Privacy Impact Assessment (PIA) Specialist
Job Details
ELIGIBILITY: Only candidates currently residing within a commutable distance to the work location specified below will be considered. Applications from outside the local area will not be reviewed or responded to.
Closing Date: Wednesday, September 30, 2026 at 12:00 p.m.
Location: 20 Dundas St W, Toronto, ON M5G 2H1, Toronto, Ontario, Canada
Client: Ministry of Public and Business Service Delivery and Procurement
Start Date: 2026-10-01
End Date: 2027-03-31
Work Arrangement: Onsite
Job Type: Contract
Job ID: 11603
Project Overview
The service transformation team is leading privacy impact assessments to evaluate new technologies, systems, programs, or policies for alignment with legal, regulatory, and policy privacy requirements including FIPPA. This includes analyzing data flows and business processes to identify privacy risks and implement countermeasures, integrating privacy best practices into business architecture, IT system design, and public sector service delivery.
Key Responsibilities
- Lead or support the development of privacy impact assessments evaluating whether new technologies, information systems, or proposed programs or policies meet legal and policy privacy requirements
- Determine and mitigate privacy risks, and address clients’ concerns
- Ensure program compliance with provincial, municipal, federal and private sector access and privacy legislation, regulations, statutes, OPS policies, directives, standards, guidelines and internationally accepted Fair Information Practices
- Analyze data flows and business processes to proactively identify potential privacy risks and implement effective countermeasures
- Interpret and apply relevant privacy laws, OPS directives, international Fair Information Practices, and ensure ongoing compliance with evolving legislation and government standards
- Support the integration of privacy best practices into business architecture, IT system design, and public sector service delivery from early planning stages
- Create clear, actionable privacy policies, risk assessment tools, and procedures; communicate these effectively across technical and non-technical audiences
- Work with cross-functional teams including legal, IT security, business analysts, and program leads to ensure privacy is embedded across all areas of project planning and implementation
- Analyze and develop data flow and business process diagrams to support privacy assessments and ensure secure handling of personal information
- Remain informed of emerging privacy issues and deliver training or guidance to teams on compliance, risk mitigation, and privacy-enhancing technologies
Qualifications & Requirements
REQUIRED
- Must be able to work 5 days onsite per week in Toronto
- Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experienced in conducting privacy assessments involving personal information, citing examples in resume
- Experienced in leading and conducting privacy assessments involving online and/or digital solutions
- Lead and conducted assessments involving personal health information involving third party solutions (e.g. private sector or non-profit application solutions) and/or service integration providers
- Excellent knowledge of privacy and security concepts, trends, and issues
- Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures
- Experience in conducting Privacy Impact Assessments in public sector context
- Knowledge of, and experience with privacy enhancing best practices
- Knowledge and ability to interpret and apply Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence
- Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act
- Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services
- Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management
- Ability to lead, manage or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization
- Knowledge and ability to create and understand data flow diagrams and business process diagrams
- Ability to recognize the need for, and seek input from external experts as required
- Excellent communication skills with technical and business audiences and non-access and privacy experts
- Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives
- Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows
- Experience in developing risk assessment tools, methodologies, policies and procedures to effectively manage personal information
- Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information
- Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards
NICE TO HAVE
- OPS or Public Sector experience
- Professional certification from a related discipline such as IT security, architecture
- Experience providing education and training related to privacy
- Knowledge of, and experience with the policies and procedures of the Ontario government (e.g. business case development, project approvals and policy development)
EVALUATION CRITERIA
Privacy Assessment Experience, Policy and Legislative Requirements - 40%
- Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experienced in conducting privacy assessments involving personal information, citing examples in resume
- Experienced in leading and conducting privacy assessments with involving online and/or digital solutions
- Lead and conducted assessments involving personal health information involving third party solutions (e.g. private sector or non-profit application solutions) and/or service integration providers
- Experienced working with policy development teams; reviewing and comparing policies and legislation to make informed recommendations to ensure adequate privacy protections and considerations are addressed within policy/legislation
Technical Understanding - 30%
- Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms
- Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including web based and backend integrations via API or similar approaches
- Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, digital and cloud-based solutions to obtain, retrieve and synchronize information
- Familiar with cloud-based technologies including the security and privacy considerations, limitations, and best practices for data protection
- Experience, knowledge and understanding of privacy protection standards and best practices, business, information and security architecture principles and emerging technology related to the protection of privacy and personal information
Leadership and Communications - 20%
- Demonstrated strong communication and engagement skills with ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies, strong writing skills to document findings, recommendation, etc.
- Demonstrated ability to interpret both technical (e.g. architecture design documents, process flows, state transition diagrams, etc.) and non-technical documentation to conduct assessment of impacts and to develop mitigation strategies
- Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting
- Strong presentation abilities to communicate findings, recommendations, etc. to senior management and executives to inform decision making; able to communicate complex problems/issues in simple terms
Digital Identity Frameworks and Standards - 5%
- Experience in developing, applying and/or evaluating digital identity trust frameworks
OPS experience - 5%
- Prior experience with leading and conducting multiple PIAs in OPS setting/environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign off
Key Skills & Competencies
FIPPA, PHIPA, PIPEDA, MFIPPA, Privacy Impact Assessment, Data Flow Diagrams, Business Process Diagrams, IT Security, Encryption, API, Cloud Security, Digital Identity Frameworks, Risk Assessment Tools, Information Architecture, Records Management, AODA, Privacy Enhancing Technologies, System Interfaces, Web Applications, Legacy Systems Integration
Applications for this position will be accepted until Wednesday, September 30, 2026 at 12:00 p.m..
Apply Now via Email - Pre-filled Form
Click the button above. Your default email app (on iPhone or Android) will open with a pre-filled message containing all required screening questions. Simply complete and send.
⚠️ Applications without the pre-filled subject & body will not be processed.
Having trouble? Click here to copy the application template to your clipboard.
Pro Tip: Match your resume to the evaluation criteria above. It takes a few minutes and makes all the difference.