Back to jobs
ScovaiScovaiJobs
Upstaff

Upstaff

Senior Privacy Impact Assessment (PIA) Specialist

Toronto, CAOn-siteContractFull-time

Posted Sep 25, 2026

Assignment: Privacy Impact Assessment (PIA) Specialist – Senior
Client: Government Services Integration Cluster, Ministry of Public and Business Service Delivery and Procurement
Location: Toronto, ON – 20 Dundas St W
Work Arrangement: 100% Onsite – 5 days per week
Contract: October 1, 2026 – March 31, 2027
Openings: 1
Security Clearance: No clearance required
Closing Date: September 30, 2026 at 12:00 PM EST
Maximum Submissions: 1 candidate
Position Overview
The Government Services Integration Cluster is seeking a Senior Privacy Impact Assessment (PIA) Specialist to lead and/or support Privacy Impact Assessments for new technologies, information systems, digital solutions, programs, policies, and services.
The successful candidate will evaluate privacy compliance and risks, identify appropriate mitigation strategies, and work with technical, business, policy, security, and other stakeholders to ensure appropriate privacy protections are incorporated.
The role requires strong knowledge of Ontario privacy legislation, public-sector privacy practices, digital technologies, information security, data flows, risk management, and OPS PIA processes.
Key Responsibilities
  • Lead or support the development and completion of Privacy Impact Assessments independently or as part of a team.
  • Evaluate proposed technologies, information systems, programs, policies, and digital solutions against applicable privacy requirements.
  • Identify privacy risks and develop appropriate mitigation strategies and recommendations.
  • Research and interpret applicable privacy legislation, regulations, jurisprudence, policies, directives, standards, and guidelines.
  • Assess privacy implications associated with online and digital solutions.
  • Conduct assessments involving personal health information and third-party solutions, including private-sector, non-profit, and service-integration providers.
  • Work with policy development teams to review and compare policies and legislation and provide recommendations for appropriate privacy protections.
  • Lead discovery sessions and gather information from technical and business stakeholders.
  • Interpret technical documentation such as architecture designs, process flows, and state-transition diagrams.
  • Create and interpret data-flow diagrams and business-process diagrams.
  • Assess privacy implications of system interfaces, APIs, information architecture, data flows, cloud solutions, and integrations.
  • Develop and apply risk assessment tools, methodologies, policies, and procedures for protecting personal information.
  • Provide privacy-related education and training where required.
  • Communicate findings, risks, recommendations, and mitigation strategies to senior management and executives.
  • Manage multiple concurrent PIA requests in an agile and dynamic environment.
  • Seek input from external subject-matter experts where required.
  • Support privacy approvals, sign-offs, and related OPS processes.


Requirements

Mandatory Qualifications & Experience
1. Privacy Legislation & PIA Experience – 40%
Candidates must demonstrate:
  • Strong experience with privacy legislation, including:
    • Freedom of Information and Protection of Privacy Act (FIPPA)
    • Personal Health Information Protection Act (PHIPA)
    • Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Demonstrated experience conducting privacy assessments involving personal information, with specific examples clearly documented in the resume.
  • Demonstrated experience leading and conducting privacy assessments involving online and/or digital solutions.
  • Demonstrated experience leading and conducting assessments involving personal health information and third-party solutions, such as private-sector/non-profit applications and/or service integration providers.
  • Experience working with policy-development teams and reviewing/comparing policies and legislation to make informed recommendations concerning privacy protections.
2. Technical Understanding – 30%
Candidates must demonstrate:
  • Experience identifying privacy risks and conducting PIAs across different technology platforms.
  • Strong understanding of security, encryption, privacy protection, and data-protection approaches for digital solutions.
  • Experience assessing web-based solutions and backend integrations using APIs or similar technologies.
  • Experience assessing privacy risks associated with integrations between:
    • Legacy systems
    • Web applications
    • Digital solutions
    • Cloud-based solutions
  • Experience with cloud technologies and an understanding of their security and privacy considerations, limitations, and data-protection best practices.
  • Knowledge of privacy protection standards and best practices.
  • Understanding of business, information, and security architecture principles.
  • Awareness of emerging technologies and their implications for protecting privacy and personal information.
3. Leadership & Communication – 20%
Candidates must demonstrate:
  • Strong communication and stakeholder-engagement skills.
  • Ability to lead discovery sessions and elicit information regarding technical solutions, business processes, and policies.
  • Strong written communication skills for documenting assessment findings, risks, recommendations, and mitigation strategies.
  • Ability to interpret both technical and non-technical documentation.
  • Ability to translate technical and complex privacy issues into practical recommendations.
  • Strong organizational and time-management skills.
  • Ability to manage multiple concurrent requests in a dynamic and agile environment.
  • Strong presentation skills, including the ability to communicate findings and recommendations to senior management and executives in clear, understandable language.
4. Digital Identity Frameworks & Standards – 5%
  • Experience developing, applying, and/or evaluating digital identity trust frameworks.
5. Ontario Public Service Experience – 5%
  • Prior experience leading and conducting multiple PIAs within an Ontario Public Service (OPS) environment.
  • Demonstrated knowledge and experience with OPS PIA processes, existing templates, expectations, approvals, and sign-off requirements.
Additional Required Knowledge
The successful candidate should also have:
  • Excellent knowledge of privacy and security concepts, trends, and issues.
  • Ability to interpret and communicate privacy principles and compliance requirements to technical and non-technical audiences.
  • Knowledge and experience researching and applying privacy laws, regulations, jurisprudence, and risk countermeasures.
  • Knowledge of privacy-enhancing best practices.
  • Knowledge of MFIPPA – Municipal Freedom of Information and Protection of Privacy Act.
  • Knowledge of PHIPA and its regulations and related jurisprudence.
  • Familiarity with PIPEDA and the US PATRIOT Act.
  • Familiarity with the OPS Privacy Impact Assessment Process and Tools.
  • Understanding of related disciplines including:
    • IT Security
    • IT/System Design
    • Privacy/Security Policy Development
    • Business Architecture
    • Legal Processes
    • Freedom of Information Administration
    • Business Analysis
    • Risk Management
    • Project Management
  • Knowledge of information and records-management practices, including classification, retention, and disposition.
  • Knowledge of Accessibility for Ontarians with Disabilities Act (AODA) and related regulations and standards.
Nice-to-Have Qualifications
  • Professional certification in a related discipline such as IT Security or Architecture.
  • Experience providing privacy education and training.
  • Experience with Ontario Government policies and procedures, including:
    • Business case development
    • Project approvals
    • Policy development
  • Previous OPS/public-sector experience.
Critical Must-Have Screening Criteria
Recruiters should not submit candidates who cannot clearly demonstrate the following four areas in their resume:
  1. FIPPA, PHIPA and PIPEDA experience
  2. Hands-on experience conducting privacy assessments involving personal information
  3. Experience leading/conducting PIAs for online and/or digital solutions
  4. Experience conducting assessments involving personal health information and third-party solutions/service-integration providers
Preferred
  • OPS or broader public-sector experience.
Work Arrangement & Contract Details
  • Location: 20 Dundas St W, Toronto, Ontario
  • Onsite: 5 days per week
  • Contract: October 1, 2026 to March 31, 2027
  • Extension: One possible extension term
  • Openings: 1
  • Allocation: 100%
  • Security Clearance: No clearance required
  • Submission Limit: Maximum 1 candidate
  • Closing: September 30, 2026 at 12:00 PM EST


Role snapshot

Job type

Full-time

Required skills

Privacy Impact Assessment (PIA) methodologyFreedom of Information and Protection of Privacy Act (FIPPA) knowledgePersonal Health Information Protection Act (PHIPA) knowledgePersonal Information Protection and Electronic Documents Act (PIPEDA) knowledgeAssessing privacy for personal health information (PHI) and third‑party/service integration providersPrivacy risk identification and mitigation developmentInterpreting technical architecture, system interfaces and APIs for privacy implicationsCreating and interpreting data-flow diagrams and business-process diagramsCloud solutions privacy and security assessmentSecurity, encryption and privacy-protection best practices for digital solutionsStakeholder engagement, facilitation and presenting findings to senior managementFacilitating discovery sessions and eliciting technical/business requirementsResearching and interpreting privacy legislation, regulations and jurisprudenceKnowledge of OPS PIA processes, templates, approvals and sign-off requirementsDeveloping, applying or evaluating digital identity trust frameworks

Similar jobs

Upstaff

Senior Solutions Designer – Oracle Siebel / Adobe AEM

Upstaff

Toronto, CAOn-siteContractFull-time
6 hours ago
Upstaff

Senior Systems Testing / QA Specialist – Senior

Upstaff

Toronto, CAOn-siteContractFull-time
yesterday
Upstaff

Senior Software Developer – MS Dynamics 365 CRM

Upstaff

Toronto, CAOn-siteContractFull-time
yesterday
Upstaff

Senior Systems Administrator / Operations Support Specialist – Siebel CRM

Upstaff

Toronto, CAOn-siteContractFull-time
3 days ago
Maarut

Senior KDB Developer

Maarut

Toronto, CAOn-siteContractFull-time
7 hours ago
Maarut

GW ClaimCenter-Mitchell integration

Maarut

Toronto, CAOn-siteContractFull-time
7 hours ago