NeverHard

Privacy Impact Assessment (PIA) Specialist at Cleo Consulting — NeverHard

Privacy Impact Assessment (PIA) Specialist at Cleo Consulting in Regent Park, City of Toronto. Skills: Business Architecture, Freedom of Information, IT Security, Privacy, Privacy Impact Assessments. Apply on NeverHard.

Company
Cleo Consulting
Location
Regent Park, City of Toronto
Type
contract

Required skills:

Assignment: RQ11096 - Privacy Impact Assessment (PIA) Specialist - Senior Job Title: Privacy Impact Assessment (PIA) Specialist Requisition (SS): RQ11096 Start Date: 2026-07-03 Client: Land & Resources Cluster End Date: 2026-08-10 Office Location: 40 St Clair St W, 14th Floor Organization: Land & Resources Cluster Ministry: Ministry of Public and Business Service Delivery and Procurement # Business Days: 30.00 Assignment Type: Onsite Must Haves: Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures Experience in conducting Privacy Impact Assessments in public sector context Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services; Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management. Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization Description Scope & Responsibilities: Required to lead the development of a privacy impact assessment that evaluates whether new technologies, information systems, or proposed programs or policies meet legal and policy privacy requirements, determine and mitigate risks, and address clients' concerns. These requirements include ensuring that the program complies with provincial, municipal, federal and private sector access and privacy legislation, as well as relevant regulations, statutes, OPS policies, Directives, standards, guidelines and internationally accepted Fair Information Practices. Experience and Skill Set Requirements General Skills - 25% Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures Experience in conducting Privacy Impact Assessments in public sector context Knowledge of, and experience with privacy enhancing best practices Knowledge and ability to interpret and apply Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act Policy Knowledge - 50% Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services; Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management. Operational Program and Business Design Skills Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization Knowledge and ability to create and understand data flow diagrams and business process diagrams Ability to recognize the need for, and seek input from external experts as required Excellent communication skills with technical and business audiences and non- access and privacy experts. Technology and Systems Knowledge - 20% Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows Information and Record Keeping Knowledge Experience in developing risk assessment tools, methodologies, policies and procedures to effectively manage personal information Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards Public Sector Experience - 5% Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards Experience in conducting Privacy Impact Assessments in public sector context Knowledge of, and experience with privacy enhancing best practices Knowledge and ability to interpret and apply Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act