How one group of California rockers fell in love with Newfoundland and Labrador
The binding power of music cannot be understated. Just this summer alone, throngs of visitors will flock to our shores for communal sonic experiences. From the Churchill Park Music Festival, to Iceberg Alley, the 40th annual George Street Festival, and the final ever Newfoundland and Labrador Folk Festival, the songs and experiences of genres and artists, both local and abroad, provide lasting memories for those young and old.
Here in Newfoundland and Labrador, music is a part of our culture and history; it is an expression, a form of communion that unites in a given love.
For Jarvis Leatherby, a lifelong artist and rocker from Ventura, California, the unifying power of music has guided his entire life and career.
Founder, lead-singer and bassist to world-travelling metal outfit Night Demon, Jarvis, alongside Armand John Anthony and Brian Wilson, fell in love with the province of Newfoundland and Labrador from their first visit to St. John’s in September 2019.
“It was a magical place right away,” Jarvis shared with Downhome. “The unpredictable weather and working-class mentality of the town correlate with the heavy metal genre at its core. I feel like some of the great fantasy authors would benefit if they spent time there to do some writing. There’s just no other place on earth like it, really.”
The band has returned twice in the subsequent six years, first in 2022 at a packed show at the Knights of Columbus Hall in St. John’s, and again the following year at the Bella Vista, to celebrate the release of their latest record, Outsider.
The trio return once more in their lone Canadian stop as part of their anniversary tour for their debut album, the epic concept album Curse of the Damned.
“While it’s hard to believe it’s already been ten years, I look back and realize we have done over 800 shows since then!” Jarvis shares of the landmark anniversary. “The songs on this album have never left our live set, and it’s the record that catapulted us into a higher and more respected realm of the metal industry. It’s a true honour to kick off this tour in St. John’s, where we know a lot of our true supporters fly the flag for this album on a consistent basis.”
And while cost and geography keep many touring artists from experiencing the diehard fan base that makes up Newfoundland and Labrador’s eclectic music community, Jarvis and company have experienced firsthand the power and energy of the place, and have rewarded their followers with frequent return visits befitting of such passion.
“The excitement from the metal and rock community is in the air. We are proud to be one of the only bands in our genre to have made the commitment to returning often,” Jarvis says. “The pandemic put us back a bit from doing that, but this being our third time back since then has really stoked the fires for something the local underground to be looking forward to. Our love of St. John’s does even go beyond the fans and the fact that our weekly podcast is produced there. The topography of the land is something to marvel at, and we spend a lot of time exploring the woods and more rural areas. It’s an inspiring reset for us and gives us a spark of creativity that we always take home with us.”
Catch Night Demon, with the return of legendary local outfit Emblem, and Nova Scotia’s Turbo, at The Rock House in St. John’s this Saturday. Tickets here.
Data Privacy Practices in Canadian Online Gaming: Insights from Casizoid
Canada’s online gaming sector has expanded considerably since the provincial regulation shifts of the early 2020s, with Ontario launching its regulated iGaming market in April 2022 under the Alcohol and Gaming Commission of Ontario (AGCO). This growth has brought data privacy to the forefront of both regulatory and consumer discussions. Unlike many jurisdictions that treat gambling platforms as entertainment services with minimal data obligations, Canadian regulators and privacy commissioners have increasingly applied the full weight of federal and provincial privacy law to licensed operators. Understanding how these platforms collect, store, and process personal data is no longer a niche concern — it directly affects millions of Canadians who engage with online casinos, poker rooms, and sports betting services on a weekly basis.
The Legal Framework Governing Player Data in Canada
Canada’s primary federal privacy legislation, the Personal Information Protection and Electronic Documents Act (PIPEDA), has governed private-sector data handling since 2001. Under PIPEDA, online gaming operators are classified as commercial entities and are therefore required to obtain meaningful consent before collecting personal information, to limit collection to what is necessary for identified purposes, and to implement safeguards proportional to the sensitivity of the data. Player data in the gaming context is particularly sensitive because it combines financial information, identity documents, behavioral patterns, and in some cases geolocation data — a combination that creates significant risk if mishandled.
In 2020, the federal government introduced Bill C-11, later replaced by Bill C-27 in 2022, which proposed replacing PIPEDA with the Consumer Privacy Protection Act (CPPA). Although this legislation had not yet received royal assent as of mid-2024, its provisions signal a clear direction: stricter consent requirements, expanded rights for individuals to request data deletion, and substantially higher administrative monetary penalties — up to 5% of global gross revenue or $25 million CAD, whichever is greater. For online gaming operators, this potential liability is not abstract. A mid-sized licensed operator processing hundreds of thousands of accounts would face enormous exposure under any significant breach scenario.
At the provincial level, Quebec’s Law 25 (formerly Bill 64) came into force in phases between 2022 and 2023 and is widely considered the most stringent privacy legislation in Canada. It requires organizations to appoint a privacy officer, conduct privacy impact assessments before launching new technology projects, and notify both the Commission d’accès à l’information and affected individuals within 72 hours of a confidentiality incident. Gaming platforms operating in Quebec — or collecting data from Quebec residents — must align their data governance structures accordingly, regardless of where the operator is incorporated.
How Licensed Operators Collect and Use Player Data
The data lifecycle for a typical Canadian online gaming account begins at registration. Know Your Customer (KYC) requirements, mandated by both the AGCO in Ontario and anti-money laundering obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), require operators to collect government-issued identification, proof of address, and in some cases source-of-funds documentation. This data is retained for a minimum of five years under federal AML rules, creating long-term storage obligations that must be secured against unauthorized access.
Beyond identity verification, operators collect behavioral data throughout a player’s session — game selection, session duration, wagering patterns, deposit frequency, and withdrawal requests. This data serves multiple purposes: it feeds responsible gambling algorithms designed to detect problem gambling indicators, it informs personalized marketing, and it supports fraud detection systems. The dual use of behavioral data for both player protection and commercial purposes creates a tension that regulators have begun to scrutinize more closely. The AGCO’s Standards for Internet Gaming, updated in 2023, specifically require operators to use player activity data to support harm reduction measures, not merely to optimize engagement metrics.
Third-party data sharing is another area of active concern. Many platforms rely on affiliate networks, payment processors, identity verification vendors, and analytics providers — each of which may receive subsets of player data. Under PIPEDA and Quebec’s Law 25, operators remain accountable for how third parties handle data transferred to them and are expected to have contractual protections in place. Resources such as casizoid.org document how specific platforms disclose their third-party data relationships within privacy policies, offering a practical reference point for consumers comparing data practices across licensed sites.
Responsible Gambling and the Data Privacy Intersection
One of the more nuanced developments in Canadian online gaming regulation is the increasing overlap between responsible gambling obligations and data privacy rights. Operators are required under AGCO standards to implement self-exclusion programs, deposit limits, and reality-check notifications — all of which depend on continuous data collection and processing. The Ontario Self-Exclusion Program (OnSE), launched alongside the regulated market in 2022, requires participating operators to match incoming registrations against a shared exclusion database. This involves processing sensitive personal data across multiple organizations, raising questions about data minimization and purpose limitation that are not yet fully resolved in regulatory guidance.
From a technical standpoint, responsible gambling systems increasingly use machine learning models trained on aggregated player behavior to flag at-risk individuals. These models introduce additional privacy considerations: the automated processing of personal data to make inferences about an individual’s psychological state arguably constitutes profiling under modern privacy frameworks. Quebec’s Law 25 explicitly addresses automated decision-making, requiring transparency about when such processes are used and giving individuals the right to request human review. Whether responsible gambling flags qualify as “decisions” under this framework is a question that gaming operators’ legal teams are actively working through.
Data retention in the responsible gambling context also creates complications. If a player’s historical session data is necessary to accurately assess risk over time, operators face pressure to retain records longer than they might otherwise need for commercial purposes. Balancing this against the principle of storage limitation — keeping data only as long as necessary — requires documented retention schedules and periodic reviews. Operators that fail to establish these governance structures expose themselves not only to regulatory penalties but to reputational damage in a market where consumer trust is increasingly tied to transparent data practices.
Cybersecurity Standards and Breach Notification in Gaming Platforms
The gaming sector has been a consistent target for cybercriminals, partly because platforms hold both financial credentials and identity documents in the same environment. High-profile breaches in the broader gambling industry — including incidents affecting major international operators in 2023 — have reinforced the need for robust technical safeguards. Under PIPEDA’s breach of security safeguards regulations, which came into force in November 2018, Canadian operators are required to notify the Office of the Privacy Commissioner (OPC) and affected individuals when a breach creates a “real risk of significant harm.” This threshold includes financial harm, identity theft, and reputational damage — outcomes that are plausible in virtually any gaming platform breach involving KYC documents.
The technical standards expected of licensed operators have evolved considerably. The AGCO’s technical standards reference internationally recognized frameworks, including controls consistent with ISO/IEC 27001 for information security management. Encryption of data in transit and at rest, multi-factor authentication for account access, penetration testing, and incident response planning are all considered baseline requirements rather than optional enhancements. Operators seeking licensure in Ontario must demonstrate compliance with these standards as part of the application process, and ongoing compliance is subject to audit.
Payment data introduces a separate but overlapping compliance layer. Online gaming platforms that process card payments are subject to Payment Card Industry Data Security Standard (PCI DSS) requirements, which mandate network segmentation, access controls, and regular vulnerability assessments. The 2022 release of PCI DSS version 4.0, with a compliance deadline of March 2025, introduced additional requirements around customized implementation approaches and expanded multi-factor authentication requirements. For operators managing both PCI DSS and PIPEDA obligations simultaneously, the administrative burden is substantial — particularly for smaller licensed operators without dedicated compliance teams.
Canada’s online gaming privacy landscape is in active development, shaped by legislative reform at the federal level, Quebec’s pioneering provincial framework, and the AGCO’s increasingly detailed technical and operational standards. Players engaging with licensed platforms in Ontario and beyond are protected by a layered system of obligations that, when properly implemented, offers meaningful safeguards for sensitive personal and financial data. The gap between what regulations require and what operators actually implement remains a legitimate area of scrutiny, and informed consumers, researchers, and regulators all play a role in closing it. As the proposed federal privacy reform moves closer to enactment, the compliance expectations for Canadian gaming operators will only become more demanding — making data governance not just a legal obligation but a core operational competency.

