Head of Data Governance

xLoop Digital Middle East

Doha

On-site

QAR 300,000 - 520,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

xLoop Digital Middle East, a newly established education venture in the GCC, is building technology and computing education programmes for secondary schools and seeks a founding-team Data Protection & Compliance lead based in Doha. You will own governance, risk and security for the platform, shaping policy with product and engineering, and interfacing with regulators, schools and parents.

This role is independent from the product line, reporting to the MD with direct escalation to the

Qualifications

  • 5–10 years in data protection, privacy, risk, or information governance; initiative handling built programs.
  • Experience with children’s data in education and regional data regimes is a plus.
  • Familiar with GCC data protection regimes and regulatory expectations.

Responsibilities

  • Own data governance, risk, and security across products and releases.
  • Develop DPIA processes and risk remediation tracking.
  • Lead policy design, training, and culture around privacy and governance.
  • Interface with regulators, school leaders, and parents as the external face.
  • Drive cross-functional alignment with product and engineering.

Skills

Data governance
Privacy
Risk management
Information governance
DPIAs
Policy development
Regulatory liaison

Tools

ISO 27001

Job description

A newly established education venture is building technology and computing education programmes for secondary schools across the GCC — delivered in partnership with schools and taught by its own employed specialist teachers. This is a founding-team appointment, based in Doha, reporting to the Managing Director with direct escalation to the Founder.

Why this role matters

The programmes will handle the personal data of children at scale. This role owns data governance, risk, and security — across both people and technology — for everything the organisation builds, with the authority to halt a release, refuse a supplier, or escalation directly. Most of the frameworks themselves aren't the hard part — that knowledge exists, and this role will draw on it. The hard part, and the actual job, is enforcement: making sure what's designed on paper is what actually ships, and holding the line when it's commercially inconvenient to do so. The function doesn't exist yet. Whoever takes this on will define it, not inherit it — and will spend the early part of the role working with the product and engineering teams, shaping the roadmap so compliance is built in from the start, before formalising the organisation-wide policy structure around it. It reports outside the technology and product line by design; that independence is the point of the appointment.

What you'll own
  • Data governance: lawful basis and consent architecture for minors' personal data, including parental and school consent flows
  • Risk: data protection impact assessments (DPIAs) for the platform and every new processing activity; enterprise, operational and third-party risk identification, assessment and remediation tracking
  • Security: safeguarding-by-design and security-by-design review of product and content releases before they reach schools, working closely with engineering
  • Retention, minimisation and deletion policy — including what happens when a student leaves the programme
  • Data residency and cross-border transfer requirements as a core design constraint
  • Supplier and processor due diligence across every third party touching student data
  • Breach response planning, rehearsal and ownership; input into incident response and business continuity
  • The external-facing role — presenting the organisation’s approach to regulators, school leaders and parents
  • Policy, training and culture across the organisation — for teaching staff as well as product and technical teams
What we're looking for
  • 5–10 years in data protection, privacy, risk, or information governance — ideally with a framework or programme you built and operated yourself, even at small scale
  • Some direct exposure to children's personal data in education, health, social care, or child-facing technology is a strong plus; a general privacy/security/GRC background with the right mindset will also be considered
  • Working knowledge of GCC data protection regimes, or a comparable framework with a credible path to regional competence quickly
  • Comfort working consultatively — influencing a product roadmap early, then formalising the policy structure once the shape of the business is clearer
  • A track record (however junior) of holding a position under commercial pressure — a decision you pushed back on, and what followed
Strong advantage
  • Arabic language capability, professional or native — this role involves regular school, parent and regulator contact
  • GCC experience, particularly government or regulator-facing work
  • A recognised privacy, risk, or information security qualification (e.g. CIPM, CIPT, CISM, CRISC, ISO 27001 Lead Implementer/Auditor)
  • Experience building a function at foundation stage, where the framework didn't exist yet

Full time, based in Doha, on-site. Competitive package commensurate with experience, with relocation support where relevant.

This role suits someone who is comfortable being the person who says no — and can explain why in terms a head teacher or a parent understands just as easily as a product lead. It's genuinely two disciplines (governance/privacy and risk/security) folded into one seat because, at this stage, neither is a full-time job on its own — so the person who thrives here will move fluidly between policy and product conversations. For a period, it's a role of one, with external specialist support — not a settled framework to administer.

Appointment is subject to background and reference checks appropriate to a child-facing role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Data Privacy & Governance Lead
Chief Data Privacy & Governance Lead

xLoop Digital Middle East • Doha

On-site
QAR 300,000 - 520,000
Senior Data Protection & Privacy Specialist
Senior Data Protection & Privacy Specialist

Gender • Doha

On-site
QAR 180,000 - 260,000
Senior Data Protection & Privacy Specialist
Senior Data Protection & Privacy Specialist

Experience • Doha

On-site
QAR 291,000 - 437,000
Data and Systems Administrator at International School of London Qatar
Data and Systems Administrator at International School of London Qatar

International School of London Qatar • Doha

On-site
QAR 120,000 - 180,000
Senior Data Governance & Classification Specialist
Senior Data Governance & Classification Specialist

Employment • Doha

On-site
QAR 180,000 - 240,000
Senior Data Protection & Privacy Specialist
Senior Data Protection & Privacy Specialist

BAE Systems Strategic Aerospace Services WLL, a limited liability company • Doha

On-site
QAR 250,000 - 450,000
EMEA Assurance Lead Doha, Qatar Apply →
EMEA Assurance Lead Doha, Qatar Apply →

Scale AI, Inc. • Doha

On-site
QAR 309,000 - 437,000
Inclusive workplace
Equal opportunity employment
Senior Analyst
Senior Analyst

Experience • Doha

On-site
QAR 250,000 - 350,000
Senior Data Governance & Classification Specialist
Senior Data Governance & Classification Specialist

Gender • Doha

On-site
QAR 40,000 - 68,000
GRC Senior Analyst/ Specialist
GRC Senior Analyst/ Specialist

BAE Systems • Qatar

On-site
QAR 240,000 - 320,000