We have an existing opening for a Data Protection Officer to join our team. The Canadian Data Protection Officer (CDPO) is responsible for overseeing the organisation’s data protection and privacy compliance across Canada and, where applicable, internationally. The role ensures that personal information is collected, used, disclosed, retained, and destroyed in accordance with Canadian privacy laws, regulatory guidance, and industry best practices. The DPO acts as both an independent advisor and a strategic business partner, embedding privacy by design into organisational operations. Regulatory Framework The CDPO ensures compliance with applicable data protection and privacy legislation, including but not limited to: Personal Information Protection and Electronic Documents Act (PIPEDA) Quebec Act Respecting the Protection of Personal Information in the Private Sector, as amended by Law 25 Alberta Personal Information Protection Act (PIPA) British Columbia Personal Information Protection Act (PIPA) Applicable breach notification, consent, accountability, and cross-border data transfer requirements Guidance and decisions issued by the Office of the Privacy Commissioner of Canada (OPC) and relevant provincial regulators Where applicable, international privacy frameworks such as the GDPR Key Responsibilities Privacy Governance & Compliance Develop, implement, and maintain a privacy management program in line with Canadian privacy laws. Monitor legislative and regulatory developments, including Law 25 requirements. Establish privacy policies, standards, and procedures. Maintain records of processing activities and data inventories. Advisory & Risk Management Provide expert privacy advice to business stakeholders. Lead or support Privacy Impact Assessments (PIAs). Embed privacy by design and by default into systems and processes. Review data sharing agreements and vendor contracts. Incident & Breach Management Respond to privacy incidents and data breaches. Ensure compliance with mandatory breach notification and reporting obligations. Coordinate incident response with internal stakeholders. Regulatory & Stakeholder Engagement Act as the primary contact for Canadian privacy regulators. Manage regulatory inquiries, investigations, and complaints. Oversee responses to access and correction requests. Training & Awareness Develop and deliver privacy training and awareness programs. Promote a culture of privacy and accountability. Oversight & Independence Operate with appropriate professional independence. Escalate material privacy risks to senior leadership and the Board. Skills, Knowledge & Expertise Bachelor’s degree in Law, Information Management, Business, IT, or a related field (or equivalent experience). 5+ years of experience in privacy, data protection, compliance, or related roles. Strong knowledge of Canadian privacy legislation. Experience implementing privacy management programs. Preferred Qualifications Legal qualification (LL.B. or J.D.). Privacy certifications such as CIPP/C, CIPP/E, CIPM, or CIPT. Experience with cross-border data protection compliance.
Privacy Program Manager
Coursera
Senior Privacy & Compliance Program Manager
Mozilla
Senior Technical Program Manager - Data Privacy
Warnerbros
Privacy and Records Manager -Canada & US
Vcna
Conservation Planning Specialist - British Columbia
Canadian Parks and Wilderness Society
Occupancy Planner
Jll