Skip to content

This article features deals sourced directly by Gizmodo and produced independently of the editorial team. We may earn a commission when you buy through links on the site.

Deals

This Toronto Privacy Tool Has 20 Million Users: Bill C-22 Could Push It Out of Canada

Psiphon, a Toronto-built anti-censorship tool with about 20 million monthly users, says it has started planning a move out of Canada because of Bill C-22, the federal lawful access bill now before the Senate.
By

Reading time 3 minutes

The bill is not law yet, and the government disputes how its critics read it. But for Canadians who rely on privacy software, the list of services weighing an exit keeps growing.

What Psiphon Said, and Why Open Source Is the Problem

Psiphon started in 2006 as a project of the Citizen Lab at the University of Toronto. Many of its users live in countries such as Iran, Russia and China. The company publishes all of its code, and that is the root of its objection.

Vice president Kenzie Elsworthy told The Globe and Mail that a law enforcement access point cannot be hidden inside software anyone can read. “That is not lawful access. It is a published vulnerability,” she said. Psiphon says it would rather stay, but would relocate if the bill passes unchanged.

What Bill C-22 Would Actually Require

Bill C-22, the Lawful Access Act, 2026, was introduced on March 12 and passed the House of Commons on June 18. Its first half updates how police and the Canadian Security Intelligence Service obtain subscriber information during investigations.

The second half creates a framework under which “electronic service providers” can be required to build and maintain the technical means to hand over information when authorities hold legal authorization. The definition is broad enough to reach messaging apps, cloud services and VPNs. Which companies will carry the heaviest duties is left to be settled after the bill passes.

What Ottawa Changed, and What It Says

Before the House vote, the government amended the text. The version sent to the Senate adds explicit protection for end-to-end encryption and cuts the maximum metadata retention period from one year to six months.

Ottawa has also rejected the claim that the bill forces companies to build backdoors, and argues that Canada lags its Five Eyes allies without these powers. Critics answer that the safeguards do not go far enough. The Senate can still amend the text.

Why 23 Companies Are Still Asking for a Fix

On September 24, 23 companies and organizations, including Nord Security, the company behind NordVPN, signed a joint letter asking the public safety and industry ministers to fix the bill before it becomes law. Signal has said it would pull out of Canada before it would weaken its privacy promises.

NordVPN said in May that it would consider limiting or removing its presence in Canadian jurisdiction, and that there is no scenario in which it would compromise its no-logs architecture or encryption. None of these exits has happened. They all depend on the final text.

See the NordVPN Offer

Where a VPN Actually Fits, and Where It Doesn’t

A VPN encrypts the traffic between your device and the VPN server and hides your IP address from the sites you visit. In practice, your internet provider sees that you are connected to a VPN, not which sites you open.

It does not make you invisible to the law. A VPN does not stop a court-authorized order served on your internet provider for your name and address. It does not hide what you do inside an account you are logged into. It cannot change what a service already stores about you.

And if C-22’s obligations end up applying to VPN providers themselves, the protection depends on what the provider actually holds and on where it is based. That is why logging policy and jurisdiction matter more than speed tests when you compare the best VPN services.

Where NordVPN Fits

NordVPN is headquartered outside Canada and runs under a no-logs policy, so it does not keep records of the sites you visit. Our NordVPN review covers how that policy has been independently audited. Its NordLynx protocol, built on WireGuard, is included in every plan.

Threat Protection Pro, which blocks phishing pages, trackers and malicious domains, and Dark Web Monitor, which alerts you if your credentials show up in criminal dumps, come with the Advanced and Ultra plans, not Basic.

If the bill passes as written, NordVPN has said its response would be to change its footprint in Canada, not its logging. Whether its Canadian servers stay available is an open question.

NordVPN Basic at $3.49 per Month

The NordVPN Basic plan costs $3.49 per month on the two-year offer, billed as $94.23 for 27 months (24 months plus 3 free), a 69% discount.

The checkout will suggest Advanced or Ultra. You only need them if you want Threat Protection Pro or Dark Web Monitor. After the first term, the plan renews at $139.08 per year, so set a reminder. There is a 30-day money-back guarantee, with refunds requested through 24/7 chat support and returned within 5 to 10 business days.

Start a 30-Day Risk-Free Trial

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.