Privacy Program Executive – PHIPA/FIPPA/PIPEDA

United Software Group Inc

Toronto

On-site

CAD 150,000 - 230,000

Full time

40 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United Software Group Inc. seeks an Accountable Privacy Executive to lead the privacy program for a major digital health transformation. This is a named, signing-authority role with end-to-end ownership of privacy governance, attestations, and breach management for PHI services.

You will establish privacy governance, oversee PIAs and TRAs, embed privacy-by-design, and manage incidents while advising executives on regulatory exposure and contractual privacy obligations.

Qualifications

  • 10+ years in privacy, data protection, or information governance in regulated environments.
  • 5+ years in an executive or named accountable capacity with signing authority.
  • 7+ years hands-on experience with Canadian privacy legislation — PHIPA, FIPPA, PIPEDA.
  • 5+ years conducting/overseeing PIAs and coordinating TRAs for enterprise or province-wide systems.
  • 5+ years leading privacy breach/incident management, including regulator notification and executive reporting.
  • 5+ years in consulting or client-facing advisory roles with executive stakeholder management.
  • 5+ years exposure to frameworks such as NIST Privacy Framework, ISO/IEC 27001/27701, HITRUST.
  • 3+ years working with health information custodians, prescribed entities, or health information network providers.
  • Active privacy certification: CIPP/C, CIPM, or CIPT.
  • Bachelor's degree in Law, Health Informatics, Information Management, Business, Engineering, Technology, Information Systems, or related field (Master's or J.D. a plus)

Responsibilities

  • Serve as the named Accountable Privacy Executive, holding executive accountability for privacy across all in-scope services, systems, and personnel
  • Sign and maintain privacy attestations, declarations, and compliance certifications (Attachment 1 requirements 1.7.15 and 1.7.18), keeping supporting evidence audit-ready
  • Establish and oversee the privacy governance framework, policies, and operating procedures for PHI collection, use, disclosure, retention, and disposal
  • Ensure ongoing compliance with PHIPA, FIPPA, and PIPEDA, along with provincial privacy/security policies
  • Direct Privacy Impact Assessments (PIAs), coordinate Threat Risk Assessments (TRAs), and embed privacy-by-design into solution architecture
  • Own privacy breach and incident management end-to-end — containment, investigation, root cause analysis, remediation tracking
  • Chair privacy governance forums; act as single escalation point for privacy risks and decisions between delivery and client stakeholders
  • Advise client executives and clinical stakeholders on privacy risk posture and regulatory exposure
  • Embed privacy obligations into contracts, data sharing agreements, and vendor onboarding
  • Oversee privacy training, confidentiality undertakings, and role-based access governance for all PHI-access resources
  • Lead privacy audits, self-assessments, and readiness reviews; respond to regulator and third-party assurance requests, including IPC reviews
  • Report privacy program performance, KRIs, incidents, and remediation status to executive sponsors

Skills

Executive leadership
Privacy governance
Regulatory compliance
Stakeholder management
Contractual/regulatory frameworks
Risk management

Education

Bachelor's degree in related field

Job description

Job Title: Accountable Privacy Executive / Privacy Program Executive – PHIPA/FIPPA/PIPEDA
Note:

Only candidates who have resided in Toronto continuously for the previous 5 years will be considered; occasional travel to client sites in Ontario required)

Job Description:

We're seeking an Accountable Privacy Executive to hold executive-level accountability for the privacy program across a major digital health transformation engagement. This is a named, signing-authority role — you'll own privacy governance, compliance attestations, and breach management end-to-end for services involving personal health information (PHI).

Day-to-Day Responsibilities:
  • Serve as the named Accountable Privacy Executive, holding executive accountability for privacy across all in-scope services, systems, and personnel
  • Sign and maintain privacy attestations, declarations, and compliance certifications (Attachment 1 requirements 1.7.15 and 1.7.18), keeping supporting evidence audit-ready
  • Establish and oversee the privacy governance framework, policies, and operating procedures for PHI collection, use, disclosure, retention, and disposal
  • Ensure ongoing compliance with PHIPA, FIPPA, and PIPEDA, along with provincial privacy/security policies
  • Direct Privacy Impact Assessments (PIAs), coordinate Threat Risk Assessments (TRAs), and embed privacy-by-design into solution architecture
  • Own privacy breach and incident management end-to-end — containment, investigation, root cause analysis, remediation tracking
  • Chair privacy governance forums; act as single escalation point for privacy risks and decisions between delivery and client stakeholders
  • Advise client executives and clinical stakeholders on privacy risk posture and regulatory exposure
  • Embed privacy obligations into contracts, data sharing agreements, and vendor onboarding
  • Oversee privacy training, confidentiality undertakings, and role-based access governance for all PHI-access resources
  • Lead privacy audits, self‑assessments, and readiness reviews; respond to regulator and third‑party assurance requests, including IPC reviews
  • Report privacy program performance, KRIs, incidents, and remediation status to executive sponsors
Required Qualifications:
  • 10+ years in privacy, data protection, or information governance, with strong focus on regulated environments (healthcare, public sector, or consulting)
  • 5+ years in an executive or named accountable capacity (CPO, Privacy Director, Accountable Privacy Executive, or equivalent), including signing authority for attestations
  • 7+ years hands‑on experience with Canadian privacy legislation — PHIPA, FIPPA, PIPEDA
  • 5+ years conducting/overseeing PIAs and coordinating TRAs for enterprise or province‑wide systems
  • 5+ years leading privacy breach/incident management, including regulator notification and executive reporting
  • 5+ years in consulting or client‑facing advisory roles with executive stakeholder management
  • Demonstrated accountability track record under contractual/regulatory frameworks
  • 5+ years exposure to frameworks such as NIST Privacy Framework, ISO/IEC 27001/27701, HITRUST
  • 3+ years working with health information custodians, prescribed entities, or health information network providers
  • Active privacy certification: CIPP/C, CIPM, or CIPT
  • Bachelor's degree in Law, Health Informatics, Information Management, Business, Engineering, Technology, Information Systems, or related field (Master's or J.D. a plus)
Nice to Have:
  • Consulting experience within the Canadian public healthcare sector
  • Experience supporting IPC Ontario reviews or prescribed entity triennial reviews
  • Additional certifications: CISSP, CISM, CISA, CHPC, or legal qualification in privacy/health law
  • Bilingual proficiency in English and French
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

RQ09375 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09375 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

Hybrid
CAD 100,000 - 130,000
RQ08931 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ08931 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

Hybrid
CAD 100,000 - 130,000
RQ09055 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09055 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
Competitive salary
Health insurance
Professional development opportunities
Privacy Lead
Privacy Lead

Canada Health Infoway • Toronto

On-site
CAD 110,000 - 140,000
Competitive salary
RQ09302 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09302 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 80,000 - 100,000
RQ09522 - Privacy Impact Assessment (PIA) Specialist - Senior
RQ09522 - Privacy Impact Assessment (PIA) Specialist - Senior

Rubicon Path • Toronto

Hybrid
CAD 80,000 - 110,000
Privacy Lead
Privacy Lead

Inforoute-Sante-Du-Canada-Inc • Montreal (administrative region)

On-site
CAD 110,000 - 140,000
Specialist, Privacy
Specialist, Privacy

University of Ottawa • Ottawa

On-site
CAD 80,000 - 110,000
Senior Privacy Experts/Data Privacy Officer (SME's) (SS - 06272025 - PTJPE/DPO)
Senior Privacy Experts/Data Privacy Officer (SME's) (SS - 06272025 - PTJPE/DPO)

Rippedboxstation • Canada

Remote
CAD 60,000 - 80,000
Privacy Lead
Privacy Lead

Canada Health Infoway • Montreal (administrative region)

On-site
CAD 110,000 - 160,000