Position: Privacy Impact Assessment (PIA) Specialist - Senior
Requisition Number: RQ11603
Assignment Number: A2903126
Client: Government Services Integration Cluster
Ministry: Ministry of Public and Business Service Delivery and Procurement
Start Date: Oct 01, 2026
End Date: Mar 31, 2027
Location: 20 Dundas St W, Toronto, ON M5G 2H1
Work Schedule: Onsite (5 days per week)
Hours: 7.25 hours per day (8:00 AM to 5:00 PM; excluding breaks)
MANDATORY SKILLS
- Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experienced in conducting privacy assessments involving personal information, citing examples in resume.
- Experienced in leading and conducting privacy assessments with involving online and/or digital solutions.
- Lead and conducted assessments involving personal health information involving third party solutions (e.g. private sector or non-profit application solutions) and/or service integration providers.
Nice to have: OPS or Public Sector exp.
EXPERIENCE AND SKILL SET REQUIREMENTS
40% - Privacy Assessment Experience, Policy and Legislative Requirements
- Experienced in privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experienced in conducting privacy assessments involving personal information, citing examples in resume.
- Experienced in leading and conducting privacy assessments with involving online and/or digital solutions.
- Lead and conducted assessments involving personal health information involving third party solutions (e.g. private sector or non-profit application solutions) and/or service integration providers.
- Experienced working with policy development teams; reviewing and comparing policies and legislation to make informed recommendations to ensure adequate privacy protections and considerations are addressed with in policy/legislation.
30% - Technical understanding
- Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms.
- Demonstrated experience and familiarity with strong security, encryption and privacy protection approaches to digital solutions, including web based and backend integrations via API or similar approaches.
- Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, digital and cloud-based solutions to obtain, retrieve and synchronize information.
- Familiar with cloud-based technologies including the security and privacy considerations, limitations, and best practices for data protection.
- Experience, knowledge and understanding of privacy protection standards and best practices, business, information and security architecture principles and emerging technology related to the protection of privacy and personal information.
20% - Leadership and Communications
- Demonstrated strong communication and engagement skills with ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies, strong writing skills to document findings, recommendation, etc.
- Demonstrated ability to interpret both technical (e.g. architecture design documents, process flows, state transition diagrams, etc.) and non-technical documentation to conduct assessment of impacts and to develop mitigation strategies.
- Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting.
- Strong presentation abilities to communicate findings, recommendations, etc. to senior management and executives to inform decision making; able to communicate Page 6 of 12 complex problems/issues in simple terms.
5% - Digital Identity Frameworks and Standards
- Experience in developing, applying and/or evaluating digital identity trust frameworks.
5% - OPS experience
- Prior experience with leading and conducting multiple PIAs in OPS setting/ environment, including demonstrated knowledge and experience with OPS processes, existing templates and expectations to obtain approvals/sign off.