Manager - Data Protection & Privacy
Job descriptions & requirements
Education:
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Data Science or related course.
A certificate in Data privacy will be an added advantage.
Work Experience
5 years’ experience in a relevant field.
At least 1–3 years in data privacy, data governance, compliance, or cybersecurity.
Familiarity with data protection laws (e.g., Uganda’s Data Protection and Privacy Act).
Oversight & Assurance
- Provide independent oversight of data protection and privacy practices across the organization.
- Monitor and assess the effectiveness of first-line controls implemented by IT, business units, and data owners.
- Review and challenge privacy risk assessments, data protection impact assessments (DPIAs), and control designs.
Policy & Framework Development
Support the development and periodic review of data privacy policies, standards, and procedures.
Ensure alignment with MTN Group frameworks and Uganda’s Data Protection and Privacy Act.
Risk Identification & Reporting
Identify emerging privacy risks and trends related to technology, data usage, and regulatory changes.
Maintain a privacy risk register and escalate significant risks to senior management and the Board.
Prepare periodic compliance reports and dashboards for internal stakeholders.
Second Line Monitoring & Testing
Conduct thematic reviews and compliance monitoring of data handling practices.
Validate the adequacy of controls around data access, retention, sharing, and disposal.
Collaborate with Internal Audit (third line) to ensure coordinated assurance activities.
Regulatory Engagement & Advisory
Act as a liaison with regulators (e.g., PDPO, NITA-U, UCC) on privacy-related matters.
Provide advisory support to business units on regulatory interpretations and compliance obligations.
Coordinate responses to regulatory inspections and inquiries related to data privacy.
Awareness & Capacity Building
Drive privacy awareness campaigns and targeted training for staff.
Build capacity within the organization to understand and manage privacy risks effectively.
Promote a culture of accountability and ethical data use.
Incident Oversight & Escalation
Oversee the management of data breaches and privacy incidents, ensuring timely escalation and resolution.
Review root cause analyses and remediation plans from the first line.
Ensure lessons learned are integrated into risk mitigation strategies.
Important safety tips
- Do not make any payment without confirming with the BrighterMonday Customer Support Team.
- If you think this advert is not genuine, please report it via the Report Job link below.