Enter a job title or keyword

Privacy Impact Assessment (PIA) Specialist – Intermediate

Upstaff


Job Location:

Toronto - Canada

Monthly Salary: Not provided by the employer
Posted: 16 September 2026 (2 days ago)
Application Deadline: 14 December 2026
Vacancies: 1 Vacancy

Job Summary

Client: Government of Ontario Central Agencies Cluster
Ministry: Ministry of Treasury Board Secretariat
Location: 222 Jarvis Street Toronto ON
Work Arrangement: 100% Onsite Monday to Friday
Start Date: September 28 2026
End Date: November 18 2026
Extension: Up to 2 days / maximum 1 extension term
Openings: 1
Security Clearance: No clearance required
Position Overview
The Government of Ontario is seeking an experienced Privacy Impact Assessment (PIA) Specialist Intermediate to lead and/or support the development of Privacy Impact Assessments for new technologies information systems digital solutions programs policies and business initiatives.
The successful candidate will assess privacy implications identify and mitigate privacy risks and ensure compliance with applicable provincial municipal federal and private-sector privacy legislation regulations statutes OPS policies directives standards guidelines and internationally accepted Fair Information Practices.
The resource must have demonstrated experience conducting PIAs involving personal information and digital/online solutions with strong knowledge of Ontario privacy legislation and prior experience conducting multiple PIAs within an Ontario Public Service (OPS) environment.
Key Responsibilities
  • Lead or support the development and completion of Privacy Impact Assessments (PIAs) independently or as part of a team.
  • Assess new technologies information systems online/digital solutions programs policies and business initiatives for privacy implications.
  • Identify privacy risks and develop appropriate mitigation strategies and recommendations.
  • Research interpret and apply applicable privacy legislation regulations jurisprudence policies directives standards and guidelines.
  • Ensure privacy requirements are appropriately incorporated into business processes policies technology solutions and system designs.
  • Conduct privacy assessments involving the collection use disclosure retention storage transfer and protection of personal information.
  • Lead and conduct PIAs involving online and/or digital solutions.
  • Evaluate privacy risks associated with web-based applications backend integrations APIs cloud technologies legacy systems and system-to-system information exchange.
  • Work with policy development teams to review and compare legislation and policies and provide recommendations to strengthen privacy protections.
  • Gather information and requirements from business technical legal security architecture and other stakeholders.
  • Lead discovery sessions to understand technical solutions business processes information flows and privacy requirements.
  • Create and interpret data flow diagrams and business process diagrams.
  • Review technical documentation such as architecture designs process flows state transition diagrams system interfaces and related documentation.
  • Develop clear assessment findings recommendations mitigation strategies and supporting documentation.
  • Communicate privacy findings and recommendations to technical and non-technical stakeholders senior management and executives.
  • Manage multiple concurrent privacy assessment requests in an agile and highly dynamic environment.
  • Recognize when external privacy legal security or technical expertise is required and obtain appropriate input.
  • Support privacy education and awareness activities where required.
  • Ensure appropriate OPS processes templates approvals and sign-off requirements are followed.


Requirements
Mandatory Skills & Experience
1. Privacy Legislation Assessment & Policy 40%
Candidates must demonstrate:
  • Experience with privacy legislation including:
    • Freedom of Information and Protection of Privacy Act (FIPPA)
    • Personal Health Information Protection Act (PHIPA)
    • Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Experience conducting Privacy Impact Assessments involving personal information with specific examples clearly identified in the resume.
  • Experience leading and conducting privacy assessments involving online and/or digital solutions.
  • Experience working with policy development teams and reviewing/comparing policies and legislation to make informed recommendations.
  • Knowledge of privacy principles compliance requirements privacy-enhancing practices and risk countermeasures.
  • Knowledge of relevant privacy laws regulations jurisprudence and particularly matters relating to the Information and Privacy Commissioner of Ontario (IPC).
2. Technical & Privacy Risk Understanding 30%
Candidates must demonstrate:
  • Experience identifying and assessing privacy risks and conducting PIAs across different technology platforms.
  • Understanding of security encryption privacy protection and data protection approaches for digital solutions.
  • Experience assessing privacy and security considerations for:
    • Web-based applications
    • Backend integrations
    • APIs and similar integration approaches
    • Legacy systems
    • Digital solutions
    • Cloud-based solutions
  • Experience assessing privacy risks associated with systems that obtain retrieve exchange and synchronize information.
  • Familiarity with cloud-based technologies including privacy/security considerations limitations and data protection best practices.
  • Knowledge of privacy protection standards and best practices.
  • Understanding of business architecture information architecture security architecture and emerging technologies affecting privacy and personal information.
  • Knowledge of IT concepts and processes affecting protection of personal information including:
    • Internet technologies
    • System interfaces
    • Information security
    • Information architecture
    • Data flows
3. Leadership & Communication 20%
Candidates must demonstrate:
  • Strong communication and stakeholder engagement skills.
  • Ability to lead discovery sessions and elicit information regarding:
    • Technical solutions
    • Business processes
    • Policies
    • Information flows
  • Strong written communication skills for documenting assessments findings recommendations risks and mitigation strategies.
  • Ability to interpret both technical and non-technical documentation.
  • Ability to develop practical privacy mitigation strategies.
  • Strong organizational and time-management skills.
  • Demonstrated ability to manage multiple concurrent requests in an agile and highly dynamic environment.
  • Strong presentation skills and the ability to communicate findings and recommendations to senior management and executives.
  • Ability to explain complex privacy security and technical issues in clear and simple terms.
4. Ontario Public Service Experience 10%
This is a key mandatory requirement.
Candidates must demonstrate:
  • Prior experience leading and conducting multiple PIAs within an Ontario Public Service (OPS) setting/environment.
  • Demonstrated knowledge and practical experience with OPS privacy processes existing PIA templates requirements expectations approval processes and sign-off procedures.
  • Familiarity with Ontario government policies directives standards and procedures relevant to privacy and information management.
Additional Required Knowledge
The successful candidate should also possess:
  • Knowledge and ability to interpret and apply:
    • FIPPA
    • MFIPPA
    • PHIPA
    • Related regulations and jurisprudence
  • Familiarity with PIPEDA and the US PATRIOT Act.
  • Familiarity with OPS Privacy Impact Assessment processes and tools released by the Ontario Ministry of Government Services.
  • Knowledge of records and information management including:
    • Classification
    • Retention
    • Disposition
    • Records-related policies directives standards business rules procedures and guidelines
  • Experience developing risk assessment tools methodologies policies and procedures for effectively managing personal information.
  • Understanding of the Accessibility for Ontarians with Disabilities Act (AODA) and related regulations and standards.
  • Understanding of related disciplines including:
    • IT security
    • IT/system design
    • Privacy/security policy development
    • Business architecture
    • Legal processes
    • Freedom of Information administration
    • Business analysis
    • Risk management
    • Project management
Nice-to-Have Qualifications
  • Professional certification in a related discipline such as:
    • IT Security
    • Information/Technology Architecture
    • Privacy
    • Information Management
  • Experience providing privacy education and training.
  • Knowledge and experience with Ontario government policies and procedures including:
    • Business case development
    • Project approvals
    • Policy development
    • OPS governance processes
  • Experience interpreting architecture design documents process flows and state transition diagrams.
  • Experience with cloud-based technologies and associated privacy/security considerations.
Work Environment
This is a 100% onsite position at the Ontario Public Service office located at:
222 Jarvis Street Toronto Ontario
The successful candidate is expected to work:
  • Monday to Friday
  • 7.25 hours per calendar day excluding lunch
  • Within standard working hours of 8:00 AM5:00 PM
Critical Candidate Requirements
Before submission candidates should be able to clearly demonstrate the following on their resume:
  1. FIPPA experience
  2. PHIPA experience
  3. PIPEDA experience
  4. Multiple Privacy Impact Assessments involving personal information
  5. PIAs involving online/digital solutions
  6. Privacy risk assessment experience
  7. Experience with security/privacy challenges across technology platforms
  8. Experience with web applications backend integrations and/or APIs
  9. Experience with legacy digital and/or cloud-based systems
  10. Multiple PIAs conducted within an OPS environment
  11. Knowledge of OPS PIA processes templates approvals and sign-off
  12. Ability to manage multiple concurrent PIA requests
  13. Strong stakeholder engagement and communication skills
  14. Ability to interpret technical and non-technical documentation
  15. Ability to develop privacy mitigation strategies and recommendations
Submission Limit: Maximum 1 candidate.
Important: Candidates who do not clearly demonstrate the mandatory privacy legislation PIA digital-solution and OPS PIA experience requirements in their resume should not be submitted.




Required Skills:

Mandatory Skills & Experience 1. Privacy Legislation Assessment & Policy 40% Candidates must demonstrate: Experience with privacy legislation including: Freedom of Information and Protection of Privacy Act (FIPPA) Personal Health Information Protection Act (PHIPA) Personal Information Protection and Electronic Documents Act (PIPEDA) Experience conducting Privacy Impact Assessments involving personal information with specific examples clearly identified in the resume. Experience leading and conducting privacy assessments involving online and/or digital solutions. Experience working with policy development teams and reviewing/comparing policies and legislation to make informed recommendations. Knowledge of privacy principles compliance requirements privacy-enhancing practices and risk countermeasures. Knowledge of relevant privacy laws regulations jurisprudence and particularly matters relating to the Information and Privacy Commissioner of Ontario (IPC). 2. Technical & Privacy Risk Understanding 30% Candidates must demonstrate: Experience identifying and assessing privacy risks and conducting PIAs across different technology platforms. Understanding of security encryption privacy protection and data protection approaches for digital solutions. Experience assessing privacy and security considerations for: Web-based applications Backend integrations APIs and similar integration approaches Legacy systems Digital solutions Cloud-based solutions Experience assessing privacy risks associated with systems that obtain retrieve exchange and synchronize information. Familiarity with cloud-based technologies including privacy/security considerations limitations and data protection best practices. Knowledge of privacy protection standards and best practices. Understanding of business architecture information architecture security architecture and emerging technologies affecting privacy and personal information. Knowledge of IT concepts and processes affecting protection of personal information including: Internet technologies System interfaces Information security Information architecture Data flows 3. Leadership & Communication 20% Candidates must demonstrate: Strong communication and stakeholder engagement skills. Ability to lead discovery sessions and elicit information regarding: Technical solutions Business processes Policies Information flows Strong written communication skills for documenting assessments findings recommendations risks and mitigation strategies. Ability to interpret both technical and non-technical documentation. Ability to develop practical privacy mitigation strategies. Strong organizational and time-management skills. Demonstrated ability to manage multiple concurrent requests in an agile and highly dynamic environment. Strong presentation skills and the ability to communicate findings and recommendations to senior management and executives. Ability to explain complex privacy security and technical issues in clear and simple terms. 4. Ontario Public Service Experience 10% This is a key mandatory requirement. Candidates must demonstrate: Prior experience leading and conducting multiple PIAs within an Ontario Public Service (OPS) setting/environment. Demonstrated knowledge and practical experience with OPS privacy processes existing PIA templates requirements expectations approval processes and sign-off procedures. Familiarity with Ontario government policies directives standards and procedures relevant to privacy and information management. Additional Required Knowledge The successful candidate should also possess: Knowledge and ability to interpret and apply: FIPPA MFIPPA PHIPA Related regulations and jurisprudence Familiarity with PIPEDA and the US PATRIOT Act. Familiarity with OPS Privacy Impact Assessment processes and tools released by the Ontario Ministry of Government Services. Knowledge of records and information management including: Classification Retention Disposition Records-related policies directives standards business rules procedures and guidelines Experience developing risk assessment tools methodologies policies and procedures for effectively managing personal information. Understanding of the Accessibility for Ontarians with Disabilities Act (AODA) and related regulations and standards. Understanding of related disciplines including: IT security IT/system design Privacy/security policy development Business architecture Legal processes Freedom of Information administration Business analysis Risk management Project management Nice-to-Have Qualifications Professional certification in a related discipline such as: IT Security Information/Technology Architecture Privacy Information Management Experience providing privacy education and training. Knowledge and experience with Ontario government policies and procedures including: Business case development Project approvals Policy development OPS governance processes Experience interpreting architecture design documents process flows and state transition diagrams. Experience with cloud-based technologies and associated privacy/security considerations. Work Environment This is a 100% onsite position at the Ontario Public Service office located at: 222 Jarvis Street Toronto Ontario The successful candidate is expected to work: Monday to Friday 7.25 hours per calendar day excluding lunch Within standard working hours of 8:00 AM5:00 PM Critical Candidate Requirements Before submission candidates should be able to clearly demonstrate the following on their resume: FIPPA experience PHIPA experience PIPEDA experience Multiple Privacy Impact Assessments involving personal information PIAs involving online/digital solutions Privacy risk assessment experience Experience with security/privacy challenges across technology platforms Experience with web applications backend integrations and/or APIs Experience with legacy digital and/or cloud-based systems Multiple PIAs conducted within an OPS environment Knowledge of OPS PIA processes templates approvals and sign-off Ability to manage multiple concurrent PIA requests Strong stakeholder engagement and communication skills Ability to interpret technical and non-technical documentation Ability to develop privacy mitigation strategies and recommendations Submission Limit: Maximum 1 candidate. Important: Candidates who do not clearly demonstrate the mandatory privacy legislation PIA digital-solution and OPS PIA experience requirements in their resume should not be submitted.


Required Education:

Bachelors degree or equivalent in a related discipline such as IT Security Information/Technology Architecture Privacy Information Management Computer Science Information Technology Business Analysis Risk Management or a related Professional certification in IT Security Information/Technology Architecture Privacy or Information Management.