An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Marriott Vacations Worldwide is seeking a Director of Data Privacy to partner with the VP PCRM and drive global privacy compliance across 80+ countries. You will lead privacy operations, risk assessments, policy development, and program governance, coordinating with Security, Legal, HR, and IT to embed privacy by design throughout the enterprise.
The role covers GDPR, CCPA, APPI, PDPA, and dpIAs/ TIAs, with a focus on building trust with customers and stakeholders through transparent practices
As a member of the professional staff, contributes a high level of specialized knowledge and skill in a discipline (e.g., Accounting, Finance, Human Resources, Information Technology, Operations Planning & Support, Sales & Marketing) area to support department and/or function objectives. Generally, works with considerable independence, developing operating plans and related operational processes for own department in alignment with broader business objectives.
The Director, Data Privacy, will report to and assist the VP, Privacy Compliance and Risk Management (PCRM) to ensure compliance with privacy laws and regulations globally. The role maintains an awareness of federal, state, and international privacy laws and standards and applies this knowledge to MVWC business processes and systems including information privacy automation technologies and tools. The role is responsible for responding to and proactively managing privacy various aspects of the global privacy program. The privacy program is responsible for ensuring privacy is part of the MVW fabric which stretches across 80+ countries.
The role should have a solid understanding of key privacy laws across the globe such as GDPR, APPI, CCPA, CPRA, and PDPA.. Ares of involvement may range from privacy operations (DSRs, Incident Response, Notice & Policy), Privacy Compliance and Risk (PIA, TIA, DPIA, ROPA), Privacy Architecture and Engineering (Cookies, OneTrust, PET enablement, PbD), as well as AI risk assessments. This includes, but is not limited to, managing others’ daily work, overseeing key programs, development, implementation and maintenance of policies and procedures to ensure MVW is operating transparently and building trust with our customers.
Performs more complex quantitative and qualitative analysis for business processes and/or projects. Often manages small projects, business processes or parts of larger ones. Responds to, solves and makes decisions on more complex/non-routine business requests with limited to moderate risk. Responsible for own work and contributing to team, department and/or business results. May direct work of non-management staff. Assists more senior associates in achieving business results by:
Demonstrates an awareness of personal strengths and areas for improvement and acts independently to improve and increase skills and knowledge. Performs other duties as appropriate.
Oversee privacy related business process data mapping for global regulations (including GDPR and CCPA as examples) Oversee privacy reviews of new systems, applications, and third-party data sharing relationships Manage contract reviews and input for privacy-related engagements Maintain and update privacy process and related documentation across the enterprise Assist in the drafting, implementation and maintenance of the company’s information privacy policies and procedures Manage recertification process of privacy policies, and global regulation documentation (including GDPR and CCPA as examples) Development and maintenance of Privacy Office SharePoint site for the enterprise Facilitate development and maintenance of privacy training materials and other communications to raise awareness and drive cultural change for data privacy awareness with associates and third parties Partner with Information Security, Procurement, Human Resources, Global Technology, Law department, and Business Relationship Managers to conduct investigations, privacy by design reviews, intake assessments and recommend opportunities for improvements Optimize, configure, and manage the technology tools used to support global privacy program Recommend improvements and automation in privacy processes that can be enhanced through technology Lead MVW’s efforts to improve customers’ data transparency needs As needed, perform initial and ongoing privacy risk assessments (e.g. TIAs, PIAs, DPIAs, AI Risk Assessments) and conduct related ongoing compliance and risk monitoring activities in coordination with the entity’s other compliance and operational assessment functions. As needed, lead and/or support privacy investigations. Act as a key advisor in the development of risk management and risk treatment plans while aligning with Business risk appetite, and work with relevant Risk Control owners for implementation and ongoing treatment, as required. Assist in the drafting, implementation and maintenance of the company’s information privacy policies and procedures Monitor adherence to MVWC’s risk management framework and measuring compliance risk ensuring that reviews are conducted consistently across the enterprise on a regular basis to confirm that controls identified are operating effectively Design and implements complex analyses of comparative and historical data, related to current status and identify trends. Maintain an enterprise record of processing activities (ROPAs) Assist in maintaining and enhancing global cookie and similar technology compliance. Privacy Operations Provide privacy program leadership for Privacy Operations Lead and investigate privacy incidents Monitor and oversee the management of the Privacy Mailbox Collaborate with the Law department and other stakeholders on privacy matters as needed Review Data Loss Prevention quarantined files and recommend disposition Assist in auditing of required federal subpoenas for Right to Financial Privacy Act Manage and document the processes required for Data Subject Access Requests (DSARs) and conduct required follow up. Manage and oversee the consent management platform Partner with the business to strategically implement a consent plan that empowers cross-business marketing. Privacy Risk and Compliance Provide privacy program leadership for Privacy Compliance & Risk Management Lead the documentation of privacy risks Oversee that privacy risks in MVWC are effectively identified, measured, monitored, and controlled, in consistent ways with the organization’s risk appetite statement and applicable policies and procedures established within the risk management and governance framework Collaborate with the Law department and other stakeholders on privacy matters as needed Collaborate and develop synergies with the Enterprise Risk Management team and other stakeholders on privacy risk matters as needed Lead the design, development and delivery of ongoing privacy metrics as it pertains to privacy compliance and risk management Lead as a privacy risk management subject matter expert and consult with internal and external stakeholders on privacy control initiatives. Manage and maintain Data Privacy Impact Assessments (DPIAs), Transfer Impact Assessments (TIAs), Privacy Impact Assessments (PIAs), AI Risk Assessment on existing and new processing activities of personal information and update flagged risks and mitigating treatment plans as needed Manage privacy risks during business decision-making, ensuring the protection of the organization’s reputation and assets, and exercise sound ethical judgment in personal and professional conduct, and transparently escal...
Bachelor’s degree required or at least 7 years of privacy experience; Advanced degree preferred. Data Privacy certification such as Certified Information Privacy Professional (CIPP); or Certified Information Privacy Manager (CIPM); preferred
At least 10 years of progressive professional experience in Privacy, Legal, Compliance, Information Security, Technology, Audit, Risk Management or related fields Proven experience in the area of Privacy, Information Security, Risk Management, Technology, SOX, or similar field Strong personal, analytical and communications skills. Demonstrated ability to translate regulations and/or standards into workable and implementable solutions. Proven experience with change management in an international organization. Experience using the One Trust or other privacy management platform preferred. Multilingual capabilities (read, speak and write), a plus.
Successful candidates should possess knowledge and experience and demonstrate strong leadership and relationship skills as follows:
Marriott Vacations Worldwide is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. Where meaningful moments are made together. Our associates want more than fulfilling work. Like our Owners, Members and guests around the world, they want fulfilling lives. Vacations expand our world to new places, new possibilities, new connections. Along the way, they help us discover our best selves. Great vacations are the embodiment of a life, fulfilled. Marriott Vacations Worldwide (NYSE: VAC) is a leading global vacation company. While our numbers tell some of the story, the heart of our success comes from the quality – and exceptional longevity – of our relationships with our associates and customers. Join us on our journey. FOR A LIFE FULFILLED. Creating vacations that move you. 20,000+ Associates worldwide Vacation Ownership 7 Iconic Brands Approximately 120 Vacation Ownership Resorts 700,000+ Owner families 90%+ Guest satisfaction score Exchange & Third-Party Management More than 3,200 affiliated resorts in over 90 countries and territories Approximately 1.6 million exchange network members