Contributions Program projects underway
On July 13, 2026, the Office of the Privacy Commissioner of Canada (OPC) announced funding for a new round of independent research and knowledge translation projects funded under its Contributions Program. The OPC will post a summary of completed projects, as well as links to their outcomes, once the projects are completed and reviewed by the OPC.
2026-27 Contributions Program funding recipients
Organization: The Canadian Shield Institute for Public Policy
Project title: Privacy Protection from Exploitative Algorithmic Pricing in Online Games
Amount requested: $54,172.30
Project leader: Vass Bednar
Project team: Erin Coakley, Kaylie Tiessen, Emily Osborne
Project summary:
Algorithmic pricing in gaming analyzes a player’s volunteered and inferred personal information and behavioural data to estimate how willing they are to pay for in-game micro-transactions. Different ‘offers’ are then made based on this analysis. Algorithmic pricing is enabled thanks to gaming software companies that promise to deliver deals suited to each player’s unique “gaming style”, or in other words, to find the maximum price any player is likely to spend.
Broadly speaking, algorithmic pricing is harmful: it is powered by invasive forms of surveillance that exploit consumers. There are many harms that are specific to its application in the gaming context. For one, online games often have a higher number of child consumers. Children are not necessarily able to make the distinction between in-game points as a currency proxy and real money and therefore may be posed to open themselves or their parents up to financial losses. Algorithmic pricing also compounds the harms of gambling-like features in online games—like loot boxes which we know are especially harmful for children—by enabling game producers to make them more inciting.
This project proposes conducting extensive research and analysis and proposing policy recommendations that strengthen privacy protections against algorithmic pricing in online games.
Expected project deliverables are an engaging research report with policy recommendations and findings will be disseminated through the organization’s newsletters, op-eds and other media, and through panel discussions with other experts.
Organization: The Samuelson-Glushko Canadian Internet Policy and Public Interest Clinic (CIPPIC) at the University of Ottawa
Project title: Leveling the Playing Field: The Privacy Implications of Kernel-Level Anti-Cheat Surveillance in the Canadian Gaming Market
Amount requested: $48,702.50
Project leader: David Fewer
Project team: Melissa Dupuis-Crane, Gareth Spanglett
Project summary:
Modern multiplayer gaming relies on “anti-cheat” software to ensure fair play. However, a growing number of the most popular titles in Canada—including Valorant, Call of Duty, Apex Legends—require users to install “kernel-level” drivers (Ring 0 access) that operate with the highest possible privileges on a user’s computer. Unlike traditional software, these tools often run at system boot, operate in the background even when the game is closed, and possess unrestricted access to every file, keystroke, and process on the machine.
This project seeks to unpack the privacy implications of this “rootkit-style” surveillance by examining: (1) the technical reality of kernel-level access versus the vague disclosures found in consumer consent mechanisms and deeper within their privacy stacks, (2) the coercive nature of “consent” when such invasive tools are a mandatory condition of play, and (3) the security vulnerabilities introduced by granting third-party gaming vendors deep system access.
To ensure this research benefits Canadian gamers, parents, and policymakers, the project will produce (1) a public-facing web resource and infographic clearly explaining what kernel-level access is, which popular games use it, and the privacy trade-offs involved. (2) A specific plain-language guide for parents explaining the software installed on their children’s computers and the data implications of these tools. (3) A detailed report recommending guidance for the regulation of anti-cheat software, specifically addressing the need for transparency, data minimization, and meaningful consent in the context of invasive “Ring 0” applications. (4) Lastly a downloadable chart comparing the ToS/data policies and technical access levels of the most commonly used anti-cheat engines.
Organization: Western University
Project title: That AI-Generated Character? Maybe NOT Your Best Friend!
Amount requested: $59,825
Project leaders: Jacquelyn Burkell and Dominique Kelly
Project summary:
Non-player characters (NPCs) have long populated the online gaming environment. Historically, interactions with these characters have been specified by pre-scripted dialogue trees, resulting in rigid and predictable NPC behaviour. However, with the advent of generative AI technologies like large language models (LLMs), NPCs now have the potential to respond to player inputs in a dynamic and lifelike manner. Heralded as ‘the future’ of the gaming industry emotionally expressive NPCs that converse with players in natural language are just beginning to appear in full games. As applications of AI-generated NPCs grow, their anthropomorphic features will make interactions highly engaging (prompting unconscious social responses from players and driving the disclosure of personal information).
By interacting with AI-generated NPCs as if they are ‘real,’ players are at risk of both sharing more information than they intend and having that same information deployed to manipulate player attitudes, decisions, and behaviours to the benefit of platform providers, for example in the forms of future data disclosure and purchasing decisions – powerfully undermining their privacy and autonomy.
The goal of this project is to support players, educators, and policymakers to respond effectively to the privacy challenges posed by AI-generated NPCs.
To meet this goal, we will: (1) review the ‘state of play’ with respect to AI-generated NPCs, focusing on gaming industry and player perspectives on the associated applications, goals, risks, and benefits; (2) summarize the academic literature that examines how NPCs might be designed or might behave in order to influence player behaviour, and the corresponding privacy implications; and, (3) critically assess the efficacy of educational and regulatory responses to minimize the privacy impact of interacting with AI-generated NPCs. The results will be mobilized to players, educators, policymakers, researchers, and the public through workshops, educational modules, academic presentations, a peer-reviewed publication, a final report, and public outreach.
Organization: University of Toronto
Project title: Turning the Privacy Gaze on the Use of Eye tracking in Online Gaming
Amount requested: $33,934
Project leader: Evan Light
Project team: Jennifer Ryan, Thanujeni Pathman, Tamir Israel
Project summary:
Moving out of science labs and into our personal lives through online gaming devices, eyetracking technology brings new opportunities and very real concerns about data privacy. In science and academia, eyetracking has been used for decades to advance our understanding of cognition and the brain. Government agencies have explored whether eyetracking would be a viable new method to detect deception—a next-generation polygraph. In industry, eyetracking technology has been used to gain an edge in advertising, to promote safety in long-haul truck drivers, and to enable communication for those who cannot speak or write. More recently, large technology companies including Meta, Apple, Lumen, Microsoft, Sony, and Google have acquired eyetracking companies and startups, and have received or submitted patent applications that outline new eyetracking technology, including eyetracking embedded in VR headsets, phones, tablets, and/or computers for the purposes of response selection, innovative storytelling, and/or facilitation of multiplayer experiences during online gaming. As eyetracking becomes increasingly embedded within such gaming environments, the public should be aware of the very real privacy concerns regarding the sharing of their eye movement data, and of who is reading that data.
Our eye movements can reveal the inner workings of our thought processes—they show our preferences, what we pay attention to when making decisions, and what we remember, even when we try to hide our thoughts or are not even consciously aware of them. They can reveal whether we are a child or an older adult. Eye movements can reveal impending or current mental and brain health concerns such as depression, autism, and neurodegenerative conditions such as Alzheimer’s disease. Research also increasingly suggests that eye movements may be uniquely identifying much like our fingerprints, no two people likely share the same viewing patterns. In Canada, however, there is no regulation surrounding the collection and use of eyetracking data, including in gaming contexts. This year-long project will critically examine privacy regarding eyetracking data collection and will result in a research report, jurisdictional scan, webinar with leaders from government, industry, and not-for-profit sectors, and policy recommendations. Researchers will also develop an educational toolkit for parents, children and gamers of all ages.
Organization: Fédération québécoise de sports électroniques (FQSE)
Project title: Protecting the privacy of young Canadian players: Awareness and education on data protection issues in electronic sports
Amount requested: $16,155
Project leader: Anouck Théorêt
Project team: François Savard, Gabriel Cadieux, Elsa Brais-Dussault, Maude Bonenfant, Thomas Burelli, Michael Daudignon, Yanis Ahmim
Project summary:
The project proposed by the Fédération québécoise des sports électroniques (FQSE), in collaboration with Esport Canada, aims to carry out a program to raise awareness, disseminate information and co-create a study on privacy protection in the esports ecosystem and online games.
Esports expose players, often minors or young adults, to many risks related to data collection through online games, tournament platforms, anti-cheating systems, streaming platforms, chat platforms such as Discord, team contracts and payment systems.
The project will analyze these risks on major platforms in order to identify the main problems and propose practical recommendations. Researchers will conduct 20 semi-structured interviews (with players, parents, educators and coaches) as well as a national survey with at least 200 participants. Based on these results, they will develop practical recommendations and produce a research report, a bilingual privacy guide, two webinars, a public awareness campaign and a final report. The project’s findings will also serve as a basis for recommendations related to Safe Esports, with privacy being a first layer of protection for participants.
Organization: Digital Moment
Project title: Achievement Unlocked: A National Applied Privacy Literacy Intervention in Online Gaming Ecosystems
Amount requested: $97,500
Project leader: German Arcila
Project summary:
While Canadian youth are deeply embedded in online gaming ecosystems (multiplayer, free-to-play, and streaming), most digital safety education focuses on cyberbullying rather than data privacy. This project addresses a critical gap by mapping federal privacy principles (PIPEDA) to commercial gaming practices. It moves beyond general safety to provide a targeted, measurable intervention that strengthens youth understanding of meaningful consent, data minimization, and organizational obligations. The intended goal is to increase awareness and understanding of privacy rights and obligations in the gaming sphere by implementing a structured privacy literacy program for grades 6-12 across 1,100 schools.
Researchers will map gaming data practices to principles under PIPEDA including meaningful consent, safeguards, transparency, accountability and data minimizations. They will then measure youth understanding of commercial data practices in gaming environments. Finally, they will translate the privacy principles into structured, bilingual classroom learning delivered nationally through the Digital Moment platform, reaching approximately 15,000 unique students and up to 500 educators nationally. Researchers will analyze anonymized aggregate participation data to identify patterns, trends and disparities in privacy literacy across age groups and regions.
Findings will be shared through a national privacy literacy report, a webinar presentation to educators and stakeholders and distributed through Digital Moment and ChatterHigh’s respective educator networks.
Organization: MediaSmarts/HabiloMédias
Project title: Achievement Unlocked? Young Canadians’ Privacy and Consent in Online Gaming
Amount requested: $94,481.20
Project leader: Kathryn Ann Hill
Project team: Julia Ladouceur, Kara Brisson-Boivin, Khadija Baig, Vanessa Turyatunga, Matthew Johnson, Sarah Tate, Marc Alexandre Ladouceur, Tricia Grant, Melinda Theriault, Penny Warne
Project summary:
Achievement Unlocked? Young Canadians’ Privacy and Consent in Online Gaming is a mixed methods research project that will examine how youth aged 9–18 and their parents/caregivers understand, experience, and navigate privacy and consent within online gaming environments. Led by MediaSmarts, the project will include interactive focus groups with youth ages 9-18, as well as a national survey of parents/caregivers of children aged 9–18. This project will explore how interactive gaming design challenges traditional privacy frameworks, assess the clarity and accessibility of privacy policies and terms of service, evaluate the effectiveness of parental controls and safeguards, and examine whether young people understand and feel empowered to exercise their privacy rights while gaming. This project will generate new, nationally relevant evidence on children’s privacy in interactive gaming environments while producing concrete, accessible educational resources to help Canadian families, educators and young people better understand, exercise, and protect privacy online.
Deliverables will include a bilingual research report synthesizing findings from the focus groups and survey as well as a bilingual key findings brief and infographic with recommendations.
Organization: Dalhousie University
Project title: It’s All Fun and Games (Until)
Amount requested: $58,650
Project leader: Alayna Kolodziechuk
Project summary:
The It’s All Fun and Games (Until) project aims to explore the unique privacy challenges and opportunities faced by those engaged in online gaming. Taking a Who-What-Where-Why-When-How Approach, the risks associated with online gaming are arguably some of the most significant and far reaching given their use by children and young people, using wearable devices and sensitive biometric monitoring, at home, and with high daily use rates. More concerning is the disarming nature that online games and entertainment can imply to the user and the normalization of privacy invasive gaming technology and features.
This research project considers what “meaningful consent” looks like in the context of online gaming. The discussion begins with a survey of the privacy impacts associated with online gaming through the investigation of certain technologies and features. Legal and technical research to convey the role that software updates, unilateral/browse-wrap agreements and settings will lay the foundation for how users can increase their engagement with privacy impacts and control will be compiled. Lastly, the project aims to take a critical look at the advertising strategies and approaches used by online gaming platforms.
The insights gained from the research outputs will result in a formal report as well as to inform the development of a two-part toolkit and companion promotional materials, all of which are intended to be visually interesting and engaging.
The first toolkit will be directed to students who wish to learn more about (i) privacy impacts of online gaming (ii) practical privacy-forward tips for how to more safely engage in online gaming and (iii) critical thinking when it comes to advertising strategies of online gaming platforms and media coverage. The second toolkit will be directed to families. Given the high uptake of online gaming by young people and children, this toolkit aims to educate families as to the risks and to provide engaging materials with which to self-assess privacy know-how, mitigate risks in the home and engage critically with advertising strategies of online gaming platforms.
Organization: York University
Project title: A Harm Reduction Approach to AI Safety in Canada: The Case of AI-Driven Privacy Harms
Amount requested: $44,275
Project leader: Jonathon Penney
Project team: Anindya Sen, Teresa Scassa, Sébastien Gambs
Project summary:
Artificial intelligence is generating urgent and serious privacy harms for Canadians. Generative AI platforms enable the mass production of non-consensual intimate imagery, including AI-generated child sexual abuse material. Online gaming platforms — used by more than half of Canadians, including millions of children — collect vast quantities of personal and behavioural data with limited transparency or meaningful consent. And AI-powered chatbots and agentic AI systems are rapidly accumulating persistent “memory” profiles of users, retaining sensitive personal information across interactions in ways that most Canadians neither understand nor control. These harms are real, escalating, and inadequately addressed by existing Canadian law.
This project proposes a harm reduction approach as a practical and principled alternative. Harm reduction is a pragmatic, evidence-based framework with deep roots in public health that has been successfully applied across many domains, from automobile safety to tobacco regulation and child exploitation prevention. Rather than waiting for a comprehensive regulatory scheme, harm reduction advocates targeted, proportionate interventions to address the most pressing harms immediately. It is flexible, complementary to other governance approaches, and well-suited to Canada’s structural constraints. A growing body of scholarship is already applying harm reduction frameworks to AI governance, yet no work has comprehensively elaborated this approach for AI-driven privacy harms in the Canadian private sector.
Expected project deliverables include a comprehensive harm reduction framework for AI-driven privacy harms in Canada, including a taxonomy of AI-driven privacy harms and an analytical framework for identifying and prioritizing urgent harms. Researchers will also produce three in-depth case study analyses (privacy harms in online gaming; generative AI and NCII; and AI agent/LLM memory), each including a harm characterization, legal analysis, and targeted harm reduction intervention recommendations. The project will also develop a policy brief with recommendations for policymakers and private sector organizations and a stakeholder workshop to bring together experts and other stakeholders.
2025-26 Contributions Program funding recipients
On August 28, 2025, the Office of the Privacy Commissioner of Canada (OPC) announced funding for a new round of independent research and knowledge translation projects funded under its Contributions Program. These projects should be completed by March 31, 2026. The OPC will post a summary of completed projects, as well as links to their outcomes, once the projects are completed and reviewed by the OPC.
Organization: University of Windsor
Project title: Driving Privacy Forward: Homomorphic Encryption and Oblivious AI in Smart Mobility
Amount requested: $80,012
Project leader: Mitra Mirhassani
Project summary:
Modern connected and autonomous vehicles (CAVs) incessantly gather and relay extensive personal information, including location history, driving patterns, biometric data, and infotainment choices, to enable AI-driven services like predictive maintenance, route optimization, and driver risk assessment. However, this rich data stream also exposes sensitive user information to potential misuse, unauthorized access, and breaches.
In Canada, regulatory protections lag behind the technology. PIPEDA provides only general guidance, underscoring a pressing need for privacy-by-design solutions that both uphold consumer rights and anticipate upcoming legislation, such as the proposed Consumer Privacy Protection Act (CPPA). The project aims to address these challenges by presenting a privacy-preserving architecture utilizing homomorphic encryption (HE) and oblivious AI to enable encrypted data analytics in connected vehicles.
In this approach, vehicle-generated data remains encrypted at all times, so cloud servers and external AI services can perform computations on the data without ever decrypting it. Even if a cloud platform is compromised, the data will remain unintelligible to attackers, hence minimizing the risk of privacy breaches. By integrating HE and oblivious AI, our framework allows connected vehicles to benefit from cloud-based machine learning and big data analytics while keeping all personal information fully encrypted. This represents a paradigm shift in automotive data handling: for example, a car can receive personalized insurance pricing or predictive maintenance alerts from cloud AI systems without revealing the driver’s raw data to the insurer or service provider. The system will be developed and evaluated for critical automotive applications and will be tested for a typical use case: privacy-preserving usage-based insurance purposes.
Organization: Toronto Metropolitan University
Project title: Losing your voice to AI: Privacy risks of health-related machine listening
Amount requested: $77,295.00
Project leader: Greg Elmer
Project team: Stephen Neville, Alexandra Borkowski
Project summary:
Smart speakers are the most popular smart home device in Canada and millions of Canadians use voice assistants like Alexa or Siri on a daily basis. However, smart speakers – and other voice-activated devices such as phones, wearables, and cars – do not only record conversations, they can also automatically produce biometric voice profiles of adults and children.
There is good reason to characterize voice data as sensitive health information as Big Tech corporations are planning to use voice data for health-related applications. When voice profiles are either tracked over time or correlated with statistical norms, this data can be used to make powerful inferences about the physical health, mental health, and wellness of Canadians. As voice data becomes increasingly processed by generative AI systems, there is a real risk of significant harm that could lead to unfair, unethical, or discriminatory treatment that contravenes human rights law – representing what the OPC labels as “no-go” zones.
The primary objective of this project is to map the array of applications for health-related machine listening to identify privacy risks and protect the privacy rights of Canadians. This will be achieved through multi-method research and an impactful digital literacy campaign. The first study maps the industry of health-related machine listening to identify information risks that fall under the scope of PIPEDA. The second study investigates the privacy policies that cover health-related voice data to see how the basic principle of consent is being fulfilled or not. And the final study identifies risks of significant harms related to health-related machine listening. Knowledge translation activities will target four segments of the public: citizens/consumers, digital literacy stakeholder organizations, privacy regulators and policy makers, and the private sector.
Organization: Automobile Protection Association
Project title: Evaluating Privacy Permissions and Consent Requested to Use a New Motor Vehicle
Amount requested: $43,005
Project leader: George Iny
Project team: Debbie Roberts Ph.D., Gilles Pilon, Ron Corbett
Project summary:
With the rise of the smart or connected car, the auto industry has become a leader in connected technology. Current vehicle models feature the internet of things (IoT); they incorporate complex systems of devices that communicate data about the driver and vehicle performance, experience and safety. These features include Global Positioning Systems (GPS), vehicle trackers, cameras and sensors, all of which can be connected to the cloud and are meant to enhance the driver experience as well as improve safety. Current vehicle technology benefits customers with hands-free calling and texting, navigation, infotainment, voice-assistance, sensors that detect drowsiness and alert drivers who are falling asleep, sensors that detect obstacles around the vehicle, and warning sensors that indicate service to the vehicle is needed or recommended. For many years, onboard data recorders have registered details of a vehicle’s operation in the seconds before a collision; recently, the depth of information collected has increased considerably and can include video of the vehicle in the minutes before a collision.
The purpose of this project is to collect and analyze the privacy permissions and releases automakers require of their Canadian customers in exchange for access to the onboard features and connected applications in their vehicles. Researchers will compile information using actual current-model-year vehicles, vehicle owner’s manuals, automaker websites, and information from auto dealers when it is available.
To the APA’s knowledge, this will be the first inventory undertaken in Canada to determine and understand the commitments that vehicle owners are making to fully use the connected capabilities of the vehicles they drive.
Organization: Vancouver Island University
Project title: Empowering Young Canadians in the Smart Device Era: A Privacy-by-Design Research and Public Engagement Initiative
Amount requested: $80,000
Project leader: Ajay Kumar Shrestha
Project team: Molly Campbell, Yulia Bobkova, Mohamad Sheikho Al Jasem, Trevor De Clark
Project summary:
This project aims to explore the unique privacy challenges and opportunities faced by older high school students and post-secondary learners (Ages 16–24) in Canada.
As smart devices become more embedded in everyday life, young Canadians are among the earliest adopters of these technologies. From AI-enabled learning platforms and gaming consoles to wearable health trackers and virtual assistants, young adults encounter a host of devices that collect, analyze, and sometimes share personal information, often with minimal transparency or user control. Recognizing the varied and sometimes hidden privacy risks these users face, this project adopts a comprehensive research approach.
First, a review of existing studies and best practices will map current knowledge on smart AI-embedded device privacy. Next, a mixed-method research design, combining surveys, focus groups, and technical audits of popular smart devices, will capture a diverse set of perspectives regarding privacy self-efficacy, perceived privacy risk, perceived privacy benefits, algorithmic transparency and trust, and privacy-protective behaviors. By focusing on the lived experiences of youth in both high school and post-secondary contexts, the research will shed light on the interplay between digital literacy levels, socio-economic backgrounds, and personal preferences around data ownership.
The insights gleaned from this multi-method study will inform the development of a privacy-by-design toolkit, tailored to the realities of young Canadians. This toolkit will offer practical guidelines and actionable recommendations for device manufacturers, educational institutions, policymakers, and families, fostering more transparent data practices and safeguarding personal information by default. In addition, interactive workshops, webinars, and a dedicated website will broaden community engagement, ensuring that the project’s findings reach not only researchers and policymakers but also young Canadians themselves.
Organization: Université de Sherbrooke
Project title: Analysis of the management of sensitive data by smartwatches: Privacy issues and recommendations for stakeholders
Amount requested: $80,000
Project leader: Pierre-Martin Tardif
Project team: Manon Ghislaine Guillemette, Aref Meddeb, Arthur Oulaï
Project summary:
The proposed project will examine the management of sensitive data collected by a wearable device, stored on a smartphone and transmitted to a cloud platform, taking a representative ecosystem as a use case: an Apple Watch connected to an iPhone via Apple’s HealthKit data aggregation platform.
The aim is to assess the technical mechanisms in place to ensure the confidentiality of sensitive information.
The results of this analysis will help identify the risks and best practices involved in managing sensitive data in these technological ecosystems.
Organization: Centre for Addiction and Mental Health
Project title: Smarter Privacy—A Service Design Approach to Public Engagement for AI Literacy of Smart Devices
Amount requested: $49,988
Project leader: Nelson Shen
Project summary:
As artificial intelligence (AI) systems become increasingly embedded in smart devices and daily life, individuals are increasingly making decisions that affect their privacy, autonomy, and rights. Despite this, public understanding of AI’s role in data collection, processing, and decision-making remains limited. Improving AI literacy, specifically digital citizenship, may empower individuals to responsibly make informed privacy decisions or effectively exercise their rights under the Personal Information Protection and Electronic Documents Act (PIPEDA).
While AI literacy programs currently exist, they are largely limited to formal education or professional settings. This creates a potential inequity as many may not have the ability, capacity, or motivation to access AI literacy courses. This project takes a human-centred service design approach to bridge this AI literacy gap by engaging the public in co-designing strategies to reach a broader population.
Organization: University of Ottawa
Project title: Connecting young women, but at what price? FemTech and privacy
Amount requested: $89,700
Project leader: Céline Castets-Renard
Project summary:
This research project aims to analyze the Personal Information Protection and Electronic Documents Act (PIPEDA) in the context of FemTech (female technology) mobile applications dedicated to wellness and the body, such as applications for tracking menstruation (Flo Health, Clue, Eve, Natural Cycle, etc.), pregnancy (e.g., Flutter Care) or breastfeeding (LactApp, Mylee, etc.). It will focus on Canadian women of childbearing age, particularly the youngest among these women, including minors, and aims to shed light on the negative impacts on their privacy. These applications, most of which are from U.S. companies, encourage women to provide a significant amount of sensitive and intimate data on their health. However, these companies’ general conditions of use and privacy policies are often vague when it comes to the measures being taken to protect personal information and comply with PIPEDA. This project will improve protection of the intimate personal information shared by women who use these applications. It will lead to recommendations to the legislator with a view to reforming PIPEDA following two unsuccessful attempts (Bill C‑11 in 2020 and Bill C‑27 in 2022).
Education and awareness‑raising initiatives specifically targeting young women will also be launched to raise awareness of their rights and the risks associated with FemTech applications to help these women better protect their personal data in a digital environment. Lastly, this research will fill a major knowledge gap, as while the extensive collection of personal information by FemTech applications has been criticized, there have been no systematic studies of the situation for women in Canada.
- Date modified: