Summary
Overview
Work History
Education
Skills
Affiliations
Accomplishments
Timeline
Generic

Rachel Kukulewich

Milton,ON

Summary

Experienced privacy professional specializing in privacy risk assessments and operational program implementation. Developed compliance frameworks and training materials while engaging stakeholders. Knowledgeable in Canadian privacy laws and strategic governance, delivering strong data protection and privacy practices across various sectors.

Overview

21
21
years of professional experience

Work History

Independent Consultant

Worth A Look Consulting Services
01.2008 - Current

Secured contracts with Vancouver Island Health Authority, Yukon, Alberta, Ontario, and Prince Edward Island for privacy impact assessments, data governance frameworks, and AI governance.

  • Developed privacy training materials for diverse government and non-government clients, enhancing compliance and awareness across sectors.
  • Prepared and investigated critical privacy and cybersecurity incidents, delivering actionable recommendations and collaborating with staff for effective implementation.
  • Conducted digital platform reviews and managed contractual negotiations, ensuring alignment with health sector regulations and standards.
  • Developed back-office risk management modeling training materials and customized privacy impact assessment template to reflect Ontario legislation using TrustArc tool.
  • Audited legal documents to verify compliance with policies and procedures.
  • Utilized document management system to organize files for accessibility and currency.
  • Managed multiple projects concurrently, ensuring timely delivery within budget constraints.

FOI, Coordinator

Town of Caledon
01.2024 - 01.2026
  • Coordinated policy and program analysis for FOI requests with legal staff and affected areas, ensuring compliance and clarity.
  • Developed privacy requirements for all procurements involving resident data.
  • Conducted privacy impact assessments on new IT platforms and existing projects.
  • Developed information governance framework for SharePoint transition, enhancing data classification, retention schedules, and policies.
  • Revised privacy policies and collection statements to promote public transparency regarding data usage.
  • Oversaw severance and release of records to maintain legislative and policy compliance.
  • Provided guidance on MFIPPA, FIPPA, IPC orders, related legislation, and corporate recordkeeping policies.
  • Built a comprehensive privacy program within the Corporate Services Division.

FOI, Coordinator (6-month contract)

Independent Electricity System Operator (IESO)
01.2025 - 06.2025
  • Led and oversaw FOI requests and program area submissions, ensuring legal liaison and cross-departmental coordination.
  • Provided expert guidance on FIPPA, privacy principles, IPC orders, related legislation, and corporate policies.
  • Coordinated records review with consulting agency and ministry program areas, ensuring compliance with FOI regulations.
  • Analyzed complex access requests for general and personal information from diverse sources, facilitating informed decision-making.
  • Identified issues in information requests, recommending compliant solutions to enhance processing efficiency.
  • Ensured statutory requirements were met with appropriate application of exemptions.
  • Made disclosure decision recommendations aligned with statutory standards.

Manager, Health Privacy

Loblaw
01.2024 - 12.2024
  • Led operational reviews for specialty health and digital health networks to enhance privacy compliance.
  • Developed foundational privacy frameworks for pharmacy mergers and acquisitions in Alberta and Ontario.
  • Supported business and project teams to ensure adherence to privacy policies, legislation, and contractual obligations.
  • Coordinated reviews of ATIP requests, consulting multiple program areas and analyzing complex access inquiries to ensure compliance.
  • Oversaw internal audits on inappropriate data access and managed formal investigations of privacy breaches to enhance organizational accountability.
  • Directed development of privacy impact assessments for AI technologies in health sector to mitigate risks and ensure regulatory adherence.
  • Coordinated threat risk assessments to align contracts and projects with Ontario's privacy legislation.
  • Advised on interpretation and application of FIPPA, PHIPA, and PIPEDA regulations.

Senior Privacy Advisor (1 year contract)

Metrolinx
01.2023 - 01.2024
  • Developed privacy requirements for five large Presto procurement lots exceeding $20 million.
  • Led privacy initiatives for Presto, implementing criteria and project management gating in approval processes.
  • Supported Metrolinx departments and project teams in achieving compliance with privacy policies and legislative obligations.
  • Conducted policy analysis, coordinated with legal staff, and managed records release to ensure compliance.
  • Oversaw privacy principles and consulted with various program areas on IPC orders.
  • Analyzed complex access requests from multiple sources, ensuring statutory requirements and exemptions were met.
  • Recommended actionable solutions to enhance privacy practices across projects.
  • Collaborated with Corporate Secretary's Office to strengthen governance around privacy compliance.

Manager, Information Privacy

Trillium Health Partners
01.2022 - 01.2023
  • Led development of privacy impact assessments and coordinated threat risk assessments, ensuring compliance with Ontario privacy legislation.
  • Oversaw internal audits in Epic, addressing inappropriate access and ensuring formal investigations of privacy breaches.
  • Oversaw adherence to privacy principles under IPC orders, MFIPPA, PHIPA, and CYFSA.
  • Provided guidance on interpretation and application of FIPPA, ATIP, PHIPA, and PIPEDA regulations, supporting organizational adherence to privacy standards.
  • Drafted and reviewed data sharing agreements, ensuring alignment with privacy regulations.
  • Prepared and investigated critical incidents related to privacy and cybersecurity, providing actionable recommendations to staff.
  • Facilitated integration of Ontario Health’s CHRIS digital platform with Epic, enhancing data management capabilities.
  • Assisted in recovery efforts for SickKids Hospital post-cyber-attack, facilitating restoration processes.

Sr. Privacy Consultant, Access and Privacy Office

Ministry of Health and Long-Term Care
01.2005 - 01.2021
  • Provided strategic advice to assistant deputy ministers and minister's office on patient privacy matters.
  • Oversaw compliance with IPC orders and legislation on recordkeeping, ensuring adherence to corporate policies and safeguarding patient information.
  • Led privacy initiatives for the Ministry of Long-Term Care during the COVID-19 outbreak.
  • Processed ministry-related FIPPA requests, achieving 83 percent extended compliance while working remotely, enhancing transparency and accountability.
  • Collaborated with long-term care homes to manage media requests related to patient health information, ensuring compliance with privacy regulations.
  • Drafted and implemented ministry processes for successful completion of requests.
  • Trained ministry staff at all levels to ensure effective use of tools and resources.
  • Supported FIPPA functions for Ministry of Health, offering guidance on legislation interpretation.

Education

Certificate - Digital Privacy

York University
Toronto, ON
03-2026

Certificate - Privacy, Access and Information Management

Ryerson University
Toronto, ON
03-2026

Certificate - Marketing

Humber College
Toronto, ON
01-2008

BA - Public Administration

Ryerson University
Toronto, ON
01-2005

Skills

  • Privacy and Information Governance
  • Project privacy management
  • Privacy impact assessments
  • Privacy Impact Assessments
  • Vendor privacy compliance oversight
  • Shared system privacy governance
  • US privacy laws
  • Canadian privacy laws
  • EU privacy laws
  • LATAM privacy laws
  • APAC privacy laws
  • AI Governance
  • Operational program implementation
  • Strategy development
  • Corporate policies
  • Risk mitigation plans
  • GRC tools
  • OneTrust
  • Archer
  • ServiceNow
  • IT Security
  • IT Controls
  • NIST
  • ISO
  • ISO27001
  • NIST CSF
  • COBIT
  • Risk Management standards
  • AccessPro
  • Records information management
  • Training development
  • Stakeholder engagement
  • Visio
  • MS Excel
  • MS Word
  • MS Outlook
  • SharePoint
  • Tugboat
  • Resolver
  • Privacy-by-design
  • Regulatory knowledge
  • Regulatory knowledge

Affiliations

• Member in good standing with AMCTO
• Member in good standing with the Privacy & Access Council of Canada
• International Association of Privacy Professionals
• Member in good standing with Standardbred Canada
• Alcohol & Gaming Commission, Licensed as a Horse Racing Groom

Accomplishments

  • AMAPCEO, Women’s Caucus Chair, 01/01/19, 12/31/21
  • Peel Charity Slo-Pitch League, League President, 01/01/16, 12/31/20
  • Municipal Elections Compliance Audit Committee, Town of Caledon and City of Brampton, Member, 01/01/14, 12/31/18

Timeline

FOI, Coordinator (6-month contract)

Independent Electricity System Operator (IESO)
01.2025 - 06.2025

FOI, Coordinator

Town of Caledon
01.2024 - 01.2026

Manager, Health Privacy

Loblaw
01.2024 - 12.2024

Senior Privacy Advisor (1 year contract)

Metrolinx
01.2023 - 01.2024

Manager, Information Privacy

Trillium Health Partners
01.2022 - 01.2023

Independent Consultant

Worth A Look Consulting Services
01.2008 - Current

Sr. Privacy Consultant, Access and Privacy Office

Ministry of Health and Long-Term Care
01.2005 - 01.2021

Certificate - Digital Privacy

York University

Certificate - Privacy, Access and Information Management

Ryerson University

Certificate - Marketing

Humber College

BA - Public Administration

Ryerson University
Rachel Kukulewich