Modern vehicles are rolling computers. SHIELD studies what data they collect, where it goes, and how drivers — and everyone around them — can stay in control.
Homomorphic Encryption and Oblivious AI in Smart Mobility. Supported by the Office of the Privacy Commissioner of Canada, this project asked a simple question: can connected-vehicle analytics stay useful without service providers routinely seeing raw personal data?
Through a technical demonstration and two rounds of stakeholder interviews, SHIELD showed that privacy-preserving analytics can improve both the intelligibility and the perceived legitimacy of connected-vehicle data use — while making the case that governance matters as much as the technology.
Data can move across manufacturers, telematics providers, insurers, apps, analytics platforms, cloud processors, and dealerships. Risk arises from over-collection, unclear downstream use, and routine exposure of raw data during processing.
Stakeholders repeatedly described excessive data collection — not data scarcity — as the central privacy concern in connected mobility.
Our demonstration showed cloud-based mobility analytics can still deliver useful results without the service provider routinely seeing raw personal data.
Encryption alone is not enough. Trust depends on data minimization, clear roles, auditability, meaningful transparency, and limits on reuse.
Connected-mobility governance should also account for passengers, pedestrians, cyclists, and others captured indirectly in public space.
Priorities for PIPEDA modernization, CPPA-style reform, and Transport Canada’s connected-mobility context.
Recognize mobility data as potentially high-sensitivity in law and binding guidance.
Require privacy impact assessments before high-risk connected-vehicle processing.
Strengthen purpose limitation and restrict function creep and repurposing.
Create a practical mobility-data transfer (portability) right for individuals.
Recognize privacy-enhancing technologies as valid ways to reduce exposure.
Clarify de-identification, anonymization, and residual inference risk.
Require layered, just-in-time transparency at the vehicle and app interface.
Require accountable, proportionate governance across the whole data ecosystem.
A plain-language campaign helping drivers understand vehicle data — part of our knowledge-transfer mandate.




To close out Privacy Awareness Week 2026, Dr. Mitra Mirhassani spoke with Dr. Ikjot Saini about what today’s vehicles collect, where that data can go, and what “privacy by design” can look like in practice.
The completed project and its knowledge-translation materials, published for public access.
The comprehensive close-out report synthesizing the technical, qualitative, and outreach work of the project.
Download PDF →A plain-language translation of the technical findings into regulatory recommendations for PIPEDA / CPPA modernization and Transport Canada’s CAV Safety Framework.
Download PDF →Public-education cards explaining what connected vehicles collect, where the data goes, and how to stay in control.
View the campaign →A closing conversation with Dr. Ikjot Saini on what today’s vehicles collect, where that data can go, and what “privacy by design” looks like in practice.
Watch the recording →The companion slide material: the prototype walkthrough, connected-vehicle privacy risks, and the best-practice guidance presented during Privacy Awareness Week 2026.
Download PDF →An anonymized bundle of encrypted logs, traces, and scripts enabling other researchers and regulators to reproduce the latency and accuracy results.
Public trust in connected and automated vehicles depends not only on safety and cybersecurity, but on credible privacy governance across the full data lifecycle.