Privacy Impact Assessment (PIA) Specialist
Job Details
ELIGIBILITY: Only candidates currently residing within a commutable distance to the work location specified below will be considered. Applications from outside the local area will not be reviewed or responded to.
Closing Date: Friday, September 18, 2026 at 1:00 p.m.
Location: 222 Jarvis St, Toronto, Ontario, Canada
Client: Ministry of Treasury Board Secretariat
Start Date: 2026-09-28
End Date: 2026-11-18
Work Arrangement: Onsite
Job Type: Contract
Job ID: 11631
Project Overview
CPOD Initiative requires a privacy impact assessment aligned with new FIPPA amendments and corporate governance, with consultation from IT Source.
Key Responsibilities
- Lead or support development of a privacy impact assessment evaluating new technologies, information systems, or proposed programs or policies for legal and policy privacy requirements.
- Determine and mitigate privacy risks and address clients' concerns.
- Ensure program compliance with provincial, municipal, federal and private sector access and privacy legislation, regulations, statutes, OPS policies, directives, standards, guidelines and Fair Information Practices.
- Follow Corporate Governance and align PIA with new FIPPA amendments.
- Conduct Privacy Impact Assessment, provide privacy advice, recommendations and directions, with consultation from IT Source.
- Produce deliverable Privacy Impact Assessment aligned to Corporate Governance.
Qualifications & Requirements
REQUIRED
- Must be able to work 5 days onsite per week in Toronto
- Experienced in privacy legislation including FIPPA, PHIPA, PIPEDA
- Experienced in conducting privacy assessments involving personal information, citing examples in resume.
- Experienced in leading and conducting privacy assessments involving online and/or digital solutions.
- Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms.
- Prior experience with leading and conducting multiple PIAs in OPS setting/environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign-off.
- Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting.
NICE TO HAVE
- Demonstrated ability to interpret technical and non-technical documentation to conduct assessments and develop mitigation strategies.
- Familiar with cloud-based technologies including security and privacy considerations, limitations, and best practices for data protection.
- Professional certification from a related discipline such as IT security, architecture.
- Experience providing education and training related to privacy.
- Knowledge of and experience with OPS policies and procedures (e.g., business case development, project approvals, policy development).
EVALUATION CRITERIA
Privacy Assessment Experience, Policy and Legislative Requirements - 40%
- Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experienced in conducting privacy assessments involving personal information, citing examples in the resume.
- Experienced in leading and conducting privacy assessments involving online and/or digital solutions.
- Experienced working with policy development teams; reviewing and comparing policies and legislation to make informed recommendations to ensure adequate privacy protections and considerations are addressed within policy/legislation.
Technical understanding - 30%
- Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms.
- Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including web based and backend integrations via API or similar approaches.
- Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, digital and cloud-based solutions to obtain, retrieve and synchronize information.
- Familiar with cloud-based technologies including the security and privacy considerations, limitations, and best practices for data protection.
- Experience, knowledge, and understanding of privacy protection standards and best practices, business, information and security architecture principles and emerging technology related to the protection of privacy and personal information.
Leadership and Communications - 20%
- Demonstrated strong communication and engagement skills with the ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies, strong writing skills to document findings, recommendations, etc.
- Demonstrated ability to interpret both technical and non-technical documentation to conduct assessments of impacts and to develop mitigation strategies.
- Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting.
- Strong presentation abilities to communicate findings, recommendations, etc. to senior management and executives to inform decision-making; able to communicate complex problems/issues in simple terms.
OPS Experience - 10%
- Prior experience with leading and conducting multiple PIAs in OPS setting/environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign-off.
Key Skills & Competencies
Privacy Impact Assessment, FIPPA, PHIPA, PIPEDA, MFIPPA, Privacy legislation, Data flow diagrams, Business process diagrams, IT security, Encryption, API integration, Cloud security, Risk assessment, Information architecture, Data protection, Records management, AODA
Applications for this position will be accepted until Friday, September 18, 2026 at 1:00 p.m..
Apply Now via Email - Pre-filled Form
Click the button above. Your default email app (on iPhone or Android) will open with a pre-filled message containing all required screening questions. Simply complete and send.
⚠️ Applications without the pre-filled subject & body will not be processed.
Having trouble? Click here to copy the application template to your clipboard.
Pro Tip: Match your resume to the evaluation criteria above. It takes a few minutes and makes all the difference.