Open this photo in gallery:

Gabriel Weinberg, the founder and CEO of DuckDuckGo, speaks before the U.S. Senate Judiciary Committee in Washington in a 2019 file photo.Alex Wong/Getty Images

U.S. search engine DuckDuckGo says it is prepared to withdraw one of its key security services from Canada over the government’s lawful-access bill, because the proposed law would conflict with the company’s policy of not tracking its users.

DuckDuckGo’s chief executive, Gabriel Weinberg, told The Globe and Mail that the company will withdraw its VPN service from Canada if Bill C-22 becomes law.

A VPN, or virtual private network, encrypts a user’s internet traffic and can disguise from where they are connecting to the internet.

DuckDuckGo would continue to offer Canadians access to its search engine, which it markets as a more secure alternative to its mainstream competitors because it does not track its users’ browsing or search histories.

But the tech company is planning to review the lawful-access legislation, including to assess if it could potentially capture browsers and other internet infrastructure.

Bill C-22, which is now being examined in a Commons committee, would require “electronic service providers” in Canada to adjust their systems to give surveillance and monitoring capabilities to police services and the Canadian Security Intelligence Service.

CSIS and law enforcement have long argued that Canada is lagging behind its Five Eyes intelligence partners in not having such a lawful-access regime to aid investigations.

Ottawa plans amendments to lawful-access bill amid backlash

Public Safety Minister Gary Anandasangaree told reporters Wednesday that the government is preparing amendments to the bill in order to address the concerns of critics, but he suggested that Ottawa would not budge on a requirement that tech companies retain metadata on their customers for up to a year.

Commenting the day after Mr. Anandasangaree’s remarks, Mr. Weinberg highlighted metadata retention as a concern for DuckDuckGo.

“C-22’s security backdoors and metadata retention requirements conflict with DuckDuckGo’s privacy policy, which states simply that we don’t track you,” he said in a statement. “If the bill passes, we will be forced to stop offering our VPN in Canada.”

DuckDuckGo is the latest of several major tech companies to warn that it will withdraw from Canada over the bill.

Secure messaging service Signal, which uses end-to-end encryption, told The Globe that it would withdraw from Canada if asked to compromise its users’ privacy under Bill C-22.

Signal warns it would pull out of Canada if made to comply with lawful-access bill

Yegor Sak, chief executive of Toronto-based security company Windscribe, told The Globe that his company has started looking at moving to another country because of Bill C-22. Among other privacy tools, Windscribe offers a VPN service.

Tailscale, a Toronto tech company that offers a VPN service for corporate clientele, also has concerns about the bill and wants it scaled back.

The company says the bill needs amendments, including limits on metadata retention and explicit protection for encryption.

In an interview, Avery Pennarun, CEO and co-founder of Tailscale, said he is concerned that the bill’s lawful-access provisions could mean his security company could be asked to plug a device or add a piece of software into Tailscale’s own software.

“Security is only as strong as the weakest link,” he said. “It’s very likely that the thing they mandate that we plug in is not going to be made by people who care about security. It’s going to be made by people who care about ability to access private information. Every time that’s happened in the past, it’s been a huge problem.”

Conservative MPs have complained that the government is not giving enough time to consider the complex bill or hear from witnesses in the committee.

Jean-Yves Duclos, chair of the Commons public safety committee, said Thursday that more time would be given to MPs to suggest amendments, and to hear from experts.

At the committee on Thursday, Mr. Anandasangaree said that through the committee process “we will address and strengthen the legislation that’s in front of you to ensure that we have a lawful-access framework that works for law enforcement,” and protects privacy, without creating “a backdoor” to access people’s data.

Mr. Anandasangaree reiterated his willingness to consider making changes to the bill “that strengthen encryption.”

“Encryption should not be compromised under any circumstances,” he said.

Open this photo in gallery:

Public Safety Minister Gary Anandasangaree.Sean Kilpatrick/The Canadian Press

Bryan Larkin, the RCMP’s Senior Deputy Commissioner, told MPs on the committee, “We’re not asking for any unchecked police powers.”

“What we’re asking for is good governance, good democracy and judicially authorized ability to investigate,” he said, adding that “technology is changing at a greater rate than we can keep up with legislative reform.”

“We have significant national-security investigations, we have significant serious organized-crime investigations where encryption is at the heart of stymying the prosecution and quite frankly the undercurrent of solving those crimes,” he said.

Bill C-22 could also force electronic service providers – such as phone companies, messaging apps and tech companies – to retain metadata relating to their customers’ activities for up to a year.

The metadata would not include e-mails, web browsing history, social-media activity or text messages, but it could include information about which telephone numbers have been in touch with each other, and data allowing someone’s location to be pinpointed.

Cybersecurity and tech experts have warned that storing so much metadata could create an enticing target for hackers, including those acting on behalf of malevolent foreign regimes.

Asked by Conservative Rhonda Kirkland if a mechanism created for lawful access, to enable interception, could potentially be discovered or exploited for unauthorized use, Ramzi Nashef, director-general for policy, planning and accountability at CSIS, replied, “There’s no technical system by any means that is 100-per-cent foolproof by any stretch.”

But he added, “You have a group of people whose fundamental ethos is to protect Canadians, Canadian systems and the critical infrastructure.”

Bill C-22 says that electronic service providers would not need to make changes that could create a systemic vulnerability in a system.

But Matt Hatfield, executive director of OpenMedia, a non-profit that advocates for inexpensive and surveillance-free internet access, said he was not reassured by the minister’s recent statements.

“So long as this legislation allows the government to install devices in a vast number of services that can intercept both encrypted and non-encrypted data, it will pose an existential threat to Canadian privacy,” he said in an e-mail.