Job DescriptionResponsibilities:- Required to lead or support the development of a privacy impact assessment that evaluates whether new technologies, information systems, or proposed programs or policies meet legal and policy privacy requirements, determine and mitigate risks, and address clients' concerns.
- These requirements include ensuring that the program complies with provincial, municipal, federal and private sector access and privacy legislation, as well as relevant regulations, statutes, OPS policies, Directives, standards, guidelines and internationally accepted Fair Information Practices.
General Skills:- Excellent knowledge of privacy and security concepts, trends, and issues. This will include an understanding of their impact on business processes, as well as skill with interpretation and communication of principles and compliance requirements
- Knowledge of, and experience in researching and applying relevant information privacy laws, regulations, jurisprudence (particularly as it relates to the Information and Privacy Commissioner of Ontario) and risk countermeasures
- Experience in conducting Privacy Impact Assessments in public sector context
- Knowledge of, and experience with privacy enhancing best practices
- Knowledge and ability to interpret and apply Ontario's Freedom of Information and Protection of Privacy Act (FIPPA) and its municipal equivalent the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), Personal Health Information Protection Act (PHIPA) their respective regulations and related jurisprudence
- Familiarity with federal Personal Information Protection and Electronic Documents Act (PIPEDA) and US PATRIOT Act
- Policy Knowledge
- Familiarity with OPS Privacy Impact Assessment Process and Tools released by the Ontario Ministry of Government Services;
- Good understanding of related disciplines, such as IT security, IT system design, policy development (privacy or security), business architecture, legal processes, Freedom of Information administration, business analysis, risk management, project management.
- Operational Program and Business Design Skills
- Ability to lead, mange or support the development of a PIA either independently or as part of a team by directing and gathering input from specific individuals within the organization
- Knowledge and ability to create and understand data flow diagrams and business process diagrams
- Ability to recognize the need for, and seek input from external experts as required
- Excellent communication skills with technical and business audiences and non- access and privacy experts.
- Technology and Systems Knowledge
- Analytical skills to understand the current and future access and privacy implications of policies, decisions and business initiatives
- Knowledge of Information Technology concepts and processes that impact the protection of personal information, including (but not limited to) Internet tools, system interfaces, information security, information architecture and data flows
- Information and Record Keeping Knowledge
- Experience in developing risk assessment tools, methodologies, policies and procedures to effectively manage personal information
- Knowledge of policies, directives, standards, business rules, procedures and guidelines relating to records management including classification, retention and disposition of information
- Knowledge and understanding of Accessibility for Ontarians with Disability Act (AODA) and related regulations and standards
Desirable Skills:- Professional certification from a related discipline such as IT security, architecture
- Experience providing education and training related to privacy
- Knowledge of, and experience with the policies and procedures of the Ontario government (e.g. business case development, project approvals and policy development)
RequirementsExperience and Skill Set Requirements:Must Haves:- Experienceand understanding of credential holder centric ecosystems (decentralizedidentity models like SSI), supporting platforms and digital wallets
- Experiencedin leading and conducting privacy assessments involving online and/ormobile digital solutions that handle personal and health relatedinformation,
- Demonstratedexperience and familiarity with strong security, encryption and privacyprotection approaches to digital solutions, including mobile; web basedand backend integrations via API or similar approaches
- Experiencewith decentralized credential systems, supporting platforms/technologiesand digital wallets that can secure a Holder's personal information andprotect their privacy through selective disclosure and zero-knowledgeproofs.
Skill Set Requirements:Must-have experience in:
- Conductingprivacy impact assessments involving both PHIPA and FIPPA, citing examplesin resume
- ConductingPIAs involving mobile app solutions and the unique security and privacychallenges associated with such platforms
- Experienceand understanding of digital credential platforms and decentralized modelsfor credentials (self-sovereign identity-SSI)
- Developprivacy-enhancing tools and techniques
- DevelopKPIs and report metrics
- Developingways and means to align with broader government programs and practices
- Developingdesigns and architectures to inform a 'privacy/data governance function'that can be implemented for the DI Program and potentially all of ODS
- Experiencein developing and implementing Consent management frameworks, policy andsupporting business practices.
In addition, must have the ability to:
- Provideprivacy and data governance advisory services
- Assistwith development of statutory and regulatory instruments to addressdigital identity and related privacy matters
• Experience with Verifiable Credentials , specifically SSI model approaches.
• Knowledge and ability to create and understand data flow diagrams and business process diagrams;
• Ability to recognize the need for, and seek input from external experts as required;
• Conduct PIAs as required
• Develop privacy-enhancing tools and techniques
• Develop KPIs and report metrics
• Develop ways and means to align with broader government programs and practices
• Develop designs and architectures to inform a 'privacy/data governance function' for the DI Program and potentially all of ODS
• Provide privacy and data governance advisory services
• Assist with development of statutory and regulatory instruments to address digital credentials and related privacy matters
Nice to have:- PublicSector experience
- CurrentOPS security clearance is highly desirable.
In addition to responsibilities and skills noted previously, the following requirements will be evaluated:
Privacy Assessment, Consent Management, Policy and Legislative Requirements:- Experiencedin privacy legislation including Freedom of Information and Protection ofPrivacy Act (FIPPA), Personal Health Information Protection Act (PHIPA),the Personal Information Protection and Electronic Documents Act (PIPEDA)
- Experiencedin conducting privacy assessments involving personal information andpersonal health information citing examples in resume.
- Experiencedin leading and conducting privacy assessments involving online and/ormobile digital solutions that handle personal and health relatedinformation,
- Experienceand understanding of credential holder centric ecosystems (decentralizedidentity models like SSI), supporting platforms and digital wallets
- Leadand conducted assessments involving personal health information involvingthird party solutions (e.g private sector or non-profit applicationsolutions) and/or service integration providers
- Experiencedworking with legal council and/or policy development teams; reviewing andcomparing policies and legislation to make informed recommendations toensure adequate legal and/or statutory authorities, privacy protectionsand record keeping considerations are addressed in support of program andproject specific objectives.
- SMEand experienced in developing approaches for consent management;developing conceptual and logical models, identifying system and businessrequirements
Technical understanding:- Experiencewith privacy risks and conducting PIAs associated with integration betweenlegacy systems, web applications, mobile and cloud based solutions toobtain, retrieve and synchronize information.
- Experiencewith privacy risks and conducting PIAs involving mobile app solutions andthe unique security and privacy challenges associated with such platforms
- Demonstratedexperience and familiarity with strong security, encryption and privacyprotection approaches to digital solutions, including mobile; web basedand backend integrations via API or similar approaches.
- Experiencewith decentralized credential systems, supporting platforms/technologiesand digital wallets that can secure a Holder's personal information andprotect their privacy through selective disclosure and zero-knowledgeproofs.
- Familiarwith Digital Wallet technologies (native within OS or third party)including the security and privacy considerations, limitations and bestpractices for local data protection on mobile devices
- Familiarwith cloud based digital wallet technologies including the security andprivacy considerations, limitations and best practices for data protection
- Experience,knowledge and understanding of privacy protection standards and bestpractices, business, information and security architecture principles andemerging technology related to the protection of privacy and personalinformation
Leadership and Communications:- Demonstratedstrong communication and engagement skills with ability to lead teams indiscovery sessions to elicit details of technical solutions, businessprocesses and/or policies; strong writing skills to document findings,recommendation, etc
- Demonstratedability to interpret both technical (e.g architecture design documents,process flows, state transition diagrams, etc) and non technicaldocumentation to conduct assessment of impacts and to develop mitigationstrategies
- Strongorganizational and time management skills to manage multiple andconcurrent requests in an agile and highly dynamic work environmentsetting.
- Strongpresentation abilities to communicate findings, recommendations, etc tosenior management and executives to inform decision making; able tocommunicate complex problems/issues in a simple terms
Digital Credential Frameworks and Standards:- Experiencein developing, applying and/or evaluating trust frameworks such as thePCTF, eIDAS, or similar.
- Experiencewith digital credential standards such as NIST, W3C, etc.
- Experiencewith and understanding of SSI models, how they relate/impact privacy,consent, data governance.