JobsAisle
G

Data Protection Officer (DPO)

GSSTech Group

UAEAED 5,000-12,000/moToday
UAELegal ComplianceFull Time

Skills Required

GitCustomer Service

Job Description

The Data Protection Officer (DPO) is responsible for ensuring Organization compliance with applicable data protection and privacy regulations, overseeing lawful processing of personal and sensitive data, and acting as the primary liaison with regulators on data privacy matters.Key ResponsibilitiesRegulatory Compliance & GovernanceEnsure compliance with UAE Federal Decree-Law No. 45 of 2021 (Personal Data Protection Law – PDPL), UAE Data Office regulations, and applicable CBUAE requirements.Develop, implement, and maintain data protection policies, standards, and procedures.Embed privacy governance across insurance operations including underwriting, claims, customer service, digital channels, and analytics platforms.Advisory & OversightAdvise senior management and business units on data protection obligations and risk exposure.Support Privacy-by-Design and Privacy-by-Default across systems and processes.Review new initiatives involving personal data, cloud services, AI/ML, and third-party integrations.Data Subject Rights ManagementOversee processes for data subject access, correction, erasure, restriction, objection, and portability requests.Act as escalation authority for data privacy complaints and disputes.Incident & Breach ManagementLead assessment and response to data breaches and privacy incidents.Coordinate regulatory notifications and remediation actions within statutory timelines.Risk Assessments & DocumentationConduct Data Protection Impact Assessments (DPIAs).Maintain Records of Processing Activities (RoPA).Identify, assess, and mitigate privacy risks across systems, applications, and vendors.Third-Party & Cross-Border Data ManagementReview and approve Data Processing Agreements (DPAs).Ensure cross-border data transfers comply with PDPL and regulatory requirements.Training, Awareness & Audit SupportDrive organization-wide data privacy awareness and training programs.Support internal audits, external audits, and regulatory inspections.Regulatory Liaison & ReportingAct as the primary point of contact with the UAE Data Office and other regulators.Provide periodic compliance reports to senior management and the Board.Qualifications & ExperienceBachelor’s degree in Law, Information Security, Risk, Compliance, or related discipline.8–12 years of experience in data protection, privacy, or information governance.Prior experience in Insurance or BFSI sector preferred.Experience handling sensitive, financial, and health-related personal data.Certifications (Preferred)ISO/IEC 27001 Lead Auditor / ImplementerCIPP/E, CIPP/A, CIPM, or equivalent privacy certificationsIndependence & AuthorityThe DPO shall operate independently and without conflict of interest.Direct access to senior management and the Board is mandatory.#J-18808-Ljbffr