10 Oct
|
Sobeys
|
Ontario
Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a full time opportunity for an Data Privacy and Ethics lead works. This role can be based out of any of our offices located in Stellarton, NS, Mississauga, ON.
Position Summary
The Privacy Compliance Specialist is responsible for leading the day-to-day oversight of the organization's compliance with regulatory Privacy controls. This role ensures compliance with applicable privacy laws and regulations, supports privacy risk management activities, and partners with business, technology, legal, cybersecurity, and data teams to embed privacy requirements into business processes, products, systems, and AI initiatives.
The successful candidate will act as a subject matter expert on privacy compliance, helping the organization navigate an evolving regulatory environment while enabling responsible innovation and data-driven business outcomes.
Key Responsibilities
Privacy Compliance Management
Partners with Cybersecurity and Enterprise Risk and Audit teams to lead the execution and maintenance of the enterprise privacy compliance program.
Monitor compliance with applicable privacy legislation and regulatory requirements, including PIPEDA, provincial privacy legislation, Quebec Law 25, and other applicable regulations.
Assess impacts of new and emerging privacy laws and develop implementation plans to address compliance gaps.
Partner with Cyber Security to update privacy policies, standards, procedures, controls, and supporting documentation.
Privacy Risk Assessment & Data Governance
Support Privacy Impact Assessments (PIAs) and related privacy reviews.
Review new business initiatives, technologies, AI solutions, and data-sharing arrangements to identify privacy risks and recommend mitigations.
Partner with Data Governance, Cyber Security, Risk Management,
and Legal teams to ensure effective privacy controls are implemented.
Support data lifecycle management activities, including retention, disposal, consent management, and data minimization practices.
Incident Response & Breach Management
Support privacy incident and breach response activities.
Assist in investigations related to privacy events and potential regulatory reporting requirements.
Document incidents, root causes, corrective actions, and lessons learned.
Coordinate with Legal, Security, and Business stakeholders during incident management activities.
Training & Awareness
Develop and deliver privacy awareness and compliance training programs.
Provide guidance and consultation to business and technology teams on privacy requirements and best practices.
Promote a culture of privacy accountability across the organization.
AI, Data & Emerging Technology Compliance
Support privacy compliance requirements for AI, analytics, data science, and emerging technology initiatives.
Review data usage practices involving automated decision-making, profiling, machine learning, and generative AI solutions.
Ensure appropriate privacy safeguards, transparency requirements, and regulatory obligations are incorporated into AI governance processes.
#LI-Hybrid
Qualifications
Education
Bachelor’s degree in law, Privacy, Information Management, Business, Risk Management, Information Security, or related field.
Relevant privacy certifications preferred (CIPP/C,
CIPP/US, CIPP/E, CIPM, CIPT).
Experience
7+ years of experience in privacy, compliance, risk, audit, governance, legal, o r regulatory functions.
Experience managing privacy compliance programs within a large, complex organization.
Experience conducting PIAs and managing privacy risk assessments.
Experience supporting regulatory audits, compliance reviews, and investigations.
Knowledge of privacy requirements related to cloud technologies, data platforms, analytics, and AI solutions.
Technical Knowledge
Strong understanding of:
PIPEDA
Quebec Law 25
Provincial privacy legislation
Privacy by Design principles
Data Governance frameworks
AI governance and responsible AI principles
Information security and cybersecurity fundamentals
Regulatory compliance and risk management frameworks
Key Competencies
Privacy regulatory expertise
Compliance monitoring and testing
Risk assessment and mitigation
Regulatory interpretation
Audit and control management
Stakeholder management
Executive communication and reporting
Policy development
Investigation and problem-solving
Influencing without authority
Strong written and verbal communication skills
Success Measures
The Senior Privacy Compliance Specialist will be successful when they:
Maintain compliance with applicable privacy regulations and obligations.
Ensure timely completion of privacy assessments and compliance reviews.
Reduce privacy risk exposure through proactive monitoring and remediation.
Successfully support regulatory examinations, audits, and investigations.
Drive adoption of privacy-by-design practices across business and technology initiatives.
Improve privacy awareness and accountability across the organization.
#J-18808-Ljbffr
📌 Data Privacy and Ethics Lead (Ontario)
🏢 Sobeys
📍 Ontario