Virtual Privacy & Security Leadership
VPO, Privacy Lawyer, or DIY: Who Should Own Privacy in a Growing Company

The question every growing company eventually has to answer
In the early days, privacy tends to belong to whoever has the bandwidth. A co-founder writes the first privacy policy over a weekend. The head of engineering picks where customer data is stored. Someone in operations fields the occasional question about consent or retention. It works, more or less, because the stakes are still small and the surface area is narrow.
Then the company grows. A health-sector prospect sends a vendor security and privacy review with sixty questions. A government RFP asks who your designated privacy officer is. PIPEDA expects an accountable individual by name, and Quebec's Law 25 makes a person in charge of personal information mandatory. Suddenly privacy is not a weekend task. It is a function that needs a clear, named owner.
The honest answer to 'who should own this' is that it depends on what you are actually trying to solve. The three realistic options, a virtual privacy officer (VPO), an external privacy lawyer, or keeping it in-house (DIY), solve different problems. This guide walks through what each is genuinely good at, where each falls short, and how to match the choice to your stage and risk.
What 'owning privacy' actually involves
Before comparing the options, it helps to be precise about the job. Owning privacy is not a single task. It is a standing responsibility made up of several distinct kinds of work, and conflating them is the most common reason companies pick the wrong owner.
- Accountability: being the named person regulators and customers can point to. PIPEDA requires organizations to designate someone accountable for compliance, and Quebec's Law 25 makes a person in charge of the protection of personal information mandatory (by default the person with the highest authority, who may delegate the role in writing).
- Program building: standing up the policies, records of processing, retention schedules, vendor reviews, and training that turn intent into a functioning program.
- Operational decisions: answering the day-to-day questions. Can we use this analytics tool? Do we need a privacy impact assessment for this feature? How do we respond to an access request?
- Assessments: running privacy impact assessments (PIAs), threat risk assessments (TRAs), and the documentation enterprise and public-sector buyers ask for.
- Legal interpretation: reading a specific clause in PHIPA, FOIPPA, the GDPR, or a contract and giving a defensible legal opinion on what it requires.
- Incident response: leading the privacy side of a breach, including notification obligations to the Office of the Privacy Commissioner of Canada, provincial regulators, or affected individuals.
Option 1: DIY (keep it in-house)
Doing it yourself means assigning privacy to an existing employee, often a founder, an operations or legal generalist, or a security lead, alongside their day job. For very early-stage companies with low-sensitivity data and no regulated customers, this is a reasonable starting point. You know your own product better than anyone, and the first version of a privacy program does not need to be elaborate.
DIY breaks down predictably, and usually around the same triggers. The internal owner can keep policies current, but they rarely have the time to run a proper PIA, the depth to interpret PHIPA versus PIPEDA versus Law 25, or the experience to answer a hospital's vendor review without guessing. The work also competes with their real job, so it slips to whenever a deal or an audit forces it.
- Best when: data sensitivity is low, you have no regulated (healthcare or government) customers yet, and privacy questions are infrequent.
- Watch for the tipping point: your first enterprise security questionnaire, your first healthcare or public-sector prospect, expansion into a new jurisdiction, or an investor asking who owns privacy.
- The hidden cost: senior people doing unfamiliar compliance work slowly and anxiously is expensive in time and risk, even though it never shows up as a line item.
Option 2: A privacy lawyer
A privacy lawyer is the right call when the question is fundamentally a legal one. If you need a defensible interpretation of a statute, a contract negotiated, an opinion you can rely on under privilege, or representation in a regulatory investigation or dispute, that is lawyer territory, and a VPO or an internal owner should not be improvising in their place.
Where lawyers are less well suited is the ongoing operational and program work. Most privacy counsel bill by the hour and are engaged for discrete questions, not for running your day-to-day program, maintaining your records, training your staff, or sitting in your vendor-review calls week after week. Using a lawyer as your standing privacy operations team is both expensive and a poor fit for the work involved.
- Best when: you need a binding legal interpretation, contract language, privilege, or regulatory representation.
- Less suited to: continuous program operation, assessments, training, and the steady cadence of vendor reviews and product questions.
- Practical note: most mature programs keep a privacy lawyer on call for the genuinely legal questions rather than as the everyday owner. The two roles complement each other rather than compete.
Option 3: A virtual privacy officer (VPO)
A virtual privacy officer is a fractional, outsourced privacy leader who acts as your designated privacy officer and runs the program, without the cost of a full-time executive hire. This is the option that maps most directly onto owning privacy as defined above: accountability, program building, operational decisions, assessments, and breach leadership, delivered on an ongoing retainer rather than ad hoc.
The model fits growing companies because it scales with you. A seed-stage SaaS company selling into clinics does not need a six-figure full-time chief privacy officer, but it does need someone who can be the named officer, stand up a credible program, and answer a hospital's review with authority. A VPO provides that continuity and that name, while pulling in a privacy lawyer for the narrow legal questions that genuinely require one.
It is worth being clear about what a VPO is not. A VPO owns privacy, not security engineering. That distinction matters when you are also weighing security leadership, which is a separate role with its own scope.
- Best when: you have regulated or enterprise customers, recurring privacy work, and need a named, accountable officer but cannot justify a full-time hire.
- What you get: continuity, a real program rather than a binder of templates, and someone who already understands how frameworks and laws such as PHIPA, FOIPPA, PIPEDA, and Law 25 differ across jurisdictions.
- Cost reference: Privacy Horizon's VPO service starts from CAD $2,200 per month, far below a full-time executive salary and more predictable than hourly legal work.
How to decide, and why it is rarely either/or
The most useful reframe is to stop treating these as three competing candidates for one chair. In a healthy program they are layers. DIY handles the simplest day-to-day, a VPO owns the program and accountability, and a privacy lawyer is on call for the legal questions that need a lawyer. The decision is really about which layer is missing for your stage and risk.
A quick diagnostic: if your data is low-sensitivity and questions are rare, DIY is fine for now. If you have a specific, contained legal question, call a lawyer. If privacy has become a recurring function, driven by regulated customers, vendor reviews, assessments, and the need for a named officer, you need a VPO, with a lawyer available for the genuinely legal edge cases.
Two further comparisons come up often, and they are worth resolving deliberately rather than by default. The first is VPO versus privacy lawyer, where the dividing line is operational ownership versus legal interpretation. The second is whether you need privacy leadership, security leadership, or both, since a VPO and a virtual CISO solve different halves of the same maturity problem and growing companies frequently need both.
The takeaway
Privacy stops being a side task long before most companies notice. The signal is rarely a dramatic event. It is the quiet accumulation of vendor reviews, regulated prospects, new jurisdictions, and questions nobody has clear time to answer well. At that point, the question is no longer whether to assign an owner, but which kind.
Keep it DIY while the stakes are genuinely small. Bring in a privacy lawyer for the questions that are truly legal. And when privacy has become a standing function your business depends on, give it a real, named owner, most often a VPO, so the next security questionnaire, healthcare deal, or regulator inquiry meets a program that is already running rather than a scramble. If you are weighing these options for your own company, we are happy to help you work out which layer you are missing.
Related reading
- VPO vs privacy lawyer which do you need
- VPO vs vCISO do you need one or both