We are looking to hire a Data Privacy Specialist who will be responsible for embedding privacy-by-design principles across enterprise data management, data ingestion, data platforms, and cross-vertical data sharing for our client based in Dubai, UAE, which is one of the largest companies in the region.
This position is a contract role with an initial duration of 12 months (renewable) and a remote work environment.
The Data Privacy Specialist will be responsible for assessing personal-data processing activities, supporting data inventories and Records of Processing Activities (RoPA), coordinating Data Protection Impact Assessments (DPIAs), and translating privacy requirements into practical technical and operational controls. The role will work closely with Data Owners, Data Governance, Technology, Security, Legal, and delivery teams to ensure that personal and sensitive data is managed in compliance with applicable privacy requirements and enterprise standards.
Key responsibilities:
- Embed privacy-by-design and privacy-by-default principles across MDM, data ingestion, enterprise data platforms, and cross-vertical data sharing initiatives.
- Assess personal and sensitive data processing activities and identify associated privacy risks and control requirements.
- Support the development and maintenance of data inventories, data maps, and Records of Processing Activities (RoPA).
- Coordinate and support Data Protection Impact Assessments (DPIAs) and privacy risk assessments for new and existing data initiatives.
- Define and document requirements relating to lawful purpose, data minimisation, retention, masking, access controls, and appropriate use of personal data.
- Review data ingestion and integration initiatives to ensure appropriate privacy controls are incorporated into solution designs.
- Assess cross-border data transfers, offshore access, and third-party data processing risks, and recommend appropriate controls and mitigation measures.
- Translate privacy and regulatory requirements into practical technical and operational controls for Data Owners and delivery teams.
- Review and provide guidance on data classification, retention, data-subject rights, access controls, and privacy-enhancing measures.
- Support vendor and third-party privacy reviews, including assessment of data processing arrangements and associated risks.
- Work with Technology and Security teams to align privacy requirements with RBAC, access management, security controls, and enterprise data governance practices.
- Provide privacy guidance for data use cases involving AI, analytics, data sharing, and enterprise data platforms, including Palantir Foundry.
- Maintain privacy risk and action registers, track remediation activities, and monitor closure of identified privacy gaps.
- Maintain comprehensive evidence and documentation to support internal governance, audits, regulatory reviews, and approval processes.
- Prepare privacy review packs, DPIAs, control requirements, and approval evidence for relevant data initiatives.
- Provide practical privacy guidance and awareness to Data Owners, technology teams, and project stakeholders.
- Support the development and adoption of privacy standards, procedures, and control frameworks across the enterprise.
- Participate in case assessments involving personal-data ingestion, cross-border access, data minimisation, retention, RBAC, and risk acceptance.
- Bachelor’s degree in Law, Data Privacy, Information Security, Computer Science, IT, Data Governance, or a related field.
- Minimum 8 years of experience in data protection, data privacy, privacy governance, or a closely related field, with practical experience in technology and data-governance implementation.
- Strong practical knowledge of privacy governance, DPIAs, privacy risk assessments, data mapping, and data classification.
- Experience defining and implementing requirements relating to data minimisation, retention, masking, access controls, and lawful processing.
- Strong understanding of data-subject rights, privacy risk management, third-party/vendor privacy assessments, and cross-border data-transfer risks.
- Experience translating legal and regulatory privacy requirements into practical technical and operational controls.
- Exposure to UAE privacy requirements and multi-jurisdictional data protection regulations is required.
- Experience working with enterprise data platforms, data management environments, and large-scale data ecosystems.
- Experience with Palantir Foundry or similar enterprise data platforms is highly desirable.
- Good understanding of AI governance and privacy considerations relating to AI and data-driven use cases.
- Working knowledge of information security and RBAC concepts, including how privacy requirements integrate with access and security controls.
- Knowledge of privacy-enhancing technologies and techniques is preferred.
- Strong stakeholder management and communication skills, with the ability to work effectively across Data, Technology, Security, Legal, Governance, and business teams.
Preferred certifications:
- CIPP/E certification is preferred.
- CIPM certification is preferred.
- Other recognised data privacy, data protection, or information governance certifications will be considered.
Availability:
- Preference will be given to candidates available immediately or within a short notice period upon accepting the offer.