Data Privacy and Ethics Lead

Sobeys
Sobeys

Full-time

Stellarton, NS, Canada

Posted on Oct 9, 2026
Sobeys is full of exciting opportunities, and we are always looking for bright new talent to join our team! We currently have a full-time opportunity for an Data Privacy and Ethics lead works. This role can be based out of any of our offices located in Stellarton, NS, Mississauga, ON. Position Summary The Privacy Compliance Specialist is responsible for leading the day-to-day oversight of the organization's compliance with regulatory Privacy controls. This role ensures compliance with applicable privacy laws and regulations, supports privacy risk management activities, and partners with business, technology, legal, cybersecurity, and data teams to embed privacy requirements into business processes, products, systems, and AI initiatives.The successful candidate will act as a subject matter expert on privacy compliance, helping the organization navigate an evolving regulatory environment while enabling responsible innovation and data-driven business outcomes. Key Responsibilities Privacy Compliance Management Partners with Cybersecurity and Enterprise Risk and Audit teams to lead the execution and maintenance of the enterprise privacy compliance program.Monitor compliance with applicable privacy legislation and regulatory requirements, including PIPEDA, provincial privacy legislation, Quebec Law 25, and other applicable regulations.Assess impacts of new and emerging privacy laws and develop implementation plans to address compliance gaps.Partner with Cyber Security to update privacy policies, standards, procedures, controls, and supporting documentation. Privacy Risk Assessment & Data Governance Support Privacy Impact Assessments (PIAs) and related privacy reviews.Review new business initiatives, technologies, AI solutions, and data-sharing arrangements to identify privacy risks and recommend mitigations.Partner with Data Governance, Cyber Security, Risk Management, and Legal teams to ensure effective privacy controls are implemented.Support data lifecycle management activities, including retention, disposal, consent management, and data minimization practices. Incident Response & Breach Management Support privacy incident and breach response activities.Assist in investigations related to privacy events and potential regulatory reporting requirements.Document incidents, root causes, corrective actions, and lessons learned.Coordinate with Legal, Security, and Business stakeholders during incident management activities. Training & Awareness Develop and deliver privacy awareness and compliance training programs.Provide guidance and consultation to business and technology teams on privacy requirements and best practices.Promote a culture of privacy accountability across the organization. AI, Data & Emerging Technology Compliance Support privacy compliance requirements for AI, analytics, data science, and emerging technology initiatives.Review data usage practices involving automated decision-making, profiling, machine learning, and generative AI solutions.Ensure appropriate privacy safeguards, transparency requirements, and regulatory obligations are incorporated into AI governance processes. #LI-Hybrid Qualifications Education Bachelor’s degree in law, Privacy, Information Management, Business, Risk Management, Information Security, or related field.Relevant privacy certifications preferred (CIPP/C, CIPP/US, CIPP/E, CIPM, CIPT). Experience 7+ years of experience in privacy, compliance, risk, audit, governance, legal, or regulatory functions.Experience managing privacy compliance programs within a large, complex organization.Experience conducting PIAs and managing privacy risk assessments.Experience supporting regulatory audits, compliance reviews, and investigations.Knowledge of privacy requirements related to cloud technologies, data platforms, analytics, and AI solutions. Technical Knowledge Strong understanding of: PIPEDAQuebec Law 25Provincial privacy legislationPrivacy by Design principlesData Governance frameworksAI governance and responsible AI principlesInformation security and cybersecurity fundamentalsRegulatory compliance and risk management frameworks Key Competencies Privacy regulatory expertiseCompliance monitoring and testingRisk assessment and mitigationRegulatory interpretationAudit and control managementStakeholder managementExecutive communication and reportingPolicy developmentInvestigation and problem-solvingInfluencing without authorityStrong written and verbal communication skills Success Measures The Senior Privacy Compliance Specialist will be successful when they: Maintain compliance with applicable privacy regulations and obligations.Ensure timely completion of privacy assessments and compliance reviews.Reduce privacy risk exposure through proactive monitoring and remediation.Successfully support regulatory examinations, audits, and investigations.Drive adoption of privacy-by-design practices across business and technology initiatives.Improve privacy awareness and accountability across the organization.