Key Responsibilities
- Leads the implementation of essential elements of the Data Protection Act, rights of data subjects, security of data processing and communication of data breaches;
- Evaluates the existing data management framework to identify areas of non-compliance and makes recommendations to rectify any issues;
- Submits an annual data protection impact assessment to the Information Commissioner, in relation to all personal data that are within the custody or control of the Commission and any affiliated entities that process personal data on behalf of the Commission;
- Devises, in conjunction with the Training Unit, Training Plans and delivering privacy training with staff members involved in data handling across all Divisions/Units, promoting a culture of compliance and raising employee awareness;
- Drives the development of an internal Data Protection Policy and Procedures and makes updates, as necessary, in consultation with the Information Commissioner;
- Conducts regular audits to ensure that the Commission processes personal data in compliance with data protection standards, as prescribed in the Data Protection Act;
- Manages sensitive information and maintains records of all data subjects, data assets and security incident management plan/activities carried out by the Commission;
- Ensures that the Commission’s existing policies and practices accord with the standards and requirements of the Data Protection Act;
- Serves as main point of a contact between the Commission and external stakeholders, including data protection authorities (Information Commissioner);
- Consults with the Commissioner, on a regular basis, to resolve any doubts about how the provisions of the Data Protection Act and any regulations under the Data Protection Act are to be interpreted and applied;
- Ensures that any breach of the data protection standards or any provisions of the Data Protection Act are dealt with in accordance with Sub-Section 5 of the Data Protection Act;
- Provides assistance to data subjects (citizens/agents of the State) in exercise of their rights in relation to the Data Protection Act;
- Provides expert advice to members of staff on data protection and compliance requirements;
- Prepares notices and/or reports to Parliament/Commissioner, if there are reasons to believe that the Commission is in breach of any requirements of the Data Protection Act, ensuring that recommendations for rectifying any such breach are documented;
- Reports to the Information Commissioner, any instance where the Commission has failed to rectify a breach of the Data Protection Act, within the prescribed timeframe, after the notification is received by the Parliament and the Commissioner;
- Fulfils all obligations/requirements outlined in the Data Protection Act in regard to the role of the Data Protection and Systems Management Officer;
- Keeps abreast of changes or amendments of the Data Protection Act and related Government regulations and makes recommendations, where necessary;
- Performs other related duties assigned.
Required Knowledge, Skills, and Competencies
- Strong knowledge of local Data Protection Act (2020) and local data privacy regulations
- Good understanding of international privacy frameworks and data protection legislations
- Excellent interpersonal and management skills
- Good oral and written communication and presentation skills
- Detail oriented, excellent planning and organization skills, and ability to learn quickly
- Ability to use independent judgment and discretion
- Comprehensive knowledge of the relevant laws, policies and procedures applicable to the Commission in the execution of its functions
- Comprehensive knowledge of cyber security risks and information security standards
- Comprehensive knowledge in computer systems operation, hardware support and maintenance and computer architecture
- Ability to lead training sessions and workshops with persons of all levels
- Ability to work well under pressure and manage sensitive and confidential information
- Ability to conduct role with integrity and high professional ethics
Minimum Required Qualification and Experience
- Undergraduate Degree in Law, Compliance, Information Technology, IT Security or related discipline;
- Specialised training or certification in Data Protection, Information or Risk Management;
- One (1) Data Protection and/or Privacy Certification, such as CIPP or CIPT;
- Three (3) years’ working experience in data protection compliance, risk management or related field.
Please note that only shortlisted applicants will be contacted.