The secure messaging service Signal, which uses end-to-end encryption to protect the communications of millions of people globally each day, says government amendments to its lawful access bill are insufficient to persuade it not to withdraw from Canada.

Udbhav Tiwari, Signal vice-president of strategy and global affairs, said amendments introduced by Public Safety Minister Gary Anandasangaree to Bill C-22 do not go far enough to safeguard encryption or protect users’ privacy.

The tech company, whose users include politicians, journalists and dissidents around the world, told The Globe and Mail in May that it would withdraw from Canada if asked to compromise its users’ privacy under the bill’s new powers.

In June, Mr. Anandasangaree introduced a number of changes to the bill, in response to criticism from tech companies, lawyers and civil liberties advocates. One amendment made it clear that a company that does not have a key to encryption would not have to decrypt information it holds.

Mr. Tiwari said that the amendments did not go far enough to address Signal’s concerns. He was speaking Monday on a panel in Ottawa hosted by the Canadian arm of the Internet Society, a global charity that advocates for a secure and open internet.

“It’s vital that the idea of encryption in the law is expanded well beyond just decrypting things with a key, because that is a very nano construction of what encryption is,” he said.

He warned that as currently worded, encryption could still be compromised or undermined by powers in the bill, which is now in the Senate.

The lawful access bill would require internet companies and other electronic service providers to make changes to their systems to give surveillance capabilities to police and the Canadian Security Intelligence Service to combat threats and criminal activity. It would give the government new powers to force them to retain metadata on their customers.

The metadata would not include e-mails, web-browsing history, social-media activity or text messages, but it could include information about which telephone numbers have been in touch with each other, and data allowing someone’s location to be pinpointed.

Although Signal would not be forced to share with the Canadian government keys used to encrypt messages, it could be asked to make serious changes to its software “that negates the very purpose of encryption itself – and that is something that is a very strong red line,” he said.

As currently worded the bill allows ministerial orders to be issued “that can be ruinous for encryption and privacy for all Canadians,” he added.

An amendment introduced by Mr. Anandasangaree in June, in response to concerns from tech companies, reduced the time that metadata would have to be retained from up to a year to six months.

But Mr. Tiwari said having to store any metadata on its users posed a serious problem for the encrypted messaging app.

Signal, which is a non-profit, runs on its own centralized servers. The only user data it stores are phone numbers, users’ last login information and the date they joined the service. Users’ contacts, chats and other information are stored by users themselves, on their phones.

If, under Canada’s lawful access law, it is ordered to start collecting more metadata about its users and store it for up to six months, so government and law enforcement can request it, it would have no choice but to withdraw from Canada to protect their privacy, he said.

“For us this is a serious enough issue that it would fundamentally break Signal,” he said.

Faced with a choice of maintaining end-to-end encryption or “creating a much weaker version of our product that collects all of this metadata, the choice for us, unfortunately, would be starkly clear: we will not make changes to our product – which is open source and available for anyone to verify – to comply with such demands that place the privacy of not just Canadians but everyone else in the world at risk,” Mr. Tiwari said.

Simon Lafortune, a spokesperson for Mr. Anandasangaree, said “the legislation explicitly states that it does not require the decryption of end-to-end encrypted information and does not permit or compel companies to introduce systemic vulnerabilities or so-called ‘backdoors’.”

He added, in a statement, that it takes concerns raised by stakeholders seriously and remains open to further amendments in the Senate “that strengthen the bill’s protections while preserving its objectives.”

Representatives of the non-profit behind Firefox, the open-source web browser, said on Monday it also had serious concerns about the bill, despite the minister’s amendments.

At the Canadian Internet Society event, Christian Sadilek, senior principal software engineer at Mozilla, said the amended bill could force companies to introduce weaknesses into their systems.

Weaknesses, he said, can be rapidly exploited using AI, “which can autonomously scan vulnerabilities, detect them, and find ways to break in.”

It would not be possible for Mozilla, an open-source product, to abide by an order to introduce “any secret capability without losing the trust of our community, trust of our users – and that would just be a terrible outcome,” Mr. Sadilek said.

The requirement to collect all kinds of metadata could reveal “almost every detail about a user” including their location, hobbies, their religion and “what diseases they are struggling with,” he warned.