Privacy Impact Assessment (PIA) Specialist at Cleo Consulting — NeverHard
Privacy Impact Assessment (PIA) Specialist at Cleo Consulting in Regent Park, City of Toronto. Skills: Business Architecture, Freedom of Information, IT Security, Privacy, Privacy Impact Assessments. Apply on NeverHard.
Company
Cleo Consulting
Location
Regent Park, City of Toronto
Type
contract
Required skills:
Business Architecture
Freedom of Information
IT Security
Privacy
Privacy Impact Assessments
Records Management
Security
data privacy laws
Assignment: RQ11096 - Privacy Impact Assessment (PIA) Specialist - Senior
Job Title: Privacy Impact Assessment (PIA) Specialist
Requisition (SS): RQ11096
Start Date: 2026-07-03
Client: Land & Resources Cluster
End Date: 2026-08-10
Office Location: 40 St Clair St W, 14th Floor
Organization: Land & Resources Cluster
Ministry: Ministry of Public and Business Service Delivery and Procurement
# Business Days: 30.00
Assignment Type: Onsite
Must Haves:
Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements
Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures
Experience in conducting Privacy Impact Assessments in public sector context
Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information
Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services;
Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management.
Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization
Description
Scope & Responsibilities:
Required to lead the development of a privacy impact assessment that evaluates whether new technologies, information systems, or proposed programs or policies meet legal and policy privacy requirements, determine and mitigate risks, and address clients' concerns.
These requirements include ensuring that the program complies with provincial, municipal, federal and private sector access and privacy legislation, as well as relevant regulations, statutes, OPS policies, Directives, standards, guidelines and internationally accepted Fair Information Practices.
Experience and Skill Set Requirements
General Skills - 25%
Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements
Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures
Experience in conducting Privacy Impact Assessments in public sector context
Knowledge of, and experience with privacy enhancing best practices
Knowledge and ability to interpret and apply Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence
Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act
Policy Knowledge - 50%
Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services;
Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management.
Operational Program and Business Design Skills
Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization
Knowledge and ability to create and understand data flow diagrams and business process diagrams
Ability to recognize the need for, and seek input from external experts as required
Excellent communication skills with technical and business audiences and non- access and privacy experts.
Technology and Systems Knowledge - 20%
Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives
Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows
Information and Record Keeping Knowledge
Experience in developing risk assessment tools, methodologies, policies and procedures to effectively manage personal information
Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information
Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards
Public Sector Experience - 5%
Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards
Experience in conducting Privacy Impact Assessments in public sector context
Knowledge of, and experience with privacy enhancing best practices
Knowledge and ability to interpret and apply Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence
Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act