Client: Ministry of Public and Business Service Delivery and Procurement – RQ11603 We are looking for a highly experienced Senior Privacy Impact Assessment (PIA) Specialist to support the Justice Technology Services and related public-sector initiatives in assessing privacy risks associated with new technologies, information systems, digital solutions, programs, and policies. The ideal candidate will have strong experience with privacy legislation, Privacy Impact Assessments, privacy risks, digital and cloud-based solutions, information security, data flows, privacy protection standards, and Ontario Public Service processes.
Role Snapshot
- Job Title: Privacy Impact Assessment (PIA) Specialist – Senior
- Req. Number: RQ11603
- Client: Ministry of Public and Business Service Delivery and Procurement
- Work Location: 20 Dundas St W, M5G 2H1, Toronto, Ontario
- Work Arrangement: Onsite
- Estimated Start Date: October 1, 2026
- Estimated End Date: March 31, 2027
- Business Days: 125
- Extension: Probable after the initial mandate
- Hours: 7.25 hours per day
- Security Level: No Clearance Required
Must Have
- Experience with privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), and Personal Information Protection and Electronic Documents Act (PIPEDA).
- Experience in conducting privacy assessments involving personal information, with examples cited in the resume.
- Experience in leading and conducting privacy assessments involving online and/or digital solutions.
- Experience leading and conducting assessments involving personal health information involving third-party solutions, such as private-sector or non-profit application solutions, and/or service integration providers.
Nice to Have
- OPS or Public Sector experience.
Description Responsibilities
- Required to lead or support the development of a Privacy Impact Assessment (PIA) that evaluates whether new technologies, information systems, or proposed programs or policies meet legal and policy privacy requirements, determine and mitigate risks, and address clients’ concerns.
- These requirements include ensuring that the program complies with provincial, municipal, federal, and private-sector access and privacy legislation, as well as relevant regulations, statutes, OPS policies, Directives, standards, guidelines, and internationally accepted Fair Information Practices.
General Skills
- Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements.
- Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence, particularly as it relates to the Information and Privacy Commissioner of Ontario, and risk countermeasures.
- Experience in conducting Privacy Impact Assessments in a public-sector context.
- Knowledge of, and experience with privacy-enhancing best practices.
- Knowledge and ability to interpret and apply Ontario’s Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent, the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA), their respective regulations, and related jurisprudence.
- Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act.
Policy Knowledge
- Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services.
- Valuable understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, and project management.
Operational Program And Business Design Skills
- Ability to lead, manage, or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization.
- Knowledge and ability to create and understand data flow diagrams and business process diagrams.
- Ability to recognize the need for, and seek input from external experts as required.
- Excellent communication skills with technical and business audiences and non-access and privacy experts.
Technology and Systems Knowledge
- Analytical skills to understand the current and future access and privacy implications of policies, decisions, and business initiatives.
- Knowledge of Information Technology concepts and processes that impact the protection of personal information, including, but not limited to, Internet tools, system interfaces, information security, information architecture, and data flows.
Information and Record Keeping Knowledge
- Experience in developing risk assessment tools, methodologies, policies, and procedures to effectively manage personal information.
- Knowledge of policies, directives, standards, business rules, procedures, and guidelines relating to records management, including classification, retention, and disposition of information.
- Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards.
Desirable Skills
- Professional certification from a related discipline such as IT security or architecture.
- Experience providing education and training related to privacy.
- Knowledge of, and experience with, the policies and procedures of the Ontario government, such as business case development, project approvals, and policy development.
Experience And Skill Set Requirements Privacy Assessment Experience, Policy and Legislative Requirements – 40%
- Experience with privacy legislation including Freedom of Information and Protection of Privacy Act (FIPPA), Personal Health Information Protection Act (PHIPA), and Personal Information Protection and Electronic Documents Act (PIPEDA).
- Experience in conducting privacy assessments involving personal information, citing examples in the resume.
- Experience in leading and conducting privacy assessments involving online and/or digital solutions.
- Experience leading and conducting assessments involving personal health information involving third-party solutions, such as private-sector or non-profit application solutions, and/or service integration providers.
- Experience working with policy development teams; reviewing and comparing policies and legislation to make informed recommendations to ensure adequate privacy protections and considerations are addressed within policy/legislation.
Technical Understanding – 30%
- Experience with privacy risks and conducting PIAs and the unique security and privacy challenges associated with various platforms.
- Demonstrated experience and familiarity with strong security, encryption, and privacy protection approaches to digital solutions, including web-based and backend integrations via API or similar approaches.
- Experience with privacy risks and conducting PIAs associated with integration between legacy systems, web applications, digital and cloud-based solutions to obtain, retrieve, and synchronize information.
- Familiarity with cloud-based technologies, including the security and privacy considerations, limitations, and best practices for data protection.
- Experience, knowledge, and understanding of privacy protection standards and best practices, business, information and security architecture principles, and emerging technology related to the protection of privacy and personal information.
Leadership and Communications – 20%
- Demonstrated strong communication and engagement skills with ability to lead teams in discovery sessions to elicit details of technical solutions, business processes and/or policies, with strong writing skills to document findings, recommendations, etc.
- Demonstrated ability to interpret both technical, such as architecture design documents, process flows, and state transition diagrams, and non-technical documentation to conduct assessment of impacts and to develop mitigation strategies.
- Strong organizational and time management skills to manage multiple and concurrent requests in an agile and highly dynamic work environment setting.
- Strong presentation abilities to communicate findings, recommendations, etc. to senior management and executives to inform decision making; able to communicate complex problems/issues in simple terms.
Digital Identity Frameworks and Standards – 5%
- Experience in developing, applying, and/or evaluating digital identity trust frameworks.
OPS Experience – 5%
- Prior experience with leading and conducting multiple PIAs in OPS setting/environment, including demonstrated knowledge and experience with OPS processes, existing templates, and expectations to obtain approvals/sign-off.
How To Apply If you are interested in this opportunity and your profile matches the requirements, please send the following mandatory documents to
[email protected] by Wednesday, September 30, 2026, 10:00 AM EST :
- Updated Resume in Word format – Mandatory
- References – Mandatory
- Expected Hourly Rate – Mandatory
- Visa Status – Mandatory
- LinkedIn ID – Mandatory
Without the mandatory documents, we cannot submit a candidate. Please ensure your resume clearly demonstrates relevant experience in privacy legislation, Privacy Impact Assessments, privacy risk assessment, digital and cloud-based solutions, information security, data flows, privacy protection standards, and OPS/Public Sector environments . WhatsApp Group For daily job updates, you can also join our WhatsApp group.
Join our WhatsApp Group
Note
- Work Arrangement: Onsite
- 5 days onsite
- Email is the best way to reach us.
If you are interested in learning more about this opportunity, or if you know someone who may be a good fit, please feel free to share or forward this opportunity. Please check our career site for additional opportunities.
You have received this message either as a result of contacting our company to express interest in employment or as a result of posting your resume in a location that can be accessed by recruiters or HR specialists, which suggests an interest in being contacted about employment opportunities.
📌 Privacy Impact Assessment (PIA) Specialist – Senior (Toronto)
🏢 S M Software Solutions
📍 Toronto