The opportunity
Toast is driven by building the all-in-one restaurant platform that helps restaurants operate their business, increase sales, engage guests, and keep employees happy. We’re seeking an experienced Senior Privacy Program Manager to join Toast’s Legal & Compliance team who will…
What you'll do
Global Privacy Program Management: Develop and maintain Toast's global privacy program, ensuring compliance with laws and best practices across the US, Canada, Europe, the UK, and other countries where Toast operates.
DPA Enablement: Help triage our Procurement queue and provide a first pass assessment of privacy risk and vendor stance against our standard DPA using pre-defined risk thresholds and protocols in conjunction with LLMs.
Privacy Rights: Continue to mature our privacy rights process and program, including driving efforts to further automate how requests are processed alongside our vendor, Ethyca, and internal business teams and developing SOPs for use in responding to privacy rights requests.
Privacy Reviews: Maintain our existing Jira queue for privacy review requests and oversee and improve on automation to generate a first pass privacy assessment that attorneys can then refine/finalize. Work with business/product teams to implement mitigations identified during such privacy reviews.
Operational Compliance & Risk Mitigation: Translate privacy requirements into actionable processes, develop and supplement privacy FAQs for different domains, manage privacy risk registers, and conduct Data Protection Impact Assessments (DPIAs) in collaboration with cross-functional teams.
Training & Awareness & Data Governance: Develop and deliver privacy training programs, and collaborate on data governance frameworks for data classification and lifecycle management.
What they're looking for
- Metrics & Reporting: Establish and track key performance indicators (KPIs) to measure program effectiveness and provide regular reports to leadership. Maintain and update the Privacy team’s Confluence page to serve as an internal resource to other teams.
- Typically requires a minimum of 12 years of related experience with a: Bachelor’s degree or 8 years and a Master’s degree. Privacy certifications (CIPP/E, CIPP/US, CIPM, etc.) are preferred but not mandatory.
- + years of relevant privacy experience. SaaS or tech industry experience preferred.
- Comprehensive knowledge of global privacy laws (GDPR, CCPA, PIPEDA, etc.),: and the ability to apply them practically in a business setting.