So the legislation specifically excludes 'personal' content, and doesn't require direct paths to data / back doors for law enforcement. This is doomerism hyperbole.
It requires that companies store meta data for a year, so that it can get accessed by law enforcement, and it establishes that law enforcement can ask if 'so and so' is a customer of tech companies, so that law enforcement can then go get a warrant from a judge to access details about that customer. In storing that metadata, the legislation says the specific requirements of what metadata to store would be decided by regulators of industries.
In terms of privacy protection, requiring companies to keep meta data log files isn't a bad thing in itself. Consider a 'log less' service where you've provided some details to get an account going -- or even something you pay for, like a VPN service, which has some payment info from you. If they got hacked, and all your payment data was taken, then your credit cards are exposed and there's a real/material risk of harm to you.... but they didn't keep any logs of any of the hacking event because they're a 'log less' company... do they even know if they got hacked? Can anyone prove they got hacked? Is there any evidence trail available leading to those hackers / tying them to the breach? I've heard guys working in fintechs say "Why would we keep logs -- they're just evidence for when we screw up". Arguably, by not monitoring for this sort of thing / tracking meta data, you expose customers to greater risks, because you are not monitoring who's accessing the personal data -- so anyone could be accessing it, even now.
Especially in the case of foreign services, with laws in foreign jurisdictions that establish their governments can look at whatever they want, even beyond the meta data, without the company being able to disclose that to others (side note, c-22 seems to put a limit of 1 year on muzzling disclosures -- so a privacy oriented company could automate the transparency and inform customers of both requests for their personal metadata, as well as provide an aggregate report of 'last years' requests from govt). But in terms of clandestine/outside legal purview stuff, consider the stuff being done in the states with DHS/Ice, and the Patriot Act. Even if that foreign service, which routes all your messages, is mirroring your messages off to a law enforcement portal for someone like the CIA -- they don't have to log themselves doing it, and would have no obligation to tell you they're doing it, and if you tried to ask for the meta data about how your messages are routed, or who'd accessed your account, they could fall back on the logless setup as an excuse for having nothing to show you.
Getting back to that first case, with the specific companies and logs -- a semi important note is that right now, there aren't really set requirements/standards for how log files are handled by companies. So a company can set a retention period for their granular logs at like 7 days or whatever they want. And most likely everyone understands that retaining log data costs money for storage devices, and that companies often aim for the cheapest options they can get away with. So even if ppl are trying to blast headlines about specific 'log less' services that are saying they may leave, they should also be thinking about "How long would a company like Telus, Bell and/or Rogers willingly pay to store log information for the purposes of investigations / tracking crimes being committed using their services? How about banks, doctors offices, and other critical service providers that hold tons of our personal information?". Same with general ISPs. Like if some ISP is hosting a kiddie porn site, yeah, I think the cops should be allowed to demand at least 1 year worth of meta data to see who connected to that kiddie porn site. That seems reasonable to me, especially if the main (non-meta) data is still behind a warrant/judicial review.