Privacy and regulatory compliance manager leading Plooto’s privacy program and responsible AI governance. Supporting risk management and compliance for its Canadian payment automation platform.
Responsibilities
Lead and continuously improve Plooto’s privacy program and serve as a primary privacy subject-matter expert
Support compliance with PIPEDA, Quebec Law 25, Alberta PIPA, BC PIPA, and other applicable privacy requirements
Provide practical, risk-based privacy guidance to the business
Lead privacy assessments for new products, features, vendors, and data uses, including Privacy Impact Assessments
Help shape Plooto’s responsible AI approach and scalable assessment methods
Embed privacy by design across products, AI tools, models, vendors, and automated processes
Manage data rights requests, privacy incidents and breach assessments, third-party privacy reviews, cross-border data considerations, and retention/deletion practices
Monitor emerging privacy, data, and AI developments in Canada and the United States and provide actionable recommendations
Support implementation of the Enterprise Risk Management framework, including risk assessments, the enterprise risk register, mitigation monitoring, and risk reporting
Work with leaders to identify material risks, clarify ownership, track actions, and maintain useful reporting
Support regulatory change, third-party risk activities, audits, effectiveness reviews, remediation, Retail Payment Activities Act obligations, and AML/ATF requirements
Build organizational understanding through guidance, tools, and training on privacy, responsible AI, and risk management
Collaborate with Product, Engineering, Security, Legal, People, Operations, and other teams
Report to the Senior Manager, Compliance within the Payments Strategy & Compliance function
Requirements
3–6+ years of hands-on privacy experience, ideally within fintech, payments, technology, banking, financial services, or another regulated environment
Strong working knowledge of Canadian privacy requirements, particularly PIPEDA and Quebec Law 25, with familiarity with Alberta and British Columbia privacy legislation
Practical experience conducting Privacy Impact Assessments, privacy reviews, data rights requests, and privacy incident or breach assessments
Judgment to apply privacy requirements proportionately and develop defensible, practical, risk-appropriate controls
Genuine curiosity about AI and emerging technologies
Ability to simplify complex requirements and create clear guidance, decision frameworks, and processes
Practical, action-oriented mindset
Strong written and verbal communication skills and ability to work collaboratively across Product, Engineering, Security, People, Operations, Legal, and leadership teams
Ability to independently manage competing priorities, exercise sound judgment, and recognize when escalation is required
Familiarity with U.S. privacy frameworks, including CCPA/CPRA and emerging state privacy laws, is an asset
Exposure to enterprise risk management, third-party risk, fintech regulation, payments compliance, or AML/ATF is helpful but not required
CIPP/C certification is preferred; CIPP/US, CIPM, or other relevant privacy certifications are assets
Bilingualism in English and French is an asset
Benefits
Compensation determined based on the successful candidate’s knowledge, skills, experience, and overall alignment with the role
Inclusive workplace
Accommodation throughout the recruitment process in accordance with applicable accessibility legislation
Director leading Board and committee compliance reporting for Sun Life, a global financial services company. Developing KRI metrics, regulatory insights and risk narratives for senior leadership.
Health Compliance Officer inspecting continuing care homes for Government of Alberta. Conducting investigations, compliance reviews, and regulatory oversight across Alberta.
Regulatory Strategist guiding Latin American drug submissions and lifecycle management for Syneos Health’s life sciences services. Providing regional expertise, coordinating authorities, and leading cross - functional submission teams.
Regulatory Consultant using Veeva Vault RIM to coordinate drug regulatory submissions for Syneos Health. Supporting Vertex submission managers with publishing, project tracking, and content planning.
Billing Compliance Analyst ensuring accurate matter setup, rates, and invoices. Supporting eBilling compliance and reporting for Canadian law firm McCarthy Tétrault.
Senior Compliance Analyst maintaining Canadian securities and crypto compliance programs at Crypto.com. Translating CSA and CIRO requirements into policies, controls, training, and operational practices.
GRC/Compliance Lead guiding SOC 2, ISO, and customer assurance for enterprise AI platforms. Building practical compliance into regulated, mission - critical software delivery.
Group Manager leading regulatory reporting change management at TD Securities, a capital markets services provider. Managing requirements, data analytics, stakeholders, and regulatory initiatives.
Senior GRC sales executive expanding Workiva’s AI - powered platform for finance, risk, and sustainability. Driving enterprise customer acquisition and complex solution sales across Western Canada.