Benevity

Benevity

Senior GRC Analyst, Privacy

Toronto, Ontario · Senior

Sponsorship not specifiedDetected 48 days ago
ComplianceNegotiationProcess ImprovementLeadershipCollaboration

About the role

  • MEET BENEVITY Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about.
  • We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more!

Responsibilities

  • Own and maintain Benevity's Records of Processing Activities (ROPA) under both controller and processor regimes, ensuring compliance with GDPR Article 30 and equivalent requirements across applicable jurisdictions.
  • Develop and maintain privacy policies, notices, standards, and control frameworks aligned with GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, CASL, and emerging global laws (AU Privacy Act, India DPDP, Swiss FADP, and others).
  • Build and manage DSAR intake, triage, and response workflows in compliance with statutory deadlines (30 days under GDPR
  • Maintain and refresh the subprocessor listing in alignment with client Data Processing Agreement commitments and GDPR Article 28 obligations.
  • Design, operationalize, and continuously improve the Data Protection Impact Assessment (DPIA) process
  • Support the DPO operational function, including regulatory correspondence readiness, breach notification preparedness, and supervisory authority interface support in coordination with Legal.
  • Partner with Security, Engineering, Product, Legal, and Data Governance teams to embed privacy by design and by default into key business initiatives.
  • Build and manage DSAR intake, triage, and response workflows in compliance with statutory deadlines (30 days under GDPR; 45 days under CPRA), including coordination with business and legal stakeholders.
  • Design, operationalize, and continuously improve the Data Protection Impact Assessment (DPIA) process; embed DPIA requirements into product, data, and business initiative workflows.
  • Review and support the negotiation of Data Processing Agreements and data transfer mechanisms (SCCs, UK IDTAs) in collaboration with Legal.

Requirements

  • 5+ years of experience in privacy, data protection, GRC, or a closely related field, ideally within a SaaS or high-growth technology environment.
  • Hands-on experience with privacy or GRC tooling (e.g., OneTrust Privacy module, Hyperproof, or equivalent) to operationalize compliance workflows at scale.

Skills

  • Benevity is seeking a Sr.
  • GRC Analyst, Privacy to anchor and advance our data protection program across a complex, multi-jurisdictional regulatory landscape.
  • You will build the foundational infrastructure that keeps

This listing is sourced directly from Benevity's careers page and normalized into a canonical job model.