This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager, Privacy & Regulatory Compliance based in Canada.
This role offers the opportunity to lead and continuously strengthen a privacy program within a fast-growing, technology-driven payments environment. You will serve as a key privacy subject-matter expert, helping teams navigate Canadian privacy requirements while enabling responsible innovation. A major focus will be supporting the responsible adoption of Artificial Intelligence (AI), automation, and data-driven technologies. You will partner closely with Product, Engineering, Security, Legal, People, Operations, and leadership teams to translate complex requirements into practical, risk-based solutions. The role also provides exposure to enterprise risk management and broader regulatory compliance priorities as business needs evolve. This is a hands-on individual contributor position suited to a pragmatic, curious professional who values sound judgment, clear processes, and meaningful business impact.
Accountabilities
- Lead and continuously improve the privacy program, serving as a primary privacy subject-matter expert and supporting compliance with Canadian privacy requirements, including the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec Law 25, Alberta Personal Information Protection Act (PIPA), British Columbia PIPA, and other applicable legislation.
- Provide practical, risk-based privacy guidance to business teams, translating legal and regulatory requirements into clear actions while minimizing unnecessary documentation, approvals, and operational friction.
- Lead privacy assessments for new products, features, vendors, and data uses, including Privacy Impact Assessments (PIAs), applying a proportionate approach based on the level of risk.
- Help develop a responsible Artificial Intelligence (AI) approach by creating scalable methods for assessing AI tools and use cases across privacy, data usage, transparency, retention, access, automated decision-making, and third-party processing.
- Embed privacy by design into product development and operational processes by partnering with Product, Engineering, Security, People, and other teams early in the implementation of new products, AI tools, models, vendors, and automated workflows.
- Manage core privacy operations, including data rights requests, privacy incidents and breach assessments, third-party privacy reviews, cross-border data considerations, and data retention and deletion practices.
- Monitor emerging privacy, data, and AI developments across Canada and the United States, assess their relevance, and translate regulatory developments into focused and actionable recommendations.
- Support the implementation and ongoing operation of the Enterprise Risk Management (ERM) framework, including coordinating risk assessments, maintaining the enterprise risk register, monitoring mitigation activities, and supporting risk reporting.
- Help make risk management a practical business discipline by working with leaders to identify material risks, establish ownership, track meaningful mitigation actions, and maintain useful reporting.
- Support regulatory change management and third-party risk activities by assessing new requirements and higher-risk relationships, identifying accountable owners, and tracking proportionate controls.
- Provide flexible support across broader regulatory compliance priorities, including regulatory initiatives, audits, effectiveness reviews, remediation activities, retail payment obligations, and Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) requirements.
- Build organizational awareness and accountability through clear guidance, practical tools, and training covering privacy, responsible AI, and risk management.
- 3-6+ years of hands-on privacy experience, ideally within fintech, payments, technology, banking, financial services, or another regulated environment.
- Strong working knowledge of Canadian privacy requirements, particularly PIPEDA and Quebec Law 25, with familiarity with Alberta and British Columbia privacy legislation.
- Practical experience conducting Privacy Impact Assessments, handling data rights requests, and assessing privacy incidents or potential breaches.
- Strong judgment and the ability to apply privacy requirements proportionately while developing controls that are defensible, practical, and aligned with the underlying risk.
- Genuine curiosity about Artificial Intelligence and emerging technologies, with an interest in understanding how new tools use data and helping organizations address evolving privacy and governance considerations.
- Experience reviewing AI tools, automated processing, emerging technologies, or data-governance matters is an asset, although extensive AI governance experience is not required.
- Ability to simplify complex legal and regulatory requirements and turn them into clear guidance, decision frameworks, and processes that business teams can realistically adopt.
- Practical, action-oriented mindset with the ability to create structure where necessary without introducing bureaucracy that does not meaningfully reduce risk.
- Strong written and verbal communication skills, with confidence collaborating across Product, Engineering, Security, People, Operations, Legal, and leadership teams.
- Ability to independently manage competing priorities, exercise sound judgment, and recognize when issues require escalation.
- Familiarity with United States privacy frameworks, including the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and emerging state privacy laws, is an asset.
- Exposure to enterprise risk management, third-party risk, fintech regulation, payments compliance, or AML/ATF is helpful but not required, with willingness to develop knowledge in these areas.
- Certified Information Privacy Professional/Canada (CIPP/C) certification is preferred; CIPP/US, Certified Information Privacy Manager (CIPM), or other relevant privacy certifications are assets.
- Bilingual English and French language skills are an asset given the Canadian regulatory environment.
- Ability to work effectively in a distributed environment with strong ownership, collaboration, and adaptability.
- Fully remote position for professionals based in Canada.
- Opportunity to lead and shape a growing privacy and regulatory compliance program.
- Meaningful involvement in responsible AI, automation, and data-driven technology initiatives.
- Opportunity to work cross-functionally with Product, Engineering, Security, Legal, People, Operations, and leadership teams.
- Hands-on exposure to enterprise risk management and broader regulatory compliance activities.
- Opportunity to contribute to products addressing important financial and cash-flow challenges for small and medium-sized businesses.
- Collaborative environment focused on customer impact, high-quality work, and purposeful execution.
- Inclusive workplace that values diverse backgrounds, experiences, perspectives, and ways of thinking.
- Accommodation available throughout the recruitment process in accordance with applicable accessibility legislation.
- Compensation determined based on the successful candidate’s knowledge, skills, experience, and overall alignment with the role.

