Remote
Senior Privacy Program Manager
About this role
Toast is driven by building the all-in-one restaurant platform that helps restaurants operate their business, increase sales, engage guests, and keep employees happy. We’re seeking an experienced Senior Privacy Program Manager to join Toast’s Legal & Compliance team who will play a pivotal role in shaping and maintaining a world-class privacy program. We are heavily leaned into AI automation efforts, and this is an exciting opportunity to help grow the program leveraging automation and LLMs.
As part of the dynamic and collaborative Privacy team, you will lead efforts to operationalize privacy requirements across our global operations. This is an opportunity to work on challenging and meaningful projects that make a difference in how we safeguard data and uphold privacy principles within the products and services we offer (both B2B and B2C). Our Legal & Compliance teams are primarily concentrated in Boston, New York, Washington D.C., San Francisco, and Chicago.
Candidates residing in these areas will be prioritized, as they will benefit from closer proximity to colleagues and greater access to company resources and events. A day in the life (Responsibilities) Global Privacy Program Management: Develop and maintain Toast's global privacy program, ensuring compliance with laws and best practices across the US, Canada, Europe, the UK, and other countries where Toast operates. DPA Enablement: Help triage our Procurement queue and provide a first pass assessment of privacy risk and vendor stance against our standard DPA using pre-defined risk thresholds and protocols in conjunction with LLMs.
Privacy Rights: Continue to mature our privacy rights process and program, including driving efforts to further automate how requests are processed alongside our vendor, Ethyca, and internal business teams and developing SOPs for use in responding to privacy rights requests. Privacy Reviews: Maintain our existing Jira queue for privacy review requests and oversee and improve on automation to generate a first pass privacy assessment that attorneys can then refine/finalize.
Work with business/product teams to implement mitigations identified during such privacy reviews. Operational Compliance & Risk Mitigation: Translate privacy requirements into actionable processes, develop and supplement privacy FAQs for different domains, manage privacy risk registers, and conduct Data Protection Impact Assessments (DPIAs) in collaboration with cross-functional teams. Training & Awareness & Data Governance: Develop and deliver privacy training programs, and collaborate on data governance frameworks for data classification and lifecycle management.