This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a highly specialized Senior Privacy Impact Assessment (PIA) Specialist for a strategic 3-month contract in Toronto. This role is critical for evaluating new technologies and digital health solutions to ensure they meet stringent provincial and federal privacy requirements. You will be responsible for identifying privacy risks, determining mitigation strategies, and ensuring compliance within a complex, multi-stakeholder environment.
Job Responsibility:
Privacy Leadership: Lead the development of comprehensive Privacy Impact Assessments (PIAs) for new technologies, information systems, and proposed policies
Risk Mitigation: Identify and evaluate privacy risks associated with personal information (PI) and personal health information (PHI), providing actionable recommendations to bridge compliance gaps
Technical Analysis: Interpret complex technical documentation, including architecture design documents, API integration flows, and cloud-based data structures, to assess privacy impacts
Stakeholder Engagement: Lead discovery sessions with technical teams, business architects, and senior executives to elicit details of business processes and digital solutions
Policy Alignment: Review and compare internal policies against provincial (FIPPA, PHIPA), federal (PIPEDA), and international privacy standards to ensure adequate protection
Reporting: Document findings and present high-level risk mitigation strategies to senior management to inform critical decision-making
Requirements:
Expert Legislative Knowledge: Deep expertise in FIPPA, PHIPA, and PIPEDA, including an understanding of Information and Privacy Commissioner (IPC) jurisprudence
Proven PIA Track Record: Minimum 7+ years of experience leading and conducting PIAs involving digital/online solutions and third-party service providers
Digital Integration Skills: Demonstrated experience assessing privacy risks in backend integrations (APIs), cloud-based platforms, and web applications
Technical Literacy: Ability to create and interpret data flow diagrams (DFDs) and business process diagrams to track the lifecycle of personal information
Security Awareness: Strong understanding of encryption standards, identity trust frameworks, and information security architecture principles
Communication Excellence: Superior writing and presentation skills, with the ability to translate complex technical privacy issues into plain language for non-experts
What we offer:
Strategic Impact: Influence the privacy posture of high-profile digital identity and health initiatives
Complex Tech Stack: Gain experience assessing modern integrations involving cloud solutions, APIs, and legacy system synchronizations
Professional Visibility: Work directly with senior executives and policy leaders in a highly dynamic public sector environment
Potential for Extension: While the initial term is 3 months, there is a strong potential for the contract to be extended based on project needs