Plooto

Manager, Privacy & Regulatory Compliance

Plooto$100K — $120K *
US-AnywhereRemote in Canada
Legal & Accounting
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-6+ years of hands-on privacy experience, preferably in fintech or regulated environments.
  • Strong knowledge of Canadian privacy laws, especially PIPEDA and Quebec Law 25.
  • Practical experience with Privacy Impact Assessments, privacy reviews, and breach assessments.
  • Judgment to apply privacy requirements proportionately, developing practical controls.
  • Genuine curiosity about AI and emerging technologies and their impact on privacy.
  • Ability to simplify complex requirements into actionable guidance for teams.
  • Strong communication skills for collaboration across various departments.

Responsibilities

  • Lead and improve Plooto's privacy program as a subject-matter expert on compliance with Canadian privacy laws.
  • Provide practical privacy guidance, translating legal requirements into risk-based actions for the business.
  • Conduct privacy assessments for new products and vendors, adjusting review depth according to risk.
  • Develop methods for assessing AI tools in line with privacy and data use principles.
  • Embed privacy practices into product and process development from the outset.
  • Manage core privacy operations, including data rights requests and incident assessments.
  • Monitor and analyze emerging privacy developments to inform actionable recommendations.

Benefits

  • Opportunity to work at the intersection of privacy and technology, especially AI.
  • Possibility of influencing Plooto's approach to responsible AI adoption.
  • Flexible support for various regulatory compliance initiatives and risk management activities.
  • Access to training and development in privacy and compliance topics.
  • Collaborative work environment with cross-functional teams to foster knowledge sharing.
Full Job Description
About the Role

We're looking for a Manager, Privacy & Regulatory Compliance to lead and scale Plooto's privacy program while helping the business adopt AI, automation, and data-driven technologies responsibly.

Privacy expertise is the foundation of this role. As AI becomes more widely adopted across Plooto, the number and complexity of decisions involving personal and sensitive information will continue to grow. You will help the business navigate these decisions thoughtfully-establishing clear guardrails, identifying material risks, and enabling teams to innovate without creating unnecessary process or paperwork.

This is a hands-on individual contributor role for someone who is pragmatic, curious, and comfortable working in areas where the answers are still evolving. We are not looking for someone with decades of AI governance experience. We are looking for a strong privacy professional who is genuinely interested in AI, asks thoughtful questions, keeps up with emerging developments, and is excited to help shape Plooto's approach.

You will also support the ongoing implementation of Plooto's Enterprise Risk Management framework and provide additional capacity across the broader regulatory compliance program. Prior depth in ERM or AML/ATF is not essential; what matters is an ability and willingness to learn, apply sound judgment, and contribute where needed.

You'll work closely with Product, Engineering, Security, Legal, People, Operations, and other teams to translate complex requirements into practical, proportionate solutions that help Plooto move quickly and responsibly.

The role reports to the Senior Manager, Compliance within the Payments Strategy & Compliance function.

Key Responsibilities

Privacy is the primary focus of this role. The role will also provide flexible support for enterprise risk management and broader regulatory compliance priorities as business needs evolve
  • Lead and continuously improve Plooto's privacy program, serving as a primary privacy subject-matter expert and supporting compliance with PIPEDA, Quebec Law 25, Alberta PIPA, BC PIPA, and other applicable privacy requirements.
  • Provide practical privacy guidance to the business, translating legal and regulatory requirements into clear, risk-based actions without creating unnecessary documentation, approvals, or operational friction.
  • Lead privacy assessments for new products, features, vendors, and data uses, including Privacy Impact Assessments. Apply a proportionate approach so the depth of review and documentation reflects the actual level of risk.
  • Help shape Plooto's approach to responsible AI, developing lightweight, scalable methods for assessing AI tools and use cases across privacy, data use, transparency, retention, access, automated decision-making, and third-party processing.
  • Embed privacy by design into how Plooto operates, partnering with Product, Engineering, Security, People, and other teams early in the development and implementation of new products, AI tools, models, vendors, and automated processes.
  • Manage core privacy operations, including data rights requests, privacy incidents and breach assessments, third-party privacy reviews, cross-border data considerations, and data retention and deletion practices.
  • Monitor emerging privacy, data, and AI developments in Canada and the United States, determine which developments are relevant to Plooto, and convert them into focused, actionable recommendations.
  • Support the rollout and ongoing implementation of Plooto's Enterprise Risk Management framework, including coordinating risk assessments, maintaining the enterprise risk register, monitoring mitigation activities, and supporting risk reporting.
  • Help make risk management a practical business discipline, working with leaders to identify material risks, clarify ownership, track meaningful actions, and maintain reporting that supports decision-making rather than documentation for its own sake.
  • Support regulatory change and third-party risk activities, helping assess new requirements and higher-risk relationships, identify accountable owners, and track implementation of proportionate controls.
  • Provide flexible support across Plooto's broader regulatory compliance program, including regulatory initiatives, audits, effectiveness reviews, remediation work, obligations under the Retail Payment Activities Act, and AML/ATF requirements under the PCMLTFA and FINTRAC guidance.
  • Build understanding and accountability across the organization through clear guidance, practical tools, and training on privacy, responsible AI, and risk management.

Qualifications
  • 3-6+ years of hands-on privacy experience, ideally within fintech, payments, technology, banking, financial services, or another regulated environment.
  • Strong working knowledge of Canadian privacy requirements, particularly PIPEDA and Quebec Law 25, with familiarity with Alberta and British Columbia privacy legislation.
  • Practical experience conducting Privacy Impact Assessments, privacy reviews, data rights requests, and privacy incident or breach assessments.
  • The judgment to apply privacy requirements proportionately and develop controls that are defensible, practical, and appropriate to the underlying risk.
  • Genuine curiosity about AI and emerging technologies, including an interest in learning how new tools use data and helping the organization navigate evolving privacy and governance considerations.
  • You do not need extensive AI governance experience. Experience reviewing AI tools, automated processing, emerging technologies, or data-governance matters is an asset.
  • An ability to simplify complex requirements and create clear guidance, decision frameworks, and processes that people will actually use.
  • A practical, action-oriented mindset. You are comfortable building structure where it is needed while avoiding bureaucracy that does not meaningfully reduce risk.
  • Strong written and verbal communication skills, with the confidence to work collaboratively across Product, Engineering, Security, People, Operations, Legal, and leadership teams.
  • The ability to independently manage competing priorities, exercise sound judgment, and recognize when an issue requires escalation.
  • Familiarity with U.S. privacy frameworks, including CCPA/CPRA and emerging state privacy laws, is an asset.
  • Exposure to enterprise risk management, third-party risk, fintech regulation, payments compliance, or AML/ATF is helpful but not required. You should be curious and willing to build knowledge in these areas with the support of the broader Compliance team.
  • CIPP/C certification is preferred. CIPP/US, CIPM, or other relevant privacy certifications are assets.
  • Bilingualism in English and French is an asset given Plooto's Canadian regulatory obligations.

This posting is for one available position. Compensation will be determined based on the successful candidate's knowledge, skills, experience, and overall alignment with the role.

About Plooto

Plooto is a financial technology company that provides an online payment platform for small and medium-sized businesses. The platform enables businesses to send and receive payments, manage their cash flow, and automate their accounting processes. Plooto's platform integrates with popular accounting software, such as QuickBooks and Xero, and supports payments in multiple currencies. The company was founded in 2015 and is headquartered in Toronto, Canada.
Learn more about Plooto
Size
50 employees
Industry
Net Income
-$3 million
Founded
2015
5 Year Trend
+150%
Revenue
$2 million

Similar Jobs

More Jobs at Plooto

More Legal & Accounting Jobs

Find similar Manager, Privacy & Regulatory Compliance jobs: