Director - Privacy Office (Deputy Chief Privacy Officer); Head of Advisory and RCM
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director - Privacy Office (Deputy Chief Privacy Officer); Head of Advisory and RCM based in Canada.
This is a senior compliance leadership role at the intersection of regulatory advisory, privacy, and risk management.
You’ll serve as a trusted advisor to product, marketing, technology, payments, partnerships, and user-focused teams.
The role combines strategic guidance with hands-on ownership of a comprehensive enterprise privacy program.
You’ll translate complex Canadian regulatory requirements into practical, risk-based advice that enables responsible business growth.
You’ll also lead regulatory change management, privacy assessments, incident response, complaints, and compliance governance.
As a people leader, you’ll develop a multidisciplinary team while partnering with Legal, Financial Crime, Operational Risk, Internal Audit, and Technology.
This is an opportunity to build durable compliance capabilities in a remote-first, high-trust environment with a strong focus on AI, automation, and meaningful financial impact.
Accountabilities:
- Act as the primary compliance advisor to business partners across Product, Marketing, Technology, Payments, Partnerships, and User Success, providing timely, practical, risk-based guidance on products, features, campaigns, and business arrangements.
- Own regulatory advisory and interpretation, resolving novel questions through clear written positions and defensible analysis that can withstand regulatory and audit scrutiny.
- Lead compliance reviews and sign-off for marketing materials, customer communications, disclosures, and product initiatives, embedding regulatory obligations early in the development process.
- Own the Whistleblower and Ethics programs, including intake, investigation oversight, non-retaliation measures, and reporting to senior leadership and the Board.
- Partner with Legal to oversee regulatory compliance management, including regulatory horizon scanning, impact assessments, implementation of new or amended requirements, and maintenance of the regulatory obligations inventory.
- Lead the development, refresh, and governance of compliance policies, standards, and procedures, including annual approval cycles.
- Own and mature the enterprise privacy program, acting as the designated privacy lead and ensuring alignment with applicable privacy legislation.
- Establish and oversee Privacy Impact Assessments for new products, vendors, data uses, and technology changes, while governing consent, collection, use, disclosure, retention, and cross-border transfers through a privacy-by-design approach.
- Lead privacy incident and breach response, including containment coordination, real-risk-of-significant-harm assessments, regulatory and individual notifications, and root-cause remediation.
- Oversee privacy complaints, access and correction requests, data inventories, privacy notices, and organization-wide privacy training and awareness.
- Lead, coach, and develop compliance and privacy professionals, establishing clear priorities and strengthening the technical capabilities of the function.
- Partner with Financial Crime, Compliance Testing, Operational Risk, Internal Audit, Legal, and Technology/Cyber teams to provide integrated risk and compliance coverage.
- Represent the organization externally through industry associations, peer forums, and regulatory engagement, staying informed about emerging compliance, privacy, and conduct-risk trends.
- Prepare clear, decision-ready materials and recommendations for senior management and applicable Board-level committees.
- Apply AI, automation, and data analytics to advisory intake, regulatory horizon scanning, marketing reviews, and privacy assessments.
- Advise on the responsible use of AI, including model transparency, fairness, explainability, and the appropriate use of personal information.
- Evaluate and implement RegTech and privacy technologies that improve speed, consistency, and scalability without compromising compliance rigor.
- 10+ years of progressive experience across compliance, privacy, or regulatory legal functions within financial services, including substantial experience in an advisory capacity.
- Deep working knowledge of Canadian consumer protection, retail banking or payments, and privacy legislation.
- Demonstrated experience building or substantially maturing a privacy program or regulatory change program rather than simply operating an established framework.
- Strong understanding of regulated fintech, neobank, or direct-to-consumer financial services environments.
- Proven people leadership experience, with the ability to coach, develop, and raise the technical standards of a multidisciplinary compliance function.
- Excellent written and verbal communication skills, with the ability to provide clear answers to complex regulatory questions and explain the rationale behind recommendations.
- Strong decision-making skills and comfort operating in ambiguity, with the judgment to balance regulatory obligations, business objectives, and customer outcomes.
- Ability to develop practical, risk-based solutions while maintaining rigorous documentation and defensible compliance positions.
- A relevant designation such as CIPP/C, CAMS, CRCM, LL.B./J.D., or an equivalent qualification is an asset.
- Genuine interest in financial wellness and in using compliance as an enabler of responsible, customer-focused product development.
- Experience with AI, automation, data analytics, or RegTech solutions is valuable, particularly where these tools can improve compliance effectiveness and scalability.
- Annual salary of CAD $190,000–$230,000, with compensation determined based on Canadian market data, technical skills, previous experience, and internal pay equity.
- Remote-first working environment designed around autonomy, trust, and work-life integration.
- Flexible working hours and asynchronous collaboration to support different working styles and schedules.
- Opportunity to lead a broad, high-impact compliance and privacy mandate with significant exposure to senior leadership and Board-level decision-making.
- Meaningful ownership of enterprise privacy, regulatory advisory, and compliance management programs.
- Opportunity to shape and build durable compliance capabilities in a lean, technology-driven, and increasingly AI-integrated environment.
- Cross-functional exposure across Product, Marketing, Technology, Payments, Partnerships, Financial Crime, Risk, Legal, and Internal Audit.
- Inclusive and accessible working environment that values diverse backgrounds, perspectives, and experiences.
- Opportunity to contribute to products and programs focused on improving financial wellbeing for Canadians.
Requirements:
Benefits:
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company