The Privacy Consultant will lead privacy impact assessments support compliance with privacy and security legislation and provide expert consultation on privacy protection strategies for Personal Health Information (PHI). The role requires extensive experience in privacy impact methodologies policy analysis and risk assessment in large complex public-sector environments.
Key ResponsibilitiesPrivacy Impact Assessments (PIA):
Develop conduct and review Privacy Impact Assessments for proposed solutions and business processes.
Recommend mitigation strategies and privacy-enhancing technologies in alignment with PIA procedures.
Privacy and Security Strategy:
Lead the development of access and privacy tools and security mechanisms for PHI collection storage access and disclosure.
Ensure compliance with privacy and security best practices including PHIPA (2004).
Stakeholder Engagement:
Facilitate privacy-related discussions with business IT legal and privacy stakeholders across ministries and agencies.
Provide expert advice to project teams senior management and ministry leadership on privacy legislation regulations and policy.
Policy and Program Analysis:
Examine complex programs and systems to assess information flows governance structures and PHI protection.
Analyze and advise on Freedom of Information (FOI) and privacy implications of new technologies policies and information systems.
Identify emerging privacy and FOI issues recommend policy updates and develop mitigation strategies.
Documentation and Reporting:
Prepare detailed reports options analyses briefing notes and presentations for executive and governance committees.
Develop business processes and procedures describing how PHI is collected used disclosed and retained.
Change Management and Communication:
Support change management initiatives related to privacy processes.
Coordinate across branches to prepare communications briefing materials and presentations.
10 years of experience in:
Privacy impact assessment methodologies tools and techniques
Threat and risk analysis business analysis and program evaluation
Policy development for information management and privacy protection
Managing privacy risks in PHI collection use and disclosure
Implementing privacy best practices and compliance frameworks
Understanding IT concepts related to information protection (e.g. security architecture data flows electronic service delivery)
10 years of experience:
Resolving complex privacy and policy issues
Analyzing policy proposals and assessing IT and business implications
Applying legislation regulations and directives to new initiatives
Identifying emerging privacy trends impacting government policy
Preparing comprehensive reports analyses and executive materials
Consulting and negotiating to gain stakeholder alignment
Building effective relationships with senior management and partners
Strong leadership and stakeholder management skills
Exceptional analytical problem-solving and decision-making abilities
Excellent communication (oral written and presentation) skills
Strong consulting facilitation and negotiation skills
Proven ability to manage multiple priorities and meet deadlines
High degree of professionalism flexibility and attention to detail
5 years of experience within federal/provincial/broader public-sector healthcare
Knowledge of:
Ontario privacy and de-identification guidelines (IPC GO-ITS PHIPA)
Public Sector I&IT project methodologies gating and governance processes
Public Sector Enterprise Architecture and digital health standards
Experience supporting large complex IT health-related projects
10 years of experience in:
Policy development for information management and privacy protection
Managing privacy risks in PHI collection use and disclosure
Identifying and evaluating emerging privacy issues and trends affecting government policy
Preparing reports options analyses and presentations on privacy matters