, up front, rather than leaving readers to guess or scroll back looking for a definition. An AMP is a fine, but it is not a criminal fine, and the process behind it is fundamentally different from the process behind a criminal or quasi-criminal charge. When most people hear “penalty” or “fine,” they picture something like a speeding ticket or a criminal charge: police or a prosecutor lays the charge, and it goes before a judge or justice of the peace who is independent of the person or agency doing the accusing. An AMP skips that structure almost entirely. Who writes the rule, who decides you broke it, and who fines you are often the same body. Parliament typically sets only the maximum dollar amount in the statute itself (e.g., “up to $10 million per violation”) and then hands the actual rule-making to the regulator — the CRTC, a minister, or in C-34’s case a brand-new Commission. That same regulator then investigates whether a company broke its own rule, decides that it did, and sets the penalty amount — all inside one administrative body, without a separate prosecutor and without an independent judge presiding over the initial decision. In the language of the rule-of-law tradition this document has been using throughout, that’s a concentration of rule-making, investigative, and adjudicative functions in a single executive-branch actor — precisely the separation criminal law insists on keeping apart. The standard of proof, and who has to prove what, is also reversed compared to a criminal or quasi-criminal offence. A true criminal charge requires the Crown to prove guilt beyond a reasonable doubt , including some level of fault (intent, recklessness, or negligence, depending on the offence). Many quasi-criminal regulatory offences — the kind prosecuted in provincial offences court — still require the Crown to prove the prohibited act beyond a reasonable doubt, though the accused can raise due diligence as a defence. An AMP regime typically drops both protections: the regulator need only show, on a much lower civil standard (balance of probabilities, i.e., “more likely than not”), that the conduct occurred — and several of the AMP regimes in this document are effectively strict liability , meaning the company is presumed to have contravened once the facts are shown, and it is the company’s burden to prove, on the balance of probabilities, that it exercised due diligence to avoid the violation. That is the “guilty until proven innocent” dynamic you’re picking up on: it isn’t that the company has literally no defence, but the burden of proof has shifted onto the accused party to establish its own innocence, rather than sitting with the state to establish guilt — the reverse of the presumption that normally anchors criminal and quasi-criminal law. Overturning an AMP is much harder than appealing a fine. A criminal or quasi-criminal conviction can typically be appealed to a higher court, which can review the facts, the law, and in some cases hear the matter fresh. An AMP, by contrast, is not usually “appealed” in that sense at all — the company’s only real recourse is judicial review , a narrower and more deferential process where a court asks only whether the regulator’s decision was reasonable , not whether the court would have reached the same conclusion itself. Courts reviewing an AMP will generally not reweigh the evidence or substitute their own judgment for the regulator’s; they will uphold the penalty unless the regulator’s reasoning was genuinely unjustifiable. That is a much higher bar for the company to clear than a normal appeal, and — as with the gag- order litigation discussed under Bill C-8, below — the cost and burden of even attempting it falls entirely on the company, with no guarantee of success even where the underlying penalty seems disproportionate. Why regulators use AMPs instead of ordinary prosecution: they’re faster, cheaper for the state, and don’t require the higher evidentiary bar or the involvement of police and Crown prosecutors — which is precisely why every single one of the six bills in this document reaches for an AMP regime as its primary enforcement tool, rather than relying on the criminal courts. That efficiency is the whole institutional appeal of AMPs, and it’s also exactly what makes them worth understanding clearly: efficiency for the regulator generally comes at the direct expense of the procedural protections a person or company would otherwise have. 1. Bill C-11 — Online Streaming Act (in force, April 27, 2023) Short name: The Streaming Act / CanCon-for-the-internet law. What it does: Amends the Broadcasting Act to bring anything that transmits programs over the internet to the public — Netflix, Spotify, YouTube, and by the CRTC’s own admission during committee, potentially algorithmically-surfaced user content — within the definition of a regulated “broadcasting undertaking.” It replaces licensing with a “conditions of service” model, letting the CRTC compel Canadian-content financial contributions and, critically, order platforms to make Canadian-designated content more “discoverable” — i.e., manipulate the ranking of what an algorithm shows you. The critical read: • Delegation without definition. Parliament didn’t decide what “discoverability” means, what percentage of a feed must be CanCon, or which entities cross the threshold into regulation. It handed that to an administrative tribunal (the CRTC) via open-ended conditions of service, revisable at will, with no sunset and no fixed licence term (the seven-year cap was removed). That is about as far from the rule-of-law ideal of knowable, prospective, general rules as domestic regulatory law gets — it’s closer to rule by an agency’s evolving discretion than rule of law. • The “not user content” assurance doesn’t hold up on the bill’s own text. Section 4.1’s carve-out for user-generated content was added specifically because the original draft plainly captured it, and even after amendment, the CRTC retains authority to bring a “commercial” YouTube channel or podcast into scope by regulation. The government’s own minister publicly muddied this in real time (the Question Period exchange about creators with “material impact” on the economy), then walked it back — which is not how a rights-respecting statute is supposed to be built: clarity was supplied after the fact, by press statement, not by amendment to binding text. • Charter angle: Section 2(b) freedom of expression includes a listener’s/viewer’s right to receive expression, not just a speaker’s right to transmit it. A regime that compels a private intermediary to re-order what you see — as opposed to compelling funding, which is a lesser intrusion — is a more direct interference with the audience’s expressive autonomy than the government’s framing (“we’re not touching what you post”) acknowledges. No court has yet tested this squarely; it is very much an open question, not a settled one, and I’d treat any confident claim either way with suspicion. • Extraterritorial commercial coercion dressed as domestic culture policy: the “cultural industries” exception under trade law was built for content quotas on television, not for compelling foreign firms to fund a parallel subsidy system administered by a domestic regulator with no reciprocal obligation. Whether that survives CUSMA scrutiny is a live trade dispute, not resolved. Penalties (Broadcasting Act, as amended): - Administrative monetary penalties (AMPs) for violating CRTC orders/regulations: up to $25,000 per violation for individuals , up to $10 million per violation for corporations (first offence; escalates for repeat). - No criminal penalties in C-11 itself. - Enforcement is entirely administrative — CRTC issues the order, CRTC assesses the penalty, with judicial review available only after the fact, on administrative-law (not full merits) standards. 2. Bill C-18 — Online News Act (in force, June 22, 2023 / effective December 19, 2023) Short name: The News Act / link-tax law. What it does: Compels “digital news intermediaries” with sufficient size and market power (in practice, Google and — until it walked away — Meta) into mandatory bargaining with Canadian news businesses over compensation for making news content “available,” including via linking. If bargaining fails, CRTC-supervised final-offer arbitration imposes a binding outcome. The critical read: • This is a compelled-payment-for-linking regime, and that is a genuinely novel intrusion on how the open web has always worked. Hyperlinking to publicly posted content has never, in Canadian or any common-law jurisdiction, required payment to the linked party — that’s closer to the logic of a compulsory licence than to copyright law, and Parliament built it outside the Copyright Act entirely, avoiding the doctrinal guardrails (fair dealing, originality thresholds, term limits) that would normally constrain such a scheme. • It produced the outcome the drafters said wouldn’t happen. Government assurances during debate were that platforms would negotiate, not exit. Meta exited entirely rather than negotiate — meaning the practical result of the Act, for the platform with the largest share of Canadians’ social news consumption, was to reduce the discoverability and diversity of news Canadians see, not increase it. During the 2023 wildfires this had real, acknowledged public-safety costs. A law that predictably narrows the information environment it claims to protect is hard to square with the “diversity of voices” rationale the government advanced to justify it. • Asymmetric, discretionary application. The Act applies to firms the CRTC decides meet size/dominance thresholds — currently, as a practical matter, one company (Google, post-exemption deal). That is a bespoke regulatory regime for named commercial actors dressed in general statutory language, which sits uneasily with rule- of-law norms against ad hoc, targeted legislation. • The Google settlement effectively rewrote the statute’s purpose by negotiation. The $100M annual pooled-fund deal Google struck to exit mandatory bargaining was not contemplated in the bill’s original design (a firm-by-firm bargaining/arbitration model) — critics on both sides note this “upended” the Act’s structure before its enforcement mechanism was ever tested. That’s a strong signal the underlying mechanism, as legislated, was not administrable as written. Penalties (Online News Act): - AMPs of up to $15 million per day against a non-compliant platform (uncapped in aggregate — it accrues daily). - No criminal offences; purely administrative, CRTC-driven. 3. Bill C-8 — An Act respecting cyber security (Statutes of Canada 2026, c. 9; Royal Assent June 16, 2026) Short name: The Cyber Security Act / CCSPA (successor to the defunct C-26). What it does: Two parts. Part 1 amends the Telecommunications Act to let the Governor in Council and the Minister of Industry order telecom providers to do — or stop doing — “anything” deemed necessary to secure the telecom system, backed by an AMP regime. Part 2 enacts the Critical Cyber Systems Protection Act (CCSPA), imposing mandatory cybersecurity obligations on “designated operators” of “critical cyber systems” across telecom, banking, energy, nuclear, interprovincial transport, and clearing/settlement systems. The critical read — this is the one that should worry a common-law lawyer most: • Unlimited, undefined ministerial direction power, checked only after the fact. Section 15.1 of the amended Telecommunications Act lets the Minister or Cabinet order a carrier to “do anything, or refrain from doing anything” to secure the system — that verb is not narrowed by an enumerated list. A Speaker’s ruling in March 2026 explicitly struck out committee amendments that would have required prior judicial authorization for these orders, on the technical ground that judicial pre-authorization was a “new concept” beyond the bill’s approved scope at second reading — a procedural technicality that gutted the most important substantive safeguard Parliament’s own committee had added. What survived is after-the-fact judicial review (deferential, administrative-law standard) plus notice to security-oversight bodies — not a warrant, not prior independent authorization, not anything resembling the Hunter v. Southam “prior authorization by a neutral arbiter” standard that has governed state search-and- seizure since 1984. • Secrecy orders with gag provisions. Section 24 makes it an offence for a designated operator even to disclose that a cyber security direction was issued, let alone its content, subject only to a discretionary weighing test the decision-maker applies to itself. There is no independent advocate regime (the government explicitly declined to create one) to test the government’s evidence where an order is issued in secret — which is a genuine gap compared to, e.g., the special-advocate model Parliament built for CSIS security- certificate proceedings after Charkaoui This gag provision is significant enough to warrant its own comparison, immediately below, to the FBI’s National Security Letter regime and Nicholas Merrill’s eleven-year fight against his own gag order. • The “no interception” carve-out is narrower than it looks. Section 6 forbids ordering interception of a “private communication” as defined in Criminal Code s.183 — but that definition covers content , not metadata, routing information, traffic-shaping, or the sweeping “do anything necessary” language that could compel a carrier to degrade, block, or reroute service to specific destinations or classes of traffic without ever “intercepting a communication” in the narrow statutory sense. A carrier ordered to block access to a service, or to throttle traffic to/from it, has not had a “private communication intercepted” under s.183 — so the carve-out doesn’t actually reach the most likely tool of state control over the internet layer. Penalties (Telecommunications Act Part 1 / CCSPA Part 2): - Telecommunications Act AMPs: up to $10 million per violation for organizations, rising to $15 million for repeat contraventions . - CCSPA carries its own AMP/compliance-order regime for designated operators (amounts set by regulation not yet finalized as of this writing). - Criminal exposure : certain contraventions can be prosecuted as offences — up to 2 years less a day on summary conviction , up to 5 years on indictment . - Personal director/officer liability : officers and directors who “direct, authorize, or acquiesce” in a violation face personal exposure — a meaningful departure from the corporate-veil norm, deliberately moving compliance risk into the boardroom. - A due-diligence defence exists for the AMP regime. C-8’s gag order compared to the FBI’s National Security Letter regime You asked specifically for this comparison, and it is a strong, precise fit — the mechanism is close, and the American experience is a documented, completed case study of exactly what happens when a gag order like C-8’s is left to run. The mechanism, side by side: Feature FBI National Security Letters (post-9/11, pre-USA Freedom Act) Bill C-8 secrecy/gag orders (ss. 24–25, Telecommunications Act) Who issues it FBI, administratively — no judge, no warrant Minister or Governor in Council, administratively — no judge, no warrant Threshold Relevance to an authorized investigation, self-certified by the FBI “Necessary and reasonable in relation to the gravity of the threat,” self-assessed by the decision-maker at time of issuance Recipient’s right to disclose the order exists No — categorical, and originally indefinite No — prohibited outright under s.24, except “to the extent necessary to comply” Feature FBI National Security Letters (post-9/11, pre-USA Freedom Act) Bill C-8 secrecy/gag orders (ss. 24–25, Telecommunications Act) under s.25 Duration of gag Originally indefinite/permanent; capped at 3 years by 2014 policy change, then reformed by USA Freedom Act (2015) to require periodic FBI reassessment Not fixed in the Act — duration is set by the decision-maker issuing the order, informed by a discretionary list of factors it weighs itself; no statutory cap disclosed in the bill text as passed Who bears the cost of challenging it The recipient, entirely, at their own expense — the burden is on the gagged party to litigate for the right to speak Structurally identical: a designated operator would have to seek judicial review of the order itself (after-the- fact, deferential standard) to contest either the substance or the secrecy — there is no equivalent of an automatic, government-initiated periodic review triggering release Independent advocate to test the government’s case while it’s under seal None, originally. None added in Bill C-8 either — the government explicitly declined to create a special- advocate regime for these orders Same — Osler’s own analysis of the Bill flags this as a structural gap: “the absence of a special advocate leaves no independent voice to test the government’s evidence in closed proceedings” What ultimately fixed it (in the U.S.) Litigation — years of it, by one recipient, at his own expense, with pro bono counsel Untested — C-8 has Royal Assent but the ss. 24-25 regime has not yet been challenged in court Why Nicholas Merrill’s case is the right cautionary tale, not just a rhetorical flourish: Merrill received his NSL in February 2004 as the owner of a small New York ISP with roughly 200 customers — Calyx Internet Access. The letter demanded subscriber records and was accompanied by a gag order forbidding him from telling “any person” that he had received it, not even his family. He challenged it immediately, won his first constitutional ruling within months (a district court found the NSL gag provisions unconstitutional as early as 2004), and the government’s response was not to stop issuing NSLs — it issued roughly 500,000 more while the litigation dragged on. Merrill won the right merely to identify himself as a recipient in 2010 — six years in. He did not win the right to describe what the letter actually asked for until September 2015 — eleven years after it was served, and only because a single federal judge, on a fresh 2014 filing represented by a law school clinic working pro bono, declined to accept the government’s continued secrecy justification. The government did not appeal, not because it lost the legal argument definitively, but — in Merrill’s own words — because it decided to “finally stop appealing every time” it lost. That is not a system with a working check; that is a system where the check exists on paper and only bites when a single, unusually persistent, well-represented litigant outlasts the government’s appetite for appeals over more than a decade. Two features of Merrill’s case map directly onto C-8’s structure, and are worth naming precisely rather than gesturing at: 1. The burden of litigating the gag falls entirely on the private party the state has conscripted, not on the state. Merrill had to find and keep counsel, stay in the case for eleven years, and absorb the personal cost — “it cut me off from the people who in normal life would be your support network,” in his words — while the government’s position cost it nothing but time. Bill C-8 replicates this asymmetry exactly: a designated operator subject to a secrecy order bears the cost, delay, and business risk of seeking judicial review to be released from it; the Minister bears no reciprocal obligation to justify continued secrecy on any fixed timetable, and no automatic sunset applies. 2. A small operator is the worst-positioned party to bear this burden, and is therefore the most likely to simply comply rather than fight. Calyx was a 200- customer ISP, not Bell or Rogers. The asymmetry between a small provider’s resources and the state’s is precisely why NSL gag orders functioned as intended for over a decade before any single one was fully broken — most recipients, reasonably, never contested them at all. C-8’s designated-operator framework nominally targets larger, federally- regulated critical-infrastructure operators, but Part 1’s telecom-security direction power (s.15.1) is not limited to large carriers, and nothing in the Act guarantees a smaller telecom or ISP swept into a direction has the resources Merrill eventually assembled, at cost, over more than a decade. Where C-8 is arguably narrower than the NSL regime, and where that narrowness is unproven: C-8 does have a five-year mandatory parliamentary review (s.17) and a notice-to-oversight- bodies requirement (NSICOP and NSIRA within 90 days) that the original NSL statute lacked — these are real, non-trivial differences, and it would be inaccurate to claim C-8 is simply “Canada’s NSL.” But notice to a parliamentary oversight committee is not the same as an independent advocate testing the order’s substance in real time, and a five-year statutory review of the whole regime is not the same as an individual recipient’s right to seek release from their specific gag order on a fixed timetable — which is the actual mechanism USA Freedom Act eventually built for NSLs (periodic FBI self-reassessment, not judicial reassessment, but at least time-bound) after Merrill’s litigation forced the issue. C-8, as enacted, does not yet have that individual, time-bound release mechanism. Until it does, or until it’s tested in court, the honest assessment is: structurally analogous to the pre-reform NSL regime, with two additional oversight features NSLs never had, and without the one feature — a fixed individual release clock — that Merrill’s decade of litigation eventually forced onto the American system. 4. Bill C-9 — Combatting Hate Act (in force July 18, 2026) Short name: The Combatting Hate Act (not primarily a telecom/internet bill — see the note on scope above). What it does: Adds a definition of “hatred” to the Criminal Code; creates a new standalone hate-crime offence (hatred as an element of the offence itself, not just a sentencing aggravating factor); creates a new hate-propaganda offence for public display of certain terrorism/hate symbols (listed-entity symbols, two specified Nazi symbols, a noose); criminalizes intimidation/obstruction of access to places of worship and similar community sites; and repeals the “good faith religious opinion” defence that previously applied to certain hate-propaganda charges. The critical read, to the extent it’s a telecom/internet-adjacent concern at all: • The symbol-display offence is framed as “public place” display, but “public” in Criminal Code jurisprudence has been read to include online public forums in analogous contexts — if that interpretation holds here, the practical enforcement surface for this particular offence does extend to social media posts, which is the one place this bill genuinely intersects your broader thesis. Everything else in C-9 is conventional criminal law reform, not platform or carrier regulation, and I’d resist folding it into the same “internet governance” bucket as the other five without flagging that distinction explicitly — a critic who conflates a hate-crime statute with a surveillance or platform- regulation statute weakens an otherwise sound argument by inviting an easy rebuttal (“this one isn’t even about the internet”). • Repeal of the religious-defence carve-out is the most substantively contested piece, on genuine 2(a)/2(b) grounds — the government’s own position is that the high “wilful promotion” threshold from R. v. Keegstra continues to do the constitutional work the specific defence used to do; critics (including faith-community submissions) argue the specific defence provided predictability that the general threshold doesn’t replicate. This is a live, good-faith legal dispute, not a fringe objection. Penalties (Criminal Code amendments): - New hate-crime offence: escalating penalty structure tied to the underlying offence — e.g., hate-motivated uttering threats carries up to 5 years on indictment . - Hate-propaganda symbol-display offence: penalties under existing s.319 structure (up to 2 years on indictment for the existing wilful-promotion offence; the new offence tracks similar exposure, per the Library of Parliament summary — exact maximum for the new symbol offence should be confirmed against the final Act text once consolidated). - Intimidation/obstruction offences: standard Criminal Code sentencing ranges apply, escalated where hate-motivated. 5. Bill C-22 — Lawful Access Act, 2026 (passed House; before the Senate) Short name: The Lawful Access Act (successor to the shelved lawful-access provisions of Bill C- 2, the Strong Borders Act ). What it does: Two parts again. Part 1 amends the Criminal Code, the CSIS Act, and the Mutual Legal Assistance in Criminal Matters Act to create new, faster mechanisms for police/CSIS to get subscriber data — including a warrantless “confirmation of service demand” compelling a telecom or electronic service provider to confirm, on reasonable suspicion alone (not probable grounds, not judicial authorization), whether it provides service to a given subscriber/account/identifier. Part 2 enacts the Supporting Authorized Access to Information Act (SAAIA) , which is the part that should draw your attention hardest: it requires certain “electronic service providers,” especially designated “core providers,” to build and maintain standing technical capability for lawful interception — i.e., legally mandated intercept-ready infrastructure, not case-by-case compliance. This is the part of the current-Parliament bills that most closely resembles Russia’s SORM system as a piece of infrastructure — see the dedicated comparison and plain- language explainer immediately below. The critical read on the rest of the bill: • Reasonable suspicion, not reasonable and probable grounds, and no judicial pre-authorization for the confirmation-of-service demand. This is a materially lower threshold than what search-and-seizure jurisprudence ( Hunter v. Southam , R. v. Spencer on subscriber-information privacy) has generally required for state access to information a person has a reasonable expectation of privacy in. The Canadian Bar Association’s own submission calls this out directly and recommends the 24-hour compliance window be extended and the up-to-one-year gag order on disclosure of the demand be cut to 90 days with court approval for extensions — Parliament has not yet accepted those recommendations. • “Electronic service provider” is defined broadly enough that it may not be limited to telecom/tech companies. Privacy counsel (David Fraser, quoted in coverage) has flagged that depending on final regulatory scoping, ordinary businesses providing any electronic service to the public in Canada could be swept in — this is a live definitional fight, not a resolved one, and the actual footprint of the Act will be set by regulation after passage, which is itself a rule-of-law concern: the operative scope of a coercive statute is being left to the executive to fill in later. • Metadata retention mandate up to one year , expanded information-sharing with foreign governments (including the U.S.), and a requirement that core providers build systems “intercept-capable” by design — cryptographers and the EFF’s position (that there is no way to build a lawful-access-only backdoor that cannot also be exploited by a hostile third party) is not a fringe view; it reflects a fairly settled technical consensus, and the 2024 Salt Typhoon compromise of U.S. carrier-side lawful-intercept infrastructure is a concrete, recent illustration of exactly that risk materializing. • Charter Statement’s own logic is thin on aggregation. The government’s s.8 defence for the confirmation-of-service demand rests on the idea that subscriber/account confirmation alone isn’t “particularly sensitive.” Spencer already rejected atomized analysis of this kind — the Court there held that subscriber information tied to online activity can reveal a biographical core of personal information precisely because it’s the key that unlocks anonymity. A bill whose Charter defence leans on the individual insensitivity of each data point, while building a system optimized for combining data points at scale, is not obviously consistent with the reasoning in the leading case on point. This particular problem gets a full treatment in its own right further down, in the third-party doctrine section — it’s the strongest doctrinal thread in this entire document. Penalties (SAAIA / Criminal Code amendments): - Confirmation-of-service demand: contravention without lawful excuse is punishable by fine. - Contravention of a production order (as opposed to a mere confirmation demand): fine, imprisonment, or both. - SAAIA creates a monetary penalty scheme for electronic service providers that fail to build/maintain mandated lawful-access technical capability (amounts to be fixed by regulation). What SORM actually is, in plain terms Before comparing C-22 to it, it’s worth explaining SORM itself, because most readers will only have heard the acronym, not what it actually does. SORM (System for Operative Investigative Activities) is Russia’s mandatory telecommunications-interception infrastructure. Since the 1990s, every Russian telecom operator and internet service provider has been legally required, at its own expense, to install a specific piece of government-specified equipment inside its own network — essentially a permanent tap built into the wiring of the network itself, not something installed after the fact when police show up with a court order. That equipment is wired directly to the FSB (Russia’s federal security service), which can activate it remotely, from its own offices, without going through the provider at all. The provider doesn’t see the request, doesn’t approve it, and — since a rule change in 2000 — isn’t even entitled to see the legal paperwork (in principle a court order is still required to exist somewhere in an FSB file, but the provider has no way to confirm it does before the tap is used). The system has expanded over three generations — SORM-1 (telephone), SORM-2 (internet traffic), SORM-3 (long-term storage of virtually all metadata and content, plus data-sharing across state agencies) — with each generation reaching further into ordinary daily communications than the last. In short: SORM is not a law about wiretapping. It is the physical and technical infrastructure that makes wiretapping something the state can do instantly, at scale, and without the provider’s knowledge or participation, on hardware the provider was forced to buy and install itself. That is the feature of SORM worth understanding before reading the comparison below — it’s an infrastructure question first, and a legal-procedure question second. SORM comparison (Bill C-22, Part 2 — SAAIA) You specifically asked for this, and it’s worth doing carefully rather than reaching for the easy rhetorical move, because there are real similarities and real, important differences. Where the comparison holds: Feature Russia’s SORM Bill C-22 Part 2 (SAAIA) Standing, built-in intercept infrastructure (not case-by- case) Yes — mandatory equipment installed in every major carrier/ISP network Yes — “core providers” must build and maintain standing technical capability Feature Russia’s SORM Bill C-22 Part 2 (SAAIA) Cost borne by provider Yes Yes (compliance cost falls on designated ESPs) Scope creeping from telephony to internet to messaging/social platforms over successive versions Yes (SORM-1 → SORM-2 → SORM-3) The bill’s own definitional breadth (“electronic service provider”) raises the same trajectory risk — regulators can widen the designated class post-enactment Metadata retention mandate Yes (Yarovaya Law, 6 months content/metadata) Yes (up to 1 year metadata) Government framing as narrowly “lawful” and targeted Yes, officially Yes, officially Where the comparison breaks down, and breaks down hard: • Who pulls the trigger. SORM’s defining, most-criticized feature is that the FSB accesses the standing infrastructure directly and remotely , with the operator having no visibility into what is being collected and no ability to confirm a warrant exists before access occurs — the equipment is maintained by FSB-linked contractors, and since 2000 the FSB isn’t even obligated to show the carrier documentation of the target before accessing data. Bill C-22, as drafted, still requires a judicial production order or warrant for the content of communications, and even the lower-threshold confirmation-of-service demand is subject to after-the-fact court challenge and a right to seek variance/revocation. The “build the pipe, but the state still needs a court order to pour anything through it” model is a materially different design from SORM’s “state has a standing, self-executing tap.” • Independent oversight exists, however imperfect. C-22 orders are reviewable by courts; the SAAIA regime is subject to Intelligence Commissioner approval for ministerial orders per the Globe and Mail’s reporting on the bill’s structure; the Privacy Commissioner has an active, public advisory role. SORM has none of this — no independent commissioner, no meaningful judicial check, and Roskomnadzor (the regulator) functions as an enforcement arm against providers who refuse to install the equipment , not as any kind of check on the state’s use of it. • Political context and use. SORM’s well-documented function, beyond ordinary crime, is domestic political surveillance — of journalists, opposition figures, and protest movements — inside an authoritarian system with no functioning separation of powers to constrain it. Canada has independent courts, a free press, and Charter litigation as live, exercised checks (as this very list of bills, several of which are being publicly challenged and amended under committee and Senate pressure, illustrates). The legal architecture of C-22 is not SORM; the technical architecture it is building — standing, built-in, carrier-side intercept capability at scale — is the same category of infrastructure, and infrastructure, once built, is agnostic to who governs next and outlives the political conditions that made its current safeguards credible. That is the honest version of the comparison: not “Canada is building SORM,” but “Canada is building the kind of intercept-capable telecom architecture that, absent the current legal and institutional constraints remaining fully intact, functions the same way SORM does at the wire level.” The infrastructure argument is the strong one; the “Canada is Russia” framing is not, and overstating it will cost the argument credibility it doesn’t need to spend. 6. Bill C-34 — Safe Social Media Act (first reading, June 10, 2026) Short name: The Safe Social Media Act / Digital Safety Act (successor in spirit, not text, to the abandoned 2024 Online Harms Act, C-63). What it does: Enacts two new statutes — the Digital Safety Act (substantive duties) and the Digital Safety Commission of Canada Act (a new standalone regulator, the “Commission”). Applies to three tiers: social media services, AI chatbot services, and “online services” (only if Cabinet decides they pose significant risk of harm to children). Headline feature is a prohibition on social media accounts for under-16s, backed by mandated age verification; also imposes content-moderation duties targeting seven categories of harmful content (CSAM, non- consensual intimate images, terrorism/extremism content, etc.), AI-chatbot-specific duties (crisis-intervention obligations, a ban on chatbots impersonating humans), and mandatory “digital safety plans” filed with and enforced by the new Commission. The critical read: • It is at first reading only — meaning this is the least legally settled of the six, and the one where your critique has the most room to actually shape the outcome if you engage now, during consultation, rather than after enactment. • Age verification is the load-bearing mechanism, and the bill doesn’t specify how it works. Any technically credible age-verification regime requires either (a) government or third-party identity verification tied to an account, or (b) biometric estimation. Both create a new, centralized or quasi-centralized record of who is (and, by implication, who is not) a minor using a given platform — a data set with obvious value to anyone wanting to de-anonymize or profile users, and one this bill leaves entirely to future regulation to define, with no statutory floor on data minimization, retention limits, or a prohibition on secondary use. • The “online service” category is elastic by design. It only regulates a service if the Commission is satisfied it poses “significant risk of harm to children” — a standard with no fixed content, decided case-by-case by the regulator itself, which is precisely the kind of open-ended, discretionary trigger that makes it hard for an operator (or a citizen) to know in advance whether a given forum, wiki, or niche platform is caught. • AI chatbot duties are a genuine legislative first for Canada — “crisis intervention requirements” imposed on a chatbot operator raise an unresolved question: what liability attaches when an automated crisis-intervention duty is triggered incorrectly, or not triggered when it should have been, and how does that duty interact with the operator’s Criminal Code mandatory-reporting obligations under the separate internet- child-exploitation-reporting statute the bill repeatedly cross-references? These interactions are not resolved in the bill text as introduced. • The regulator