The Data Privacy Manager will oversee the organization's data protection and privacy compliance across Canada, ensuring adherence to relevant laws and regulatory guidance. They will act as a strategic partner to embed privacy by design into operations while managing privacy incidents, regulatory inquiries, and training programs.
Data Privacy Manager
Application Deadline: 27 August 2026
Department: Risk and Compliance
Employment Type: Permanent - Full Time
Location: Home Canada
Compensation: $120,000 - $140,000 / year
Description
We have an existing opening for a Data Protection Officer to join our team.
The Canadian Data Protection Officer (CDPO) is responsible for overseeing the organisation’s data protection and privacy compliance across Canada and, where applicable, internationally. The role ensures that personal information is collected, used, disclosed, retained, and destroyed in accordance with Canadian privacy laws, regulatory guidance, and industry best practices. The DPO acts as both an independent advisor and a strategic business partner, embedding privacy by design into organisational operations.
The CDPO ensures compliance with applicable data protection and privacy legislation, including but not limited to:
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- Quebec Act Respecting the Protection of Personal Information in the Private Sector, as amended by Law 25
- Alberta Personal Information Protection Act (PIPA)
- British Columbia Personal Information Protection Act (PIPA)
- Applicable breach notification, consent, accountability, and cross-border data transfer requirements
- Guidance and decisions issued by the Office of the Privacy Commissioner of Canada (OPC) and relevant provincial regulators
- Where applicable, international privacy frameworks such as the GDPR
Key Responsibilities
- Develop, implement, and maintain a privacy management program in line with Canadian privacy laws.
- Monitor legislative and regulatory developments, including Law 25 requirements.
- Establish privacy policies, standards, and procedures.
- Maintain records of processing activities and data inventories.
- Provide expert privacy advice to business stakeholders.
- Lead or support Privacy Impact Assessments (PIAs).
- Embed privacy by design and by default into systems and processes.
- Review data sharing agreements and vendor contracts.
- Respond to privacy incidents and data breaches.
- Ensure compliance with mandatory breach notification and reporting obligations.
- Coordinate incident response with internal stakeholders.
- Act as the primary contact for Canadian privacy regulators.
- Manage regulatory inquiries, investigations, and complaints.
- Oversee responses to access and correction requests.
- Develop and deliver privacy training and awareness programs.
- Promote a culture of privacy and accountability.
- Operate with appropriate professional independence.
- Escalate material privacy risks to senior leadership and the Board.
Skills, Knowledge & Expertise
- Bachelor’s degree in Law, Information Management, Business, IT, or a related field (or equivalent experience).
- 5+ years of experience in privacy, data protection, compliance, or related roles.
- Strong knowledge of Canadian privacy legislation.
- Experience implementing privacy management programs.
- Legal qualification (LL.B. or J.D.).
- Privacy certifications such as CIPP/C, CIPP/E, CIPM, or CIPT.
- Experience with cross-border data protection compliance.