Privacy and Records Manager -Canada & US
Toronto, ON, CA, M4G 3W9
Privacy and Records Manager – Canada and US
WELCOME TO VCNA!
We are St Marys Cement, part of Votorantim Cimentos North America (VCNA), as the North American operations of Votorantim Cimentos, a global building materials and sustainability solutions leader in 11 countries, we are helping to make a positive impact and are transforming our world. We have a culture built on solid partnerships, long-lasting relationships, and opportunities for those who want to learn, grow and be part of a diverse and dynamic culture.
With solutions that include cement, ready-mix concrete and aggregates, we help to build homes, highways, hospitals, buildings, bridges, and schools across the Canadian and U.S. Great Lakes region and Northeast United States. Our commitment to excellence can be seen in those who invest and believe in what we do, those who share their lives with us, those who trust in our deliveries and those committed to innovation and a sustainable future.
Every day, we have the chance to accomplish something new and you're invited to be part of it.
Department: Legal Team
Work Location: Toronto - Leaside
WHAT IS THE OPPORTUNITY?
Job Summary:
The Privacy and Records Manager – Canada and US role exists to ensure VCNA meets its privacy and records management obligations across both jurisdictions, safeguarding personal information and overseeing the lifecycle of physical and electronic records. By embedding privacy-by-design into business and IT initiatives, serving as the internal subject matter expert, and working with VCNA to put in action records governance best practices, the role protects VCNA from regulatory, financial, and reputational risk while enabling secure, compliant, and efficient operations that support the company's broader business objectives.
Key Responsibilities: 50/50 split between Privacy & Records Management. The Privacy and Records Manager – Canada and US would own day-to-day privacy and records management execution and recognize and escalate legal interpretation and high-risk issues.
- Privacy
- Duties with respect to Policies & Procedures, including:
- Develop and assist with implementation of new and updated forms, policies, and procedures; review and advise on required updates to policies and procedures as laws and regulations change; ensure there is alignment between policies with respect to privacy matters, both at a Company level and as between the Company and the Global level policies.
- Collaborate with our VCNA business and corporate groups (and global parent in Brazil) to identify and address privacy - related issues, including policies and procedures, that require improvement.
- Assist both external and internal parties in completing forms resulting from our privacy policies and procedures (including with respect to individuals who want correction or deletion of their data); respond to all PII-related requests.
- Compliance Responsibilities, including:
- Serve as the internal subject matter expert on privacy law in all of our jurisdictions.
- Perform compliance monitoring related activities (e.g. personal data audits and record retention audits).
- Chief Privacy Officer duties under the Quebec Privacy Act.
- Act generally as a liaison with all VCNA departments, including IT, on privacy matters and on projects with any PII or other sensitive data facet.
- In cooperation with the Breach Coordinator and VCNA Response Team, be part of the response/participating in/coordinating VCNA’s response to any data breach.
- PII Management
- Work with different teams as necessary to improve record management from a privacy perspective.
- Work with IT to tighten controls around PII in VCNA systems (this may include, for example, recommending application of controls to existing repositories of PII, deletion of PII unnecessary for VCNA business purposes, moving PII out of insecure or uncontrolled repositories, or tightening access controls to PII).
- Privacy Impact Assessments (“PIA”)
- Responsible for evaluating Company projects against a threshold analysis to determine whether a PIA should be conducted; conducting all necessary PIAs; working with the project delivery team to ensure appropriate mitigations instituted.
- Record Management
- Participation in the team responsible for VCNA’s document management strategy and structure as the team institutes a new document management structure for the Company.
- Provide advice relating to VCNA’s collection, use, organization, accessibility, modification, storage, security, transfer, retrieval, receiving, maintenance, anonymization, de-identification, deletion, disclosure and management of data and work with employees to increase compliance.
- Responsibility for records management lifecycles, including overseeing the application of existing records management timelines to VCNA electronic systems and paper records and, where appropriate, vendor systems.
- Behavior Change Management
- Drive the agenda organization-wide of moving forward with a structured, defined approach to record management.
- Provide general training for VCNA and targeted training for groups with specific needs or challenges on policies relating to Privacy and Records, including Privacy Policies, Data Breach Response and related obligations and on data management best practices.
- Proactive interfacing with VCNA departments and employees to improve compliance.
- Planning & benchmarking - setting annual plans for each area (privacy & record management), with a longer-term plan in mind. This should take into account benchmarking and maturity comparisons with the industry.
Qualifications:
Education and/or Designations:
Must-have: Bachelor’s degree (law, business, information management, public policy, privacy/data governance or related)
Preferred but not mandatory professional certifications: CIPP/C (Canada) and/or CIPP/US (US), CIPM
Experience: 4 -7 years in a regulated or industrial environment
- Privacy:
- Has actually been in charge of all or part of a privacy program
- Experience supporting or managing:
- Privacy impact assessments (PIAs/DPIAs)
- Data inventories or data mapping exercises
- Incident/breach tracking and documentation
- Has dealt with regulators
- Has had exposure to more than dimply Ontario regulatory framework
- Policy drafting & roll-out, behavior change management & training a plus
- Record Management
- Exposure to records management / information governance, including:
- Retention schedules
- Document classification and cleanup initiatives
- Working with business units on classification
Skills:
Communication & Language
- Fluent in English (written and oral)
- French fluency is an asset
- Excellent written communication skills (policies, summaries, clear business guidance)
- Strong verbal communication skills, with the ability to explain privacy and records requirements in plain language to non-legal audiences
Stakeholder Management & Influence
- Ability to work effectively with cross-functional stakeholders (IT, HR, operations, business teams)
- Comfortable following up and driving accountability across teams
- Able to balance collaboration with firm but respectful pushback
- Strong interpersonal skills and professional judgment
Organization & Project Management
- Strong organizational and coordination skills
- Ability to manage multiple workstreams and competing priorities
- Experience tracking tasks, deliverables, and deadlines across stakeholders
- Detail-oriented with strong follow-through
- Nice-to-have: Familiarity with basic project management approaches (formal or informal)
Problem-Solving & Judgment
- Practical, solutions-oriented mindset
- Ability to work with imperfect or incomplete information
- Knows when to act independently vs. escalate
- Sound judgment in handling sensitive or confidential information
Self-Management & Work Style
- Proactive and self-directed
- Comfortable operating in a fast-paced, multi-jurisdictional environment
- Strong sense of ownership and accountability
- Comfortable organizing self, will be working in a less structured environment
- Strong proficiency in Microsoft 365 (especially Excel, Word, Outlook, Teams, SharePoint)
- Ability to:
- Track and manage information using spreadsheets or simple tools
- Organize and maintain documentation in shared environments
- Comfortable learning new internal systems (e.g., DMS, privacy tools) without heavy technical support
This role requires a balance of collaboration and coordination, including tracking deliverables and ensuring follow-through across multiple stakeholders. This person must have the ability to drive execution across others without direct authority. This role will not have any direct reports.
Work Environment:
Leaside office per our Remote Work Policy
5-10% travel, our Ontario locations plus possibly the US (but not necessarily)
Salary Range: $102,000-$120,000
WHAT'S IN IT FOR YOU?
- Being part of VCNA is being part of building famous landmarks such as Toronto's CN Tower, Roy Thompson Hall, Maple Leaf Gardens and the Darlington Nuclear Station and Ryerson Centre, St. Regis Chicago and 150 N. Riverside, Louis High-Speed Rail in Chicago and more
- Opportunities to collaborate with teams around the globe and growth opportunities in different areas
- Training, professional development
- Tuition reimbursement/assistance
- Competitive wages, vacation and holiday time
- Medical, dental, vision, disability and life insurance
- RRSP and DC (CAN) and 401K (U.S.)
- Lifeworks Employee Assistance Program (EAP): confidential support for you and your family (CAN)
- Educational scholarship program for dependents of regular salaried employees.
- Fertility drug coverage
- Paid Maternity Leave Top Up
- Hybrid work model for certain positions
Salary Range: $105,000 - $120,000
Location: Toronto, Ontario
OUR PEOPLE
We care about people - all people. At VCNA, we take safety, health and wellness seriously. We're dedicated to giving our employees a safe workplace, our neighbors a safe environment and our customers a high-quality and safe product. Safety first -and always!
Our VC Way reflects who we are, inspiring us to unite our culture and be our best: Our Way of Being: ethical and respectful, Our Way of Working: together with excellence and Our Way of Thriving: with the courage to transform.
INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENT
We have a results-oriented culture that values being open, honest, and authentic. It's part of our DNA. We are continually expanding our diverse and inclusive team by providing opportunities for everyone, regardless of race, ethnicity, age, gender, religion, sexual orientation, gender identity, gender expression, disability or economic status - a workplace where you can express your individuality and be your best self!