Privacy Analyst
Status: Full Time
Hours: Monday – Friday, 35 hours/week
Home Campus: Fennell (hybrid work arrangements available)
Rate of Pay: Payband 10 ($88,983 - $111,230 per year)
Vacancy Status: 1 vacancy available
Posting Date: September 30th, 2026
Closing Date: October 6th, 2026 at 7:00 pm EST
We believe the rich diversity among our students and the communities we serve should be reflected within our workforce. As educators, we believe it is important to act and show leadership in advancing the principles of reconciliation, equity, diversity, and inclusion in our community.
The Privacy Analyst supports the institution's Privacy Management Program (PMP) by conducting privacy impact assessments (PIAs), reviewing technology and vendor solutions for privacy and data protection risk, and supporting compliance with the Freedom of Information and Protection of Privacy Act (FIPPA) and related provincial privacy legislation.
Working under the direction of the Privacy and Records Management Officer, the Privacy Analyst plays a hands-on role in operationalizing institutional privacy policy, assessing new systems and third-party agreements, supporting breach response, and helping build a culture of privacy-by-design across academic and administrative units. The incumbent is able to interpret complex privacy regulations to communicate them in clear language to a cross-section of College stakeholders, while maintaining positive working relationships and adhering to imposed deadlines.
The Privacy Analyst role is well suited to a detail-oriented privacy professional with formal IAPP certification who is comfortable translating legislative and regulatory requirements into practical, defensible assessments and recommendations.
This position can primarily work remotely, however, occasional travel to campus for in-person work may be required.
What you’ll be doing:
Privacy Impact Assessments & Technology Reviews
- Conduct Privacy Impact Assessments (PIAs) for new and existing systems, applications, vendor platforms, and institutional initiatives involving the collection, use, or disclosure of personal information.
- Perform privacy and data flow reviews for third-party technology platforms (e.g., learning management systems, survey and assessment tools, AI-enabled applications, cloud services), including data flow mapping, collection authority analysis under FIPPA, and identification of secondary-use or re-identification risk.
- Evaluate vendor contracts, data processing and sharing agreements, and SOC 2/security attestation documentation for privacy-relevant terms (sub-processor disclosure, breach notification obligations, data residency, no-secondary-use clauses).
- Assess emerging technologies, including AI and machine learning tools, against applicable guidance (e.g., IPC guidance, Ontario's Trustworthy AI Framework) and institutional privacy-by-design principles.
- Maintain a PIA and vendor assessment tracking log, including risk ratings, outstanding action items, and sign-off status.
Policy, Governance & Advisory Support
- Support development, maintenance, and interpretation of privacy policies, procedures, and templates under the institution's Privacy Management Program.
- Provide day-to-day privacy advisory support to faculty and staff on FIPPA collection, use, disclosure, retention, and disposal requirements.
- Assist in preparing briefing materials, risk summaries, and recommendations for the Privacy Officer and Senior Leadership Team.
- Support role-based data governance activities (e.g., Data Owner/Steward/Custodian mapping) and delegation frameworks for PIA sign-off.
Breach & Incident Support
- Assist in the intake, triage, and investigation of suspected privacy breaches or information incidents, including RROSH (Real Risk of Significant Harm) threshold analysis in accordance with Bill 194 amendments to FIPPA.
- Support completion of breach investigation reports, containment recommendations, and notification requirements to affected individuals and the Information and Privacy Commissioner of Ontario (IPC), as required.
- Contribute to post-incident reviews and recommendations for corrective action.
Training, Awareness & Reporting
- Develop and/or deliver privacy training and awareness materials for staff, faculty, and vendors.
- Track and report on institutional privacy metrics (PIA completion rates, breach volumes, vendor review status) for governance and audit purposes.
- Support responses to Freedom of Information (FOI) requests as needed, in coordination with Records/FOI staff.
Other duties as assigned.
What you’ll bring to the role:
- 3-year diploma/degree in relevant fields such as Information Management, Privacy, Legal Studies, Data Science, or related field, or equivalent combination of education and experience.
- 5 years of experience working in privacy, compliance, information governance or related roles, including reviewing and managing privacy case files, applying privacy legislation, and preparing clear summaries or recommendations for decision-maker.
- Demonstrated experience interpreting and applying the Freedom of Information and Protection of Privacy Act (FIPPA), including preparing responses and engaging with the Information and Privacy Commissioner of Ontario.
- Experience in a postsecondary or broader public sector environment/institution is preferred.
- Familiarity with data governance frameworks (e.g., DAMA-DMBOK) and role-based accountability models (Data Owner/Steward/Custodian).
- Experience assessing AI/ML-enabled tools against emerging AI governance frameworks.
- Experience supporting privacy breach investigations and regulatory reporting.
- Additional IAPP credentials (AIGP) considered an asset.
- CIPP/C (Certified Information Privacy Professional – Canada) or CIPM
- Relevant professional designation from the International Association of Privacy Professionals (IAPP) or other recognized professional bodies is an asset.
- Sound judgment and discretion in handling sensitive and confidential information.
- Ability to work independently while exercising escalation judgment on higher-risk matters.
- Collaborative approach - able to work effectively with IT, Legal, Records Management, academic units, and external vendors.
- Comfortable operating within audit-trail-driven, documentation-heavy governance processes.
- Commitment to privacy-by-design and proactive risk identification.
- Strong knowledge of Canadian privacy legislation (FIPPA, PHIPA, PIPEDA).
- Excellent communication and interpersonal skills, with the ability to influence diverse stakeholders.
- Ability to interpret complex privacy regulations, communicate them in clear, accessible language, and create and deliver effective training programs to educate diverse audiences.
- Skilled in reviewing, organizing, and interpreting large volumes of complex information, particularly in areas such as data breaches, privacy impact assessments and FIPPA requests.
- Strong critical thinking and problem-solving skills, with the ability to assess risks, identify solutions, and make sound decisions.
- Capable of working independently under pressure, managing multiple priorities, and meeting tight deadlines with minimal supervision.
- Demonstrated commitment and understanding of human rights, equity, diversity, inclusion, and accessibility.
- The ability to communicate and work effectively with diverse students, employees, and communities.
What we offer:
- Progressive vacation plan starting with 22 vacation days per year plus holiday closure.
- Defined Benefit pension plan (CAAT) with contributions matched by Mohawk College.
- 93% top up of maternity and parental leave pay for 52 weeks.
- Annual employee performance incentive program.
- Comprehensive benefits package including health, dental, vision, paramedical services (massage therapy, acupuncture, naturopath, psychotherapy and psychology), short-term and long-term disability.
- Ability to take courses at a reduced rate for employees and dependents.
To find out more about working at Mohawk College, including our Employee Value Proposition, please visit https://www.mohawkcollege.ca/about-mohawk/careers-at-mohawk
We are committed to reconciliation and nurturing an inclusive, diverse, equitable, and accessible (IDEA) environment for everyone who learns and works at Mohawk College. We welcome applications from racialized persons, women, Indigenous people, persons with disabilities, 2SLGBTQIA+ persons, and others who may contribute to the further diversification of ideas.
The College is committed to fostering inclusive and barrier-free recruitment and selection processes. If you require accommodation during any stage of the recruitment process, please contact Human Resources.
To learn more about Mohawk College’s commitments, please visit the Mohawk College strategic plan webpage: https://www.strategicplan.mohawkcollege.ca/