The Real Risk in Bill C-22 Isn't Government Overreach, It's Who Already Holds the Keys
Brad Redekopp,
Your reply to Bill C-22 focused on stopping the government from turning private companies into an unchecked surveillance arm of the state. That risk is real, and worth guarding against. But it isn't the risk I'm raising here. The infrastructure carrying police records is already effectively controlled from outside Canada, by a foreign government, not through some future overreach, but through the ordinary hosting arrangements Ottawa has already chosen. That's not a 1984 scenario you need to prevent, its the current architecture.
Using public domain and network records, I confirmed that rcmp.ca, the RCMP's public website, is hosted directly on Microsoft Azure, with no Canadian company anywhere in that chain. Shared Services
Canada's own domain, ssc-spc.gc.ca, routes mail through Microsoft 365 and Exchange Online. The RCMP's own domain, rcmp-grc.gc.ca, keeps a mail server in Ottawa, but its SPF record explicitly authorizes Microsoft 365 and Exchange Online Protection to send mail on its behalf. Microsoft is part of the RCMP's mail system, confirmed in the domain's own records, not inferred.
None of this required any special access or a security flaw. I used standard, publicly available tools, WHOIS lookups, DNS queries, and IP registration records, to confirm all of it. These records are public by design; the internet only functions because network operators can look up who owns an address block and where traffic and mail should route. I am not raising this because the information is exposed. I am raising it because what that public information shows is a US company sitting directly in the operational path of federal law enforcement systems.
This is the risk C-22 does not account for. Part 1 assumes police can reliably retrieve records, but that assumption now rests on infrastructure owned by a US company, while Canada and the US are in an active trade dispute, or as Prime Minister Carney himself put it, a war. If the US restricted that access through the CLOUD Act, sanctions, or political pressure, records could become unreachable, not through an attack, but through a decision made in another country. That is not abstract: in 2025, the International Criminal Court's chief prosecutor lost access to his own Microsoft email after a US executive order sanctioned him, not through a hack, through the ordinary reach of US law over a US company. It happened to an institution on EU soil and drew formal questions in the European Parliament. A missing record here could mean someone with a history involving children is not flagged, or intelligence on a planned attack does not reach the right desk in time.
I am not asking you to oppose lawful access, and I am not suggesting any of this should be hidden. It cannot be, and should not be. This is not a request for your opinion. RCMP and SSC systems handling police records must run on Canadian owned infrastructure, with backups on Canadian servers, so none of this is reachable under the CLOUD Act. I expect you to press for public confirmation of exactly which companies host this infrastructure now, and to push for legislation requiring Canadian ownership and control of systems this critical to public safety.
One more thing. Your own office email, on parl.gc.ca, is filtered through Cisco and authorizes Amazon, NGP VAN, and SMTP.com, three more US companies, to send mail on Parliament's behalf. This is not hypothetical. It already reaches your own office.
I expect a response on what actions you will be taking, not an explanation about it being difficult.
Reann Legge
I use the pronouns she/her
reannlegge.ca