IFZA Dubai logo

Data Protection Officer

IFZA Dubai
1 hour ago
Full-time
On-site
Dubai, Dubai, United Arab Emirates
Data Protection Officer

Summary

The Data Protection Officer (DPO) is pivotal in leading IFZA’s privacy and data protection initiatives, ensuring compliance with legal and regulatory standards. This role provides expert advice on privacy obligations, governance, and risk management, fostering a culture of responsible information handling throughout the organization. Collaborating with cross-functional teams, the DPO monitors compliance, supports business initiatives, and advises on privacy-related risks and controls. This position is crucial in advancing IFZA’s privacy program, driving continuous improvement, and supporting strategic projects requiring data protection expertise.

Key Responsibilities

Privacy Governance
  • Oversee the enhancement of IFZA's privacy and data protection framework, ensuring alignment with legislation and business objectives.
  • Review and update policies and procedures to comply with legislative and business requirements.
  • Develop new privacy standards in response to operational changes or regulatory developments.
  • Maintain documentation to demonstrate compliance with data protection legislation.
  • Manage IFZA's Record of Processing Activities (ROPA) and associated privacy documentation.
  • Monitor privacy legislation developments and communicate changes to management.

Advisory and Business Support

  • Provide guidance on the collection, use, storage, sharing, and retention of personal information.
  • Participate in projects involving new systems or business initiatives processing personal data.
  • Assist in identifying privacy risks and implementing controls for new processes.
  • Support contract reviews involving third-party processing of personal information.

Compliance Monitoring

  • Conduct reviews to assess compliance with internal privacy requirements.
  • Monitor corrective actions from audits or compliance reviews.
  • Maintain records demonstrating ongoing compliance.
  • Prepare management reports on privacy compliance status.

Privacy Impact Assessments

  • Coordinate Privacy and Data Protection Impact Assessments as needed.
  • Identify privacy risks associated with new products or operational changes.
  • Recommend measures to mitigate identified risks.
  • Monitor the implementation of mitigation actions.

Data Subject Rights

  • Manage requests from individuals exercising their data protection rights.
  • Liaise with departments to obtain required information.
  • Ensure timely acknowledgment, assessment, and response to requests.
  • Maintain a register of requests and outcomes.

Personal Data Incidents

  • Coordinate responses to personal data breaches.
  • Collaborate with Information Security and business units to assess incidents.
  • Maintain records of privacy incidents and corrective actions.
  • Assist with regulatory notifications as required.

Training and Awareness

  • Deliver privacy awareness initiatives across the organization.
  • Assist with induction training for new employees.
  • Provide targeted guidance to departments handling high-risk personal information.
  • Promote awareness of information handling and confidentiality responsibilities.

Reporting

  • Prepare management reports summarizing privacy activities, risks, incidents, and initiatives.
  • Escalate significant privacy risks to the Head of Group Compliance.
  • Support regulatory inspections and audits related to privacy and data protection.


Requirements

Essential
  • Bachelor’s degree in Law, Compliance, Business, Information Security, or a related field.
  • 4-5 years of experience in data protection, privacy, governance, or regulatory compliance.
  • Strong understanding of UAE Personal Data Protection legislation and international privacy principles.
  • Experience in drafting policies, procedures, and governance documentation.
  • Excellent written and verbal communication skills.
  • Ability to work effectively across multiple business functions.
  • High level of discretion in handling confidential information.

Desirable

  • Professional certification in privacy or data protection.
  • Experience in financial services, regulated entities, or corporate service providers.
  • Experience supporting regulatory inspections or internal audits.


Benefits

  • International Team (60+ nationalities)
  • 24 working days leave
  • Birthday leave
  • Annual flight home
  • Life Insurance plan
  • Medical Insurance plan(with an option to upgrade at your own cost)