Job Purpose:
Personal Data Protection Officer responsible for overseeing the Personal Data Protection agenda within the entity and monitors compliance with Personal Data Protection Law and applicable regulations. Personal Data Protection officer ensures that personal data is processed in accordance with legal and regulatory requirements, organizational policies and recognized best practices. The PDPO acts as the main point of contact with regulators, individuals, and internal stakeholders on matters relating to personal data protection.
Key Accountabilities :
Inform and advise GIB, which acts as Data Controller or Data Processor, and its employees about their obligations to comply with the KSA PDPL and other applicable data protection laws within the organization. Be the first point of contact for the authorities and for individuals whose personal data is processed (employees, users, etc.). Furthermore, responsible for implementing the provisions of the Saudi Arabia Personal Data Protection Law, the Implementation regulations, and the Regulation of Personal Data – Transfer Outside the Kingdom. As well as, executing the decisions and instructions issued by the Competent Authority. Maintain and regularly update the Record of Processing Activities (RoPA), as per regulatory requirements. Through identifying, assessing and monitoring risks associated with personal data processing. Lead and supervise the completion of data protection impact assessments and recommend corrective actions and ensure risk mitigation measures are implemented across GIB's privacy ecosystem. Support and coordinate with Relevant Stakeholders (including Compliance Unit) to identify, reporting and manage personal data incidents or breaches, as well as ensure compliance with regulatory requirements. Monitor and report to top management on the organization's privacy compliance and current status periodically.. Oversee the resolution of violations and non-compliance across data privacy activities and ensure corrective measures are implemented. Manage and respond to data subject rights in line with the privacy regulations, whilst collaborating with Business Units to process requests within the regulatory timelines, and maintaining records of all requests. Work with legal and HR teams to develop appropriate sanctions for failure to comply with the privacy policies and procedures. Coordinate with Business Units, including procurement, to review and advise on third party data processing agreements for local/ international transfers, and advise Business Units on ensuring on-going compliance with such agreements. Evaluate personal data cross-border transfer requests and ensure compliance with regulatory requirements and safeguards. Oversee the design, implementation, maintenance and ongoing compliance of GIB's privacy policies and procedures. Periodically reviewing and, where necessary, updating the procedures set forth in GIB's Privacy Policy. Assign responsibilities and educate the employees on important compliance requirements and training staff involved in personal data processing and Develop Data privacy mitigation plan to mitigate identified privacy risks. Establish and maintain an internal privacy audit program in coordination with the internal audit function to assess the compliance of GIB’s data privacy activities. Supporting and advising Business Units responsible for developing and operating modern technological systems to ensure compliance with the applicable regulations.
Qualifications, Experience & Skills
Qualifications:
Bachelors in Law
Professional Certifications:
Certified Data Protection Officer (CDPO)
Experience:
2-4 years of legal background
Skills:
Legal research – Governance Risk and Control