Pauline Vengeroff, Senior Manager Data & Model Ethics AI - Legal and Compliance

Pauline Vengeroff

Senior Manager Data & Model Ethics AI - Legal and Compliance

Thomson Reuters - Other Locations

Location
Canada - Toronto
Education
Master's degree, Data Protection and Tech Law
Experience
7 years, 0 Months

Share My Profile

Block User


Work Experience

Total years of experience :7 years, 0 Months

Senior Manager Data & Model Ethics AI - Legal and Compliance at Thomson Reuters - Other Locations
  • Canada - Toronto
  • My current job since April 2021

Reporting to the Director of Data & Model Ethics, I am responsible for developing and driving the strategy and planning involved in the successful adoption of standards and regulations related to the ethical use of data and AI by:
- Acting as the key contact and liaison with legal counsel, I develop the strategy for the enterprise wide understanding and adoption of regulatory requirements for ethical data use and AI - building and owning success metrics;
- Monitoring and reporting on the latest developments in legislative and regulatory instruments as it pertains to key ethics principles - translating into technical policies and requirements;
- Working closely with external industry leaders, customers, and stakeholder groups to understand latest regulatory and social trends, sentiments, and challenges;
-Working closely with Data and Model stewardship network, Ethics Leads, and stakeholders as a specialist consultant on data and AI projects across the organization - advising on upcoming legal and regulatory trends, as well as compliance best practices;
- Ensuring that data and AI ethics policies and guiding standards are inclusive of the requirements necessary to meet the growing demands of data and AI related regulation and best practices - drafting new policies where necessary;
- Providing thought leadership, executive summaries, and insights on data and AI ethics and governance matters to colleagues across the organization - contribute to educational resources;
- Participating in data and AI governance policy and standard creation, management, and analyzing potential impacts of policy choices under consideration;
- Using and understanding governance activities including oversight mechanisms, documentation, development processes - and expert on standardization bodies requirements and best practices, such as the ISO, IEEE, W3C, EU document, and OECD;
- Working closely with data management, ModelOps and traditional software development life cycles 

Risk Manager and Privacy Officer (Digital Health) at Telus
  • Canada - Toronto
  • March 2021 to April 2022

Supported by the Director of Privacy & Innovation, I materially influenced the ongoing development of TELUS' business by:
- Ensuring that business initiatives meet rigorous privacy, ethical and security standards;
- Developing new internal and external guidance frameworks for de-identification and synthetic data;
- Conducting privacy impact assessments, data risk assessments and strategic planning as part of the privacy management for businesses; - Conducting Privacy Due Diligence reports for Mergers and Acquisitions of TELUS international; Ensuring compliance with all provincial and federal Canadian privacy laws; as well as international laws such as the CCPA, GDPR and HIPAA;
- Supporting business units in deploying technology responsibly and ethically by providing counsel to execute data handling frameworks;
- Educating and advising on new or existing data, privacy or ethicaluses and provide strategies to address data governance and privacy;
- Primary support for all of TELUS Quebec initiatives, advising and in English and French, as well as for compliance with Quebec civil law;
- Escalating privacy risks promptly and ensure mitigation techniques are implemented; and
- Learning continuously.

In my hybrid position at the TELUS Data and Trust office, I was the Privacy Officer of the TELUS Health Virtual Pharmacy for all of Canada, I:
- Implemented and deployed an entire privacy management program (including training, privacy policies, disaster recovery responses, privacy risk assessments, etc). to ensure provincial healthlegislation compliance, regulatory and legal compliance with all operations in Canada;
- Managed and mitigated breach incidents;
- Was the officer responsible for all pharmacy management systems (PMS) owned by TELUS in Canada;
- Worked closely with all stakeholders, provincial and federal privacy commissioners and regulatory boards for pharmacies in Canada.

Legal Advisor at Canadian Air Transport Security Authority
  • Canada - Ottawa
  • March 2020 to March 2021

Reporting to the Manager of Information Management and Privacy, I provided support and advice on privacy requirements including:
- Conducting full Privacy impact Assessments (PIAs) and organizational reviews;
- Providing subject matter expertise and advice on potential privacy implications of CATSA's Activities through Privacy by Design and GAPP frameworks for new technologies;
- Supporting the Manager in the development of PIPEDA and Privacy Act compliant policy practices, processes and policy documents, including notice and consent requirements;
- Facilitating privacy training for management and staff to increase awareness and importance of privacy requirements within the organization;
- Conducting research, analysis and recommendations for privacy best practices, legislation and regulations.

Legal Advisor at Statistics Canada
  • Canada - Ottawa
  • March 2019 to January 2021

Supporting the Chief Privacy Officer of Statistics Canada, I:
- Advised divisions on legal requirements under the Statistics Act and Privacy Act,  standards for de-identification and anonymization procedures with internal and external stakeholders. 
- Advised on Information Security, Classification of Datasets, Cloud Technologies and Privacy security best practices for new technologies.
- Interpreted laws, regulations, policies and orders to determine the organization's access and privacy rights.
- Prepared Privacy Impact Assessments (PIAs); Ensured legal compliance with recommendations on preventative measures to comply with privacy laws.
- Identified developed, recommended and/or implemented business processes that maintain or improve organizational privacy compliance, while meeting functional requirements and maintaining business continuity.
- Member of the security information coordination division.
- Updated and amend internal policies and directives to align with current modernization agenda.
- Supported Access to Information Requests (ATIP),  breach notifications, and internal active monitoring projects.
- Conducted research on national and international privacy standards including European Union's GDPR.

Research Scholar at University of Ottawa
  • Canada - Toronto
  • May 2017 to December 2020

Canada Research Chair, Faculty of Law, University of Ottawa.
- Provided research support to Canadian Research Chair Katherine Lippel that included case-law compilation, analysis and review;
- Legal analysis and research of academic literature.
- Labour law and occupational health and safety,  including: occupational diseases, compensation for first-responders and nurses, presumptive legislation, stress at work and traumatic/acute mental stress disorders.
- Reviewed primarily Quebec and Ontario legislation: Workers Safety and Insurance Act,  Loi sur la santé et sécurité du travail (LSST),  Loi sur les accidents du travail et maladies professionnelles (LATMP).
- Worked with case law from the WSIB, WSIAT (Ontario) and CNESST (Quebec).
- Wrote legal reports analyzing the current state of legislation and recommendations for future changes.

Research Assistant at University of Ottawa
  • Canada - Ottawa
  • April 2019 to December 2020

Faculty of Law, Health and Tech Law Section
- Prepared a white paper for the Ministry of Ontario eHealth.
- Reviewed legal implications of implementing MyChart, a patient portal, in Ontario for Southern Ontario hospitals - Sunnybrook Health Sciences.
- Outlined potential approaches for governmental, regional, and/or institutional policy and regulatory frameworks to manage consent and liability issues posed by patient portals.
- Ensured legal compliance with Canadian privacy laws: Ontario’s Personal Health Information Protection Act (PHIPA), Freedom of Information and Protection of Privacy Act (FIPPA) and federal’s Personal Information Protection and Electronic Documents Act (PIPEDA).

Consultant at Osler, Hoskin & Harcourt
  • Canada - Ottawa
  • June 2018 to September 2018

Privacy and Anonymization Laws
- Created a spreadsheet of legal requirements for all provinces and Canadian legislation for anonymization/deidentification of health data (consent requirements, third-party sharing, etc.)
- Researched international legal requirements for Ireland, Australia, UK, New Zealand, South Korea, and United States.

Legal Researcher at Childrens Eastern Hospital of Ontario (CHEO)
  • Canada - Ottawa
  • June 2017 to June 2018

Legal Researcher and Compliance for Innovative Medicine and the eHealth Laboratory
Supervised by Dr. Khaled, El Emam:
- Researched and studied international standards for de-identification (anonymization) of personal health information.
- Wrote comparative reports on varying guidelines internationally (re-identification sanctions, consent requirements,
techniques for anonymization/de-identification, minimum standards, etc.)

Research Supervisor at Piano Pedagogy Laboratory, University of Ottawa
  • Canada - Ottawa
  • June 2017 to September 2017

Supervised 4 researchers from the Faculty of Music (piano) during the collection of questionnaires at the Orkidstra music
program. Ensured collaboration with the ‘El Sistema’ stakeholder and effective communication.

Education

Master's degree, Data Protection and Tech Law
  • at University of Ottawa
  • August 2021
Bachelor's degree, law
  • at University of Ottawa
  • April 2019
High school or equivalent, general
  • at Vaughan Secondary School
  • April 2014

Specialties & Skills

Legal Technology
Artificial Intelligence
Privacy Law
Personal Data Protection
Compliance
Due Diligence Reports
Mergers and Acquisitions
Microsoft Office
Research & Analysis
Strategic Planning
Industry Legal Analysis and Compliance
Privacy / Data Management Programs
Legal Innovation
Legal Compliance
Data and Model Governance
negotiation
research ethics
problem solving

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Native Speaker
French
Expert
Russian
Expert

Memberships

International Association of Privacy Professionals (IAPP)
  • member
  • December 2019

Training and Certifications

Privacy Law and Data Protection in the USA - University of Pennsylvania (Certificate)
Date Attended:
April 2020
Certified Information Privacy Professional (CIPP) - European Union (Certificate)
Date Attended:
June 2022
Certified Information Privacy Professional (CIPP) - Canada (Certificate)
Date Attended:
May 2020

Hobbies

  • Competitive Swimmer
    I was a competitive swimmer for over 12 years and I was nationally qualified in 2015.
  • Piano
    I completed the highest level of the Royal Conservatory of Music in piano performance.