Chief Privacy Officer (CPO) (Volunteer)
Mentor A Promise is a New York City–based nonprofit serving children and youth (ages 5–18) experiencing housing instability, grounded in the belief that every child is a Promise—full of potential, dignity, and possibility. We deliver consistent, high-quality programming across mentorship, literacy, social-emotional learning, and creative expression in shelters, schools, and community spaces, creating structured environments where students can grow, be seen, and build lasting skills. Through signature experiences like The Imagination Studio, The Kitchen Table, The Sound Lab, and The Story Space, we nurture academic development, emotional well-being, and creative voice, all within a trauma-informed, culturally responsive, and accessibility-centered framework. Our work prioritizes dignity-protective storytelling, consent-driven engagement, and deep community partnership, ensuring that how we serve is as intentional as whom we serve.
Organization: PromiseShield | Privacy, Data Protection & Digital Trust Division of Mentor A Promise (MAP)
Location: Remote with NYC-based collaboration as needed
Type: Volunteer Executive Leadership Role
Commitment: Approximately 5–10 hours per week, minimum 6-month commitment required
About the Role
Mentor A Promise is seeking an experienced Chief Privacy Officer (CPO) to establish and lead the organization’s enterprise privacy, data protection, and responsible-data strategy. Reporting directly to the CEO, the CPO will serve as MAP’s senior privacy leader, helping determine how personal information is collected, accessed, used, shared, retained, and protected throughout its lifecycle. This is an active executive leadership position, not an honorary or advisory title. The CPO will build privacy governance that protects children and families while enabling MAP’s programs, research, technology, communications, partnerships, and innovation to operate responsibly.
What You’ll Build
- An enterprise privacy and data-protection framework
- Privacy governance and accountability structures
- Data classification, retention, access, and lifecycle standards
- Consent and transparency frameworks
- Privacy impact and risk-assessment processes
- Vendor and technology privacy-review practices
- Privacy incident and breach-response protocols
- Privacy-by-design practices for new programs and technologies
- Organization-wide privacy education and awareness
- A sustainable culture of responsible data stewardship
Responsibilities
Privacy Strategy & Governance
- Develop and lead MAP’s enterprise privacy and data-protection strategy.
- Establish privacy policies, standards, procedures, and accountability structures.
- Define responsible practices for collecting, using, sharing, retaining, and disposing of personal information.
- Integrate privacy considerations into organizational planning and decision-making.
- Provide executive leadership with clear guidance on emerging privacy risks and priorities.
Children, Families & Sensitive Information
- Establish heightened safeguards for information involving children, families, and other sensitive populations.
- Strengthen informed consent, transparency, and appropriate data-use practices.
- Advise programs, research, communications, and technology teams on responsible handling of sensitive information.
- Promote data minimization and purpose-based collection.
- Ensure dignity and privacy remain central when MAP develops new initiatives involving participant information.
Regulatory & Policy Compliance
- Partner with legal and governance leadership to identify applicable privacy and data-protection obligations.
- Help operationalize requirements that may arise under laws and regulatory frameworks relevant to MAP’s activities, including child privacy, education records, cybersecurity, and state privacy requirements.
- Monitor regulatory developments and recommend organizational responses.
- Support privacy documentation, assessments, audits, and compliance reviews.
- Maintain appropriate records of privacy decisions, risks, and mitigation activities.
Privacy by Design & Technology
- Partner with PromiseStack and PromiseShield teams to integrate privacy into technology design and implementation.
- Review new applications, platforms, systems, AI tools, and digital initiatives from a privacy perspective.
- Develop privacy-impact and data-protection assessment processes.
- Evaluate data flows, permissions, access, retention, and third-party integrations.
- Advocate for privacy-preserving solutions wherever practical.
Vendor & Third-Party Privacy
- Establish privacy review processes for vendors, platforms, partners, and service providers.
- Identify privacy risks associated with third-party data processing.
- Collaborate with PromiseTrust on data-protection provisions, agreements, and contractual safeguards.
- Support appropriate due diligence before sensitive information is shared externally.
- Monitor significant third-party privacy risks and remediation needs.
Incident Preparedness & Response
- Help establish privacy incident and breach-response protocols.
- Partner with cybersecurity, legal, operations, and executive leadership during privacy incidents.
- Define escalation, documentation, assessment, and communication processes.
- Support post-incident reviews and corrective-action planning.
- Strengthen organizational preparedness through exercises and continuous improvement.
Privacy Education & Culture
- Develop practical privacy training for volunteers, staff, leaders, and teams.
- Help team members understand their responsibilities when handling personal information.
- Translate complex privacy concepts into clear operational guidance.
- Promote a culture where privacy concerns can be raised early and addressed constructively.
- Reinforce that responsible data practices are everyone's responsibility.
Chief Leadership Expectations
- Attend our weekly Chiefs Meeting and come prepared to contribute to strategy, governance, risk discussions, and organizational decision-making.
- Meet weekly with the CEO to discuss privacy priorities, emerging risks, challenges, progress, and opportunities.
- Take ownership of the privacy function by setting direction, solving problems, establishing priorities, and driving measurable progress.
- Communicate regularly with Directors and direct reports, ensuring team members remain informed, supported, connected, and clear about responsibilities.
- Follow through on commitments and model accountability, collaboration, integrity, discretion, transparency, and professional judgment.
- Recruit, develop, recognize, and retain volunteers while building a capable, healthy, and mission-driven privacy function.
- Develop leaders and systems so that privacy governance does not depend on one individual.
- Collaborate closely with legal, governance, cybersecurity, technology, operations, research, programs, and communications teams.
- Keep MAP’s mission at the center of every privacy decision, remembering that responsible data stewardship ultimately protects the children and families we serve.
Qualifications
We are looking for a privacy leader who can combine legal and regulatory awareness, technology fluency, ethical judgment, and practical organizational leadership. Strong candidates may have experience in:
- Privacy and data protection
- Information governance
- Privacy law or compliance
- Cybersecurity governance
- Technology risk
- Data governance
- Regulatory compliance
- Responsible AI or emerging technology governance
- Education, healthcare, nonprofit, or youth-serving environments
Candidates should demonstrate:
- Strong knowledge of privacy principles, consent, transparency, data minimization, and lifecycle governance
- Experience developing privacy policies or programs
- Ability to translate legal and technical concepts into practical operational guidance
- Strong executive judgment and discretion
- Experience collaborating across legal, technology, security, operations, and program teams
- Excellent written and verbal communication
- Commitment to ethical, inclusive, trauma-informed, and dignity-centered practices
Professional credentials such as CIPP/US, CIPP/E, CIPM, CIPT, legal training, or comparable privacy and information-governance experience are highly valued but not required.
What Success Looks Like
- MAP has a clear enterprise privacy strategy and governance framework.
- Sensitive information is collected intentionally and protected throughout its lifecycle.
- Privacy responsibilities and decision rights are clearly understood.
- New technologies and initiatives incorporate privacy earlier in development.
- Vendor and third-party privacy risks receive consistent review.
- Consent and transparency practices become stronger and more standardized.
- Privacy incidents have clear escalation and response pathways.
- Team members receive practical privacy education.
- Executive leadership has meaningful visibility into material privacy risks.
- MAP continues to innovate without compromising the dignity, safety, or trust of the communities it serves.
Why This Role Matters
Privacy is ultimately about people. Behind every record is a child, parent, volunteer, donor, partner, or community member who has trusted Mentor A Promise with information about their life. The Chief Privacy Officer helps ensure that trust is earned every day through thoughtful systems, responsible decisions, and ethical stewardship. Protect trust. Safeguard dignity. Ensure data serves people—not the other way around.
What You’ll Gain
- C-suite experience shaping enterprise privacy strategy within a growing nonprofit
- Direct collaboration with the CEO and Executive Leadership Team
- Opportunity to build MAP’s privacy and data-protection infrastructure
- Exposure to privacy issues spanning youth services, technology, research, communications, partnerships, and nonprofit operations
- Collaboration with legal, cybersecurity, technology, and other teams