Job Description:
Purpose of the position
Support the Data Protection Officer in implementing and maintaining the Bank’s data privacy framework through a combination of legal, regulatory and information technology knowledge. The role will assist with legal and regulatory research, policy and notice drafting, privacy assessments, contractual reviews, data mapping, technology-related privacy reviews, issue tracking and maintenance of compliance evidence.
Primary Responsibilities
- Support privacy legal and regulatory research, including review of applicable data protection requirements, regulatory developments and internal compliance obligations; prepare structured summaries and implementation trackers for DPO review.
- Assist in drafting and periodic review of privacy policies, procedures, consent wording, privacy notices, forms, internal guidance and other privacy-related legal documentation.
- Support review of contracts, data processing clauses, confidentiality terms and third-party privacy requirements in coordination with Legal, Procurement, Information Security and relevant business teams.
- Conduct or support Privacy Impact Assessments / DPIAs for new or changed products, processes, systems and technologies, including identification and documentation of legal and technology-related privacy risks.
- Support data flow mapping, data inventory, records of processing and review of personal data collection, use, storage, sharing, retention and disposal across systems and processes.
- Participate in privacy-by-design reviews for technology projects and change initiatives; assess whether privacy requirements are appropriately reflected in system and process design.
- Support privacy incident assessment, data subject request / grievance handling, awareness activities and periodic DPO reporting.
Profile description
Knowledge, Skills, Experience & Qualifications
- Knowledge Requirements: Working knowledge of data protection and privacy requirements, legal research, contract and policy review, technology systems, data lifecycle concepts, privacy-by-design, DPIA / PIA, data subject rights, grievance handling and basic information security controls.
- Specialist / technical skills: Legal and regulatory research; drafting and document review; contract clause review; data flow mapping; privacy assessment; technology risk understanding; issue tracking; Microsoft Office and structured record management. Familiarity with privacy management or GRC tools is desirable.
- Behavioural / management skills: Analytical thinking, attention to detail, written and verbal communication, documentation discipline, stakeholder coordination, confidentiality, ownership and ability to work under the guidance of the DPO.
- Education & Qualifications: Relevant graduate or post-graduate qualification. A combined legal and technology background is preferred. Relevant privacy, technology or security certification may be desirable.
Requirements: