Chief Privacy Officer - Privacy Office - Regular Full-Time 2026-16605

Back to Job List

Date Posted: 3/9/2026

Location: Toronto, ON, Canada

Reference No.: 2026-16605

Position Type: Regular full-time

Department: Privacy Office

FTE Status: 1.00

Hours of Work: 8 hrs

Campus Site: Bayview

Shifts Weekday Required: Days

Shifts Weekend Required: No Weekends

Statutory Holiday(s) Required: No

Salary Range: $78.2460-$100.4090/hr

Vacancy Status: Existing

The Chief Privacy Officer (CPO) is responsible for ensuring organizational compliance with all applicable information privacy and freedom of information legislation and internal policies related to the protection of personal information. The CPO leads the development, implementation, and continuous improvement of the associated privacy programs, policies, and procedures to safeguard data and mitigate privacy risk across the organization.

 

At this critical juncture, during the organization’s transition to a new health information system and in the context of rapid change associated with artificial intelligence, the CPO plays a pivotal role in ensuring that privacy control requirements are embedded across Sunnybrook’s information management system design, configuration, workflows, audit and compliance processes. This includes overseeing privacy impact assessments, supporting system and procedural change‑management activities, and ensuring the new system meets legislative and best‑practice standards for the protection of personal health information.

 

This role provides subject-matter expertise, guidance, and training to staff on privacy best practices, and acts as the primary point of contact for privacy-related concerns, inquiries, and incident management. When privacy incidents occur, the CPO coordinates appropriate responses with Legal Counsel, Senior Leadership, external partners, and the Information and Privacy Commissioner of Ontario as necessary.

 

Key Responsibilities:

  • Develop and maintain privacy programs, policies, and procedures.
  • Oversee compliant processes for managing personal and sensitive information.
  • Lead investigations of privacy incidents, assess risks, implement mitigations, and ensure required reporting.
  • Conduct privacy audits and assessments to ensure adherence to legislation and policies.
  • Provide organizationwide training on privacy requirements and best practices.
  • Participate in the institutional review and approval of research activity.
  • Review and approve integrated care systems and data sharing initiatives.
  • Provide strategic leadership and direction to the Privacy Office team, including the Privacy Office Manager and Privacy Analyst, ensuring clear priorities, effective workflow management, and high‑quality service delivery across all privacy functions.
  • Develop, mentor, and coach staff to build organizational privacy expertise; foster a collaborative, high‑performing team culture grounded in accountability, continuous learning, and operational excellence.

 

Qualifications:

  • Undergraduate degree required; Graduate degree preferred.
  • Minimum 5 years of experience in privacy, compliance, or related fields, preferably in healthcare or regulated sectors.
  • Experience conducting privacy impact assessments and leading privacy investigations.
  • Knowledge of relevant privacy legislation and regulatory requirements (e.g., PHIPA, FIPPA).
  • Relevant certifications such as CIPP/C, CIPT, CDPSE or equivalent (preferred).
  • Relevant knowledge and experience in the acquisition, development and management of information technology.

 

Knowledge and Skills:

  • Strategic leadership: Ability to lead the Privacy Office, set clear priorities, and foster a culture of privacy excellence and continuous improvement.
  • Organizational influence: Skilled at influencing senior leaders, crossfunctional teams, and stakeholders on privacy issues and strategic decisionmaking.
  • Exceptional communication: Capable of translating complex privacy concepts and risks into clear guidance for diverse audiences.
  • Strategic negotiation & representation: Adept at negotiating and representing the organization with patients, external stakeholders and regulators.
  • Advanced analytical problemsolving: Ability to evaluate complex privacy issues and develop riskbased solutions.
  • Sound judgment and discretion: Demonstrated capacity to manage sensitive, confidential, or highrisk matters.
If you are looking for an exciting opportunity and to build a career in an innovative and dynamic organization, submit your resume by clicking on Apply Now below. 

Sunnybrook Health Sciences Centre is committed to providing accessible employment practices that are in compliance with the Accessibility for Ontarians with Disabilities Act (AODA). If you require accommodation for disability during any stage of the recruitment process, please indicate this in your cover letter.


Sunnybrook Health Sciences Centre is strongly committed to inclusion and diversity within its community and welcomes all applicants including but not limited to: visible minorities, all religions and ethnicities, persons with disabilities, LGBTQ persons, and all others who may contribute to the further diversification of ideas.

We thank all applicants for their interest. However, only candidates selected for an interview will be contacted. Sunnybrook Health Sciences Centre is an equal opportunity employer.

Review Sunnybrook Health Sciences Centre's Privacy Statement.