We Signed a Letter Agreeing With Nord and ExpressVPN

Curtis Chanders

September 24, 2026

We Signed a Letter Agreeing With Nord and ExpressVPN

If you've followed VPN drama for more than five minutes, you know the usual vibe. We roast each other's marketing, argue about jurisdictions, and generally refuse to share a group chat. So this is weird, in a good way.

Today, Windscribe joined 22 other companies and organizations in signing a joint letter asking Canada's Public Safety and Industry ministers to fix Bill C-22 before it becomes law. The list includes Nord Security, Kape Technologies (ExpressVPN, Private Internet Access), Tailscale, Tucows, Coinbase Canada, Tuta, easyDNS, and more. You can read the whole thing at fixc22.ca.

When companies that compete on everything show up on the same letter about the same bill, that should set off some alarm bells.

What is Bill C-22?

Bill C-22, formally the Lawful Access Act, was introduced on March 12 2026. "Debated" is a strong word for what happened next. The government passed a motion cutting off committee study, and the bill cleared the House on June 18, the day Parliament left for summer break. It's now in the Senate but it hasn't become law yet, which means there is still time to fix it.

Canada has a long-running hobby of trying this. Bill C-30 died in 2012 after a huge backlash, helped by the government's charming suggestion that opponents sided with child predators. C-13 in 2014 and C-51 in 2015 pushed further, and the same powers appeared in last year's Strong Borders Act before returning as C-22. The pattern never changes. Serious crimes are invoked, powers are drafted broadly, and everyone acts shocked when broad powers get used broadly.

What it actually does

The bill covers any "electronic service provider" serving people in Canada or doing business here, and an "electronic service" is anything involving creating, recording, storing, processing, transmitting, receiving, or making available electronic information. Your homework assignment is to name a single thing you can do on the internet that doesn't involve at least one of those.

From there, regulations can require "core providers" to build access capabilities, install equipment, and retain categories of user metadata for up to six months. The Minister of Public Safety can also issue secret orders imposing the same obligations on any provider, core or not (which is most businesses), for up to two years. The order expires, but the secrecy doesn't. You can't disclose to users that the order exists, what it says, or even that you pushed back on it. Ever.

"But it was amended!"

It was, and credit where due. The retention cap was cut from one year to six months. Content, browsing history, and social media activity can't be required, orders now need Intelligence Commissioner approval, and nobody can be forced to build a "systemic vulnerability" or to decrypt what they can't decrypt.

But governments don't amend bills to fix problems they insist don't exist. The C-22 amendments that passed are good, but they are not nearly enough.

Metadata is not harmless

If you're sending a letter, metadata is the outside of the envelope. It shows who the mail is from, who it's addressed to, when it was sent, and from which post office. The letter inside is the data which stays private. Governments love pointing this out, as if it settles something. But collect six months of everyone's envelopes and you don't need the letters.

The envelopes say you called a crisis line at 3 AM and stayed on for forty minutes. They say you contacted an oncologist on a Tuesday and your whole family that evening. They say which addiction helpline you call every Thursday, where your phone sleeps at night, and that a reporter and a government employee were both online through the same privacy tools at 2 AM, the week before a leak broke. Michael Hayden, a man who ran both the NSA and the CIA put it more plainly (and grimly) than we ever could. "We kill people based on metadata."

If that data exists, it can be demanded, mishandled, or hacked. The best database breach is the one that never happens because the database never existed.

Canada is not the first

Australia sold metadata retention as a serious-crimes tool. A parliamentary review later found more than 80 non-designated bodies accessing the data, including local councils, regulators, and even the RSPCA (an animal welfare organization).

In the UK, a secret government demand for encrypted iCloud access made Apple pull Advanced Data Protection from British users in February 2025. The demand was dropped, then reissued in narrower form, and eighteen months later the feature still isn't back.

And this past July, the EU revived "Chat Control" and legalized the scanning of private messages until 2028. More MEPs actually voted against it than for it, but a procedural quirk meant opponents needed an absolute majority, and they fell 47 votes short. The permanent version, the one that could reach further, is back at the negotiating table this month.

The lesson from places that passed laws like C-22 is clear - you cannot give access to private messages and identifying metadata only to the good guys.

Why Windscribe is hit differently

Signal has already said it would leave Canada rather than comply, and most companies on this letter could pull the same lever and simply turn off Canada from a dashboard. Awful for Canadians, but survivable for them.

We can't.

Canada is our legal home, and escaping this framework would mean moving the entire company to another jurisdiction. As our CEO Yegor put it, "Bill C-22 makes Canada an untenable place for most tech companies to operate in, foreign and domestic. It is in direct conflict with attracting the capital Canada claims to want, and literally forces existing Canadian companies to take their taxable revenue elsewhere."

The MPs who want this bill passed should be embarrassed that a Canadian privacy company might have to leave Canada to protect Canadians' privacy.

There is still time

The Senate is studying Bill C-22 right now, and senators can give it the scrutiny the House cut short. The ask, from us and 22 other companies, is simple. Fight cybercrime, keep encryption intact, but don't force companies to store data they don't need. Don't invent secret powers with undefined targets.

Law enforcement should have real tools to fight crime, and nobody signing this letter says otherwise. But privacy, encryption, and cybersecurity are the safety rails of modern life, and this bill treats them like annoying obstacles to be routed around. Your bank account, medical portal, password manager, work messages, and family photos all depend on systems that cannot quietly become weaker because a minister ordered it.

Wanting privacy is not a radical opinion, it is a basic human instinct. You close your curtains at night not because you're hiding criminal activity, but because you don't want everyone looking at the things you do in private.

Read the letter at fixc22.ca, then tell your senators and your MP to fix this bill. Because if Parliament gets it wrong, the final days of your private life will arrive quietly, as a compliance requirement, a retention policy, a secret order, and a database someone promised would be secure.

Keep your browsing private and secure by masking your IP address.
Get Windscribe