Who is your Privacy Officer?
If you cannot name the individual accountable for your organization's privacy compliance, you are already offside. Canadian privacy law does not treat this as optional, and in Quebec it now has to be published.
The requirement
Under the federal Personal Information Protection and Electronic Documents Act, an organization is responsible for personal information under its control and must designate an individual accountable for the organization's compliance. That accountability sits with a person, not with a department and not with a policy document. The organization remains responsible even where processing is handled by a third party.
Alberta's and British Columbia's Personal Information Protection Acts contain comparable designation requirements. In Quebec, the reforms brought in by Law 25 went further: responsibility for the protection of personal information falls by default to the person with the highest authority in the organization, that responsibility can be delegated in writing, and the title and contact information of the person holding the role must be published on the organization's website.
What the role actually involves
Naming someone is the beginning, not the end. The designated individual is expected to be the person who can answer for:
- What personal information the organization holds, where it lives and which vendors touch it
- The privacy policy, the consent practices behind it and whether they match what actually happens
- Vendor and cross-border transfer arrangements, and the agreements behind them
- Access and correction requests, and the response timelines
- Breach assessment, notification to the Commissioner and to affected individuals, and the breach record
- Privacy impact assessments where the law or the circumstances require them
The uncomfortable question is not "do we have a privacy policy." It is "if the Commissioner called tomorrow, who takes the call, and what can they actually answer?"
Why companies get stuck
The role usually lands on whoever is closest to it: a founder, a head of operations, sometimes an IT lead. That is understandable and it is better than nobody. But the responsibilities are legal ones, and being named without the knowledge or the authority to act is a poor position for the individual and a weak one for the company.
The alternative most companies consider is hiring. A dedicated privacy lead is a real salary for a role that, at their size, is not a full-time job. So the appointment stays nominal, the program stays thin, and nobody notices until there is an incident or a customer's security questionnaire asks for the name.
A workable middle
The fractional route puts a qualified person in the seat and accepts the appointment: named as your Privacy Officer, responsible for the program, available to the regulator, at a fraction of a salary. At Murjis that seat is $2,450 a month, the same as any other seat, and it comes with the program build rather than just the name on a page.
Whatever route you take, the test is the same. Name the person. Give them the authority and the information to do the job. Make sure they could answer the Commissioner's questions on a Tuesday afternoon without a week of preparation.
Not sure which seat you need?
Fifteen minutes, no pitch. We will tell you which seats your company needs filled now, which can wait, and what it costs.
☕ Book a 15-min virtual coffeeThis article is general information, not legal advice, and does not create a solicitor-client relationship. The law changes and its application depends on your circumstances. Speak to a lawyer about your situation.