Interested in this role?Maarut • Toronto, Ontario
Apply Now
Website Maarut
Description:
- To guide, influence and lead planning and development of
Privacy Impact Assessment (PIA) that evaluates whether new technologies,
information systems or proposed / policies meet legal privacy requirements and
address client concerns. - Requirements include ensuring program complies with FIPPA,
PIPEDA, PHIPA and other privacy laws (provincial, federal, municipal) as well
as applicable regulations, program statutes, Management Board of Cabinet
Directives, corporate policies and internationally established Fair Information
Practices. May involve work with other jurisdictions and the broader public
sector.
Major Responsibilities:
- Knowledge and ability to interpret and apply Ontario’s
Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal
equivalent the Municipal Freedom of Information and Protection of Privacy Act
(MFIPPA), Personal Health Information Protection Act (PHIPA) their respective
regulations and related jurisprudence. - Provides consultative advice and guidance on laws,
regulations, policies, standards, or procedures to clusters & ministries,
management, personnel, or key groups. - Leads the development of a privacy impact assessment that
evaluates whether new technologies, information systems, or proposed programs
or policies meet legal and policy privacy requirements, determines and
mitigates risks, and addresses clients’ concerns. - Manages PIA service resource utilization, workload
management and manage PIA intake queue to optimize resource allocation. - Provides guidance and leadership to staff with the
responsibility to plan work, set objectives, direct the work of staff while
managing unexpected changes to deadlines and work demands. - Leads client stakeholder management as primary point of
contact of IT clients, providing strategic advice on project provisioning,
policy and to make informed business decisions. - Leads and/or participates on cross-cluster/IPC/Ministry
research teams and working committees mandated to review/implement key
strategic FOI/Privacy I & IT commitments. - Analyzes policy proposals from ministries and cabinet
submissions, to assess/evaluate I & IT implications and to develop privacy
strategy and planning approaches.
Requirements
Experience and Skill Set Requirements:
Must have:
- Excellent
knowledge of privacy and security concepts, trends, and issues. - This
will include an understanding of their impact on business processes, as
well as ability to interpretation and communicate principles and
compliance requirements. - Knowledge
of, and experience in researching and applying relevant information
privacy laws, regulations, jurisprudence (particularly as it relates to
the Information and Privacy Commissioner of Ontario) and risk
countermeasures. - Familiarity
with OPS Privacy Impact Assessment Process and Tools released by the
Ontario Ministry of Government Services; - Good
understanding of related disciplines, such as IT security, IT system
design, policy development (privacy or security), business architecture,
legal processes, Freedom of Information administration, business analysis,
risk management, project management. - Analytical
skills to understand the current and future access and privacy
implications of policies, decisions and business initiatives - Knowledge
of Information Technology concepts and processes that impact the
protection of personal information, including (but not limited to)
Internet tools, system interfaces, information security, information
architecture and data flows
Nice to have:
- Knowledge
of, and experience with the policies and procedures of the Ontario
government (e.g. business case development, project approvals and policy
development)
Skill Set Requirements:
Responsibilities:
- Required to lead or support the development of a Privacy
Impact Assessment that evaluates whether new technologies, information systems,
or proposed programs or policies meet legal - and policy privacy requirements, determine and mitigate
risks, and address clients’ concerns. - These requirements include ensuring that the program
complies with provincial, municipal, federal and private sector access and
privacy legislation, as well as relevant regulations, statutes, OPS policies,
directives, standards, guidelines and internationally accepted Fair Information
Practices.
General Skills:
- Excellent knowledge of privacy and security concepts,
trends, and issues. - This will include an understanding of their impact on
business processes, as well as ability to interpretation and communicate
principles and compliance requirements. - Knowledge of, and experience in researching and applying
relevant information privacy laws, regulations, jurisprudence (particularly as
it relates to the Information and Privacy Commissioner of Ontario) and risk
countermeasures. - Experience in conducting Privacy Impact Assessments in
public sector context. - Knowledge of, and experience with privacy enhancing best
practices. - Knowledge and ability to interpret and apply the Ontario’s
Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal
equivalent the Municipal Freedom of Information and Protection of Privacy Act
(MFIPPA), Personal Health Information Protection Act (PHIPA) their respective
regulations and related jurisprudence. - Familiarity with the federal Personal Information Protection
and Electronic Documents Act (PIPEDA) and US PATRIOT Act.
Policy Knowledge:
- Familiarity with OPS Privacy Impact Assessment Process and
Tools released by the Ontario Ministry of Government Services; - Good understanding of related disciplines, such as IT
security, IT system design, policy development (privacy or security), business
architecture, legal processes, Freedom of Information administration, business
analysis, risk management, project management.
Operational Program and Business Design Skills:
- Ability to lead, manage or support the development of a PIA
either independently or as part of a team by directing and gathering input from
specific individuals within the organization. - Knowledge and ability to create and understand data flow
diagrams and business process diagrams. - Ability to recognize the need for, and seek input from
external experts as required. - Excellent communication skills with technical and business
audiences and privacy experts.
Technology and Systems Knowledge::
- Analytical skills to understand the current and future
access and privacy implications of policies, decisions and business initiatives - Knowledge of Information Technology concepts and processes
that impact the protection of personal information, including (but not limited
to) Internet tools, system interfaces, information security, information
architecture and data flows
Information and Record Keeping Knowledge:
- Experience in developing risk assessment tools,
methodologies, policies and procedures to effectively manage personal
information - Knowledge of policies, directives, standards, business
rules, procedures and guidelines relating to records management including
classification, retention and disposition of information - Knowledge and understanding of Accessibility for Ontarians
with Disabilities Act (AODA) and related regulations and standards
Desirable Skills::
- Professional certification from a related discipline such as
IT security, architecture - Experience providing education and training related to
privacy - Knowledge of, and experience with the policies and
procedures of the Ontario government (e.g. business case development, project
approvals and policy development)
PIA Specialist Skills:
- Privacy
Assessment Experience, Policy and Legislative Requirements - Technical
knowledge - Leadership
and Communications - Digital
Identity Frameworks and Standards
Apply Now
Opens the employer application page in a new tab.
