Your Opportunity
We are seeking a Privacy Specialist to join BDO Canada’s Legal Department. This replacement role will support the firm’s Privacy Office, report to Senior Counsel, Privacy, and work with Information Security, Data Governance, Risk, Human Resources, and other internal stakeholders.
The successful candidate will help support the day-to-day operation and continued maturity of BDO’s privacy program, including privacy impact assessments, data mapping, privacy incident response, vendor and technology reviews, privacy inquiries, training and awareness, and privacy program documentation. This role will also support BDO’s work on digital tools, AI, data analytics, and privacy-by-design by helping internal teams understand privacy risks and identify practical steps to address them.
Key Responsibilities
- Support the operation of BDO’s privacy program by coordinating intake, follow-up, documentation and metrics, and helping develop and update policies, procedures, templates, training and awareness materials.
- Identify and document personal information flows across systems, processes, service lines, and vendors to support privacy impact assessments, incident response, retention, cross-border transfer assessments, and program governance.
- Conduct and support Privacy Impact Assessments, DPIAs where applicable, and reviews for digital tools, analytics initiatives, service line projects, internal processes, and new uses of personal information.
- Help teams apply privacy-by-design and reduce risk through data minimization, access controls, retention, transparency, consent, de-identification, vendor controls, and appropriate use limitations.
- Assist with privacy incident response, including information gathering, documentation, containment and remediation, breach assessment, and stakeholder follow-up.
- Support vendor, technology, and cross-border privacy reviews by assessing data flows, vendor practices, security and privacy documentation, data processing arrangements, transfer risks, and transfer impact assessments in collaboration with legal counsel and internal stakeholders.
- Monitor Canadian and global developments in privacy, data protection, AI, and related regulation, including PIPEDA, provincial privacy laws, Quebec Law 25, GDPR, CCPA/CPRA, regulator guidance, enforcement trends, and industry practices; translate developments into practical updates to BDO's program.
- Respond to internal privacy inquiries with practical guidance aligned with BDO policies and applicable requirements.
How do we define success for your role?
- You demonstrate BDO's core values through all aspects of your work: Integrity, Respect, and Collaboration
- You understand your clients' industry, challenges, and opportunities; clients describe you as positive, professional, collaborative, and someone who delivers high-quality work
- You identify, recommend, and are focused on effective service delivery to your clients
- You share in an inclusive and engaging work environment that develops, retains, and attracts talent
- You actively participate in the adoption of digital tools and strategies to drive an innovative workplace
- You grow your expertise through learning and professional development
Your Experience and Education
- Four to six years of relevant experience in privacy, data protection, compliance, technology governance, or a related field; candidates with at least three years of direct privacy experience may also be considered.
- Experience developing, operating, or improving a privacy program in a complex organization.
- Strong working knowledge of Canadian privacy laws, including PIPEDA and provincial legislation such as Quebec's Law 25, with strong research skills to monitor developments in Canada and other relevant jurisdictions.
- Experience conducting or supporting Privacy Impact Assessments, privacy reviews, data mapping, or similar risk assessments; DPIA experience is an asset.
- Experience documenting personal information flows, including collection, use, disclosure, storage, retention, access, vendor involvement, and cross-border processing.
- Experience supporting privacy incident response, breach documentation, privacy inquiries, or access and deletion requests.
- Ability to translate privacy requirements into practical, business-facing guidance and clear next steps, supported by strong communication, sound judgment, attention to detail, and the ability to manage competing priorities.
- Understanding of privacy-by-design principles, including data minimization, transparency, consent, retention, access controls, and appropriate use limitations.
- Familiarity with GDPR, CCPA/CPRA, cross-border data transfers, data processing agreements, transfer impact assessments, AI-enabled solutions, data analytics, cloud tools, information security concepts, and privacy terms in vendor, technology, or commercial agreements is an asset; an IAPP certification such as CIPP/C, CIPM, or CIPT is also an asset.
The expected base salary range for this role is $90,000-$110,000 annually, based on skills, experience, location, and qualifications.
Ready to make your mark at BDO? Click “Apply now” to send your up-to-date resume to one of our Talent Acquisition Specialists.
To explore other opportunities at BDO, check out our careers page.
#LI-ES1