وظيفة أخصائي خصوصية بيانات شاغرة لدى Hastraa Arabia Limited في الرياض
تفاصيل الوظيفة
تعلن شركة Hastraa Arabia Limited عن توفر وظيفة أخصائي خصوصية البيانات (Data Privacy Specialist) في الرياض، السعودية.
نبذة عن الوظيفة
نبحث عن خبير متمرس في خصوصية البيانات لقيادة ودعم برنامج خصوصية وحماية البيانات في المؤسسة، بما يتوافق مع نظام حماية البيانات الشخصية السعودي (PDPL) ولائحته التنفيذية، ومتطلبات NDMO، وأنظمة مؤسسة النقد العربي السعودي (SAMA)، والأطر السعودية الأخرى ذات الصلة بحماية البيانات والأمن السيبراني. سيكون المرشح الناجح مسؤولاً عن تطوير وتشغيل سياسات الخصوصية، وإجراء تقييمات الأثر، والحفاظ على سجل أنشطة المعالجة (RoPA)، وإدارة مخاطر خصوصية البيانات، والإشراف على امتثال الأطراف الثالثة، ودعم حقوق أصحاب البيانات، وإدارة نقل البيانات عبر الحدود، وتقديم المشورة لأصحاب المصلحة في الأعمال والتقنية بشأن متطلبات الخصوصية. يتطلب هذا الدور معرفة قوية بالبيئة التنظيمية السعودية، خاصة في قطاع البنوك/الخدمات المالية، بالإضافة إلى القدرة على التعامل بفعالية مع الإدارة العليا والجهات الرقابية والفرق القانونية والتقنية والموردين وأصحاب المصلحة.
المهام والمسؤوليات
- تطوير وتنفيذ وتحسين سياسات وإجراءات ومعايير ومبادئ وأدلة وقوالب خصوصية البيانات وفقاً لنظام حماية البيانات الشخصية السعودي (PDPL) ولائحته التنفيذية ومتطلبات NDMO والمتطلبات التنظيمية المطبقة.
- تقديم المشورة للمؤسسة والموظفين بشأن متطلبات معالجة البيانات الشخصية وجمعها واستخدامها وتخزينها ومشاركتها والاحتفاظ بها والتخلص منها.
- ضمان امتثال العمليات التجارية والسجلات والتطبيقات والأنظمة والتقنيات التي تحتوي على بيانات شخصية لمتطلبات الخصوصية المطبقة.
- إنشاء وصيانة إطار شامل للامتثال لخصوصية البيانات.
- تحديد معايير ومتطلبات الخصوصية التي يجب أن تتبعها فرق أمن المعلومات وتقنية المعلومات وإدارة البيانات والأعمال.
- مراجعة ممارسات الخصوصية وتعزيزها بشكل دوري لمواكبة التغييرات التنظيمية والتجارية والتقنية.
- قيادة أنشطة تقييم تأثير الخصوصية (PIA) وتقييم تأثير حماية البيانات (DPIA) في جميع أنحاء المؤسسة.
- إجراء وصيانة مستودع سجل أنشطة المعالجة (RoPA) لجميع أنشطة معالجة البيانات الشخصية ذات الصلة.
- تحديد أنشطة المعالجة التي تتطلب DPIAs بناءً على نتائج PIA والمتطلبات التنظيمية المطبقة.
- إجراء DPIAs والتوصية بالضوابط التقنية والتنظيمية المناسبة للتخفيف من مخاطر الخصوصية المحددة.
- إجراء رسم خرائط تدفق البيانات لتوثيق دورة حياة البيانات الشخصية من الجمع عبر المعالجة والتخزين والمشاركة والأرشفة والإتلاف.
- دعم الأعمال في تحديد وتحديد أولويات أنشطة معالجة البيانات الشخصية الحرجة وعالية المخاطر.
- تطوير وصيانة سجل شامل لمخاطر خصوصية البيانات يغطي المخاطر المحددة وأصحاب المخاطر وخطط المعالجة وتواريخ الإغلاق المستهدفة وحالة التصحيح.
- تقييم مخاطر الخصوصية المرتبطة بالعمليات التجارية والتطبيقات والأنظمة والمنتجات والخدمات الجديدة والحالية.
- مراجعة ضوابط الخصوصية المنفذة من قبل فرق الأعمال والتقنية والتوصية بالتحسينات عند الحاجة.
- تحديد مقاييس أداء الخصوصية ومؤشرات الأداء الرئيسية (KPIs/KRIs) وتقديم تقارير منتظمة للإدارة العليا.
- مراقبة مخاطر الخصوصية الناشئة والتطورات التنظيمية والتوصية بالإجراءات التصحيحية المناسبة.
- إجراء العناية الواجبة للخصوصية وتقييمات البائعين والموردين ومقدمي الخدمات من الأطراف الثالثة.
- التعاون مع فرق المشتريات والقانونية وأمن المعلومات والأعمال لتقييم مخاطر خصوصية الطرف الثالث.
- مراجعة وتقديم المشورة بشأن متطلبات الخصوصية في عقود البائعين والاتفاقيات وبيانات العمل.
- دعم التفاوض على اتفاقيات معالجة البيانات (DPAs) وبنود الخصوصية واتفاقيات مشاركة البيانات والأحكام التعاقدية الأخرى ذات الصلة.
- مراقبة امتثال الطرف الثالث لالتزامات الخصوصية المطبقة طوال دورة حياة البائع.
- إنشاء وصيانة عمليات وسياسات وإجراءات لإدارة حقوق أصحاب البيانات (DSRs).
- إدارة والاستجابة لطلبات أصحاب البيانات وفقاً لمتطلبات PDPL المطبقة والإجراءات التنظيمية.
- التنسيق مع فرق الأعمال والقانونية والتقنية وخدمة العملاء المعنية لضمان حل DSRs في الوقت المناسب.
- تطوير وصيانة إشعارات خصوصية واضحة وشفافة ومتوافقة عبر قنوات العملاء والموظفين والرقمية وغيرها من القنوات ذات الصلة.
- تقديم الاستشارات والإرشادات المتعلقة بالخصوصية أثناء خروقات البيانات الشخصية وحوادث الأمن السيبراني والحوادث المتعلقة بالخصوصية.
- دعم التحقيق في الحوادث وتقييمها وتصعيدها وتوثيقها والإبلاغ التنظيمي عند الاقتضاء.
- تقديم المشورة للإدارة العليا وأصحاب المصلحة المعنيين بشأن آثار الخصوصية وإجراءات التصحيح المطلوبة.
- ضمان وضع الإجراءات المناسبة لإدارة والاستجابة لخروقات البيانات الشخصية.
- تقديم المشورة لأصحاب المصلحة بشأن نقل البيانات الشخصية عبر الحدود والمتطلبات التنظيمية المطبقة.
- إنشاء وصيانة عمليات لتقييم والموافقة وتوثيق ومراقبة عمليات نقل البيانات عبر الحدود.
- مراجعة ودعم تنفيذ اتفاقيات مشاركة البيانات مع الأطراف الخارجية.
- ضمان امتثال ترتيبات مشاركة البيانات ونقلها لمتطلبات الخصوصية والتنظيم السعودية المطبقة.
- العمل كنقطة اتصال رئيسية للمسائل المتعلقة بالخصوصية التي تشمل العملاء والموظفين وأصحاب المصلحة التجاريين والموردين والجهات التنظيمية.
- التعاون مع SAMA وSDAIA وNDMO والجهات الأخرى ذات الصلة بشأن حماية البيانات ومسائل الخصوصية.
- دعم عمليات التفتيش التنظيمي والتقييمات والاستفسارات والتحقيقات وطلبات المعلومات.
- العمل بشكل وثيق مع الفريق القانوني بشأن المتطلبات القانونية المتعلقة بالخصوصية والاستفسارات التنظيمية والتحقيقات والمسائل التعاقدية.
- العمل كحلقة وصل بين فرق الأعمال والبيانات والقانونية وأمن المعلومات وتقنية المعلومات والتقنية لضمان فهم وتنفيذ متطلبات حماية البيانات الشخصية والحساسة بشكل واضح.
الشروط والمتطلبات
- درجة البكالوريوس في تقنية المعلومات أو الأمن السيبراني أو علوم الحاسب أو الهندسة أو إدارة البيانات أو القانون أو مجال ذي صلة.
- من 5 إلى 10 سنوات من الخبرة المهنية ذات الصلة، منها 5 سنوات على الأقل في دور مخصص لخصوصية البيانات أو حماية البيانات أو حوكمة الخصوصية أو الامتثال للبيانات.
- خبرة عملية قوية في نظام حماية البيانات الشخصية السعودي (PDPL) ولائحته التنفيذية.
- فهم قوي لمتطلبات NDMO ومتطلبات حوكمة البيانات والخصوصية السعودية.
- خبرة في العمل مع أنظمة/أطر مؤسسة النقد العربي السعودي (SAMA)، ويفضل أن يكون ذلك في قطاع البنوك أو الخدمات المالية.
- خبرة في أطر الخصوصية والأمن السيبراني المطبقة على القطاع المالي السعودي، بما في ذلك SAMA Cyber.
عرض النص الأصلي للإعلان
Data Privacy Expert
Location
Saudi Arabia
Experience
5-10 Years
Notice Period
Immediate to 30 Days Maximum
Employment Type
Full-Time
Job Summary
We are looking for an experienced Data Privacy Expert to lead and support the organization's data privacy and protection program in compliance with the Saudi Personal Data Protection Law (PDPL), its Implementing Regulations, NDMO requirements, SAMA regulations, and other applicable Saudi data protection and cybersecurity frameworks.
The successful candidate will be responsible for developing and operationalizing privacy policies, conducting PIAs/DPIAs, maintaining the Record of Processing Activities (RoPA), managing data privacy risks, overseeing third-party privacy compliance, supporting data subject rights, managing cross-border data transfers, and advising business and technology stakeholders on privacy requirements.
The role requires strong knowledge of the Saudi regulatory environment, particularly within the banking/financial services sector, along with the ability to engage effectively with senior management, regulators, legal teams, technology teams, vendors, and business stakeholders.
Key Responsibilities
Data Privacy Governance & Compliance
- Develop, implement, and continuously improve Data Privacy Policies, Processes, Procedures, Standards, Principles, Guidelines, and Templates in accordance with KSA PDPL, Implementing Regulations, NDMO requirements, and applicable regulatory requirements.
- Advise the organization and employees on personal data processing, collection, use, storage, sharing, retention, and disposal requirements.
- Ensure business processes, records, applications, systems, and technologies containing personal data comply with applicable privacy requirements.
- Establish and maintain a comprehensive Data Privacy Compliance Framework.
- Define privacy standards and requirements to be followed by Information Security, IT, Data Management, and business teams.
- Regularly review and enhance privacy practices to address regulatory, business, and technology changes.
PIA, DPIA & RoPA
- Lead Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) activities across the organization.
- Conduct and maintain the Record of Processing Activities (RoPA) repository for all relevant personal data processing activities.
- Identify processing activities requiring DPIAs based on PIA results and applicable regulatory requirements.
- Conduct DPIAs and recommend appropriate technical and organizational controls to mitigate identified privacy risks.
- Conduct data flow mapping to document the lifecycle of personal data from collection through processing, storage, sharing, archival, and destruction.
- Support the business in identifying and prioritizing critical and high-risk personal data processing activities.
Privacy Risk Management
- Develop and maintain a comprehensive Data Privacy Risk Register covering identified risks, risk owners, treatment plans, target closure dates, and remediation status.
- Assess privacy risks associated with new and existing business processes, applications, systems, products, and services.
- Review privacy controls implemented by business and technology teams and recommend improvements where required.
- Define privacy performance metrics and KPIs/KRIs and provide regular reporting to senior management.
- Monitor emerging privacy risks and regulatory developments and recommend appropriate corrective actions.
Third-Party & Vendor Privacy Management
- Conduct privacy due diligence and assessments of third-party vendors, suppliers, and service providers.
- Collaborate with Procurement, Legal, Information Security, and Business teams to assess third-party privacy risks.
- Review and advise on privacy requirements in vendor contracts, agreements, and statements of work.
- Support negotiation of Data Processing Agreements (DPAs), privacy clauses, data sharing agreements, and other relevant contractual provisions.
- Monitor third-party compliance with applicable privacy obligations throughout the vendor lifecycle.
Data Subject Rights & Privacy Notices
- Establish and maintain processes, policies, and procedures for managing Data Subject Rights (DSRs).
- Manage and respond to data subject requests in accordance with applicable PDPL requirements and organizational procedures.
- Coordinate with relevant business, legal, technology, and customer service teams to ensure timely resolution of DSRs.
- Develop and maintain clear, transparent, and compliant Privacy Notices across customer, employee, digital, and other relevant channels.
Data Breach & Incident Management
- Provide privacy consultation and guidance during personal data breaches, cybersecurity incidents, and privacy-related incidents.
- Support incident investigation, assessment, escalation, documentation, and regulatory reporting where applicable.
- Advise senior management and relevant stakeholders on privacy implications and required remediation actions.
- Ensure appropriate procedures are established for managing and responding to Personal Data Breaches.
Cross-Border Data Transfers & Data Sharing
- Advise stakeholders on cross-border personal data transfers and applicable regulatory requirements.
- Establish and maintain processes for assessing, approving, documenting, and monitoring cross-border data transfers.
- Review and support the implementation of Data Sharing Agreements with external parties.
- Ensure data sharing and transfer arrangements comply with applicable Saudi privacy and regulatory requirements.
Regulatory & Stakeholder Engagement
- Act as a key point of contact for privacy-related matters involving customers, employees, business stakeholders, vendors, and regulatory authorities.
- Collaborate with SAMA, SDAIA, NDMO, and other relevant authorities on data protection and privacy matters.
- Support regulatory inspections, assessments, inquiries, investigations, and information requests.
- Work closely with Legal on privacy-related legal requirements, regulatory inquiries, investigations, and contractual matters.
- Serve as a liaison between Business, Data, Legal, Information Security, IT, and Technology teams to ensure personal and sensitive data protection requirements are clearly understood and implemented.
Reporting & Continuous Improvement
Qualifications & Experience
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Engineering, Data Management, Law, or a related field.
- 5-10 years of relevant professional experience, with at least 5 years in a dedicated Data Privacy, Data Protection, Privacy Governance, or Data Compliance role.
- Strong hands-on experience with Saudi Personal Data Protection Law (PDPL) and its Implementing Regulations.
- Strong understanding of NDMO requirements and Saudi data governance and privacy requirements.
- Experience working with SAMA regulations/frameworks, preferably within the banking or financial services sector.
- Experience with privacy and cybersecurity frameworks applicable to the Saudi financial sector, including SAMA Cyber Security Framework (CSF) and relevant IT governance requirements.
- Practical experience in RoPA, PIA, DPIA, data mapping, privacy risk assessments, DSRs, privacy notices, breach management, and data transfer assessments.
- Experience in data governance and data management is highly desirable.
- CDMP certification or relevant data management certification will be an advantage.
- Experience working in a large, complex organization, preferably within banking, financial services, fintech, telecommunications, or other highly regulated industries.
- Fluent in both Arabic and English, written and spoken.
Required Skills
- In-depth knowledge of KSA PDPL and applicable data protection regulations.
- Strong understanding of privacy principles including:
- Data minimization
- Purpose limitation
- Transparency
- Accountability
- Data accuracy
- Storage limitation
- Confidentiality and integrity
- Strong understanding of data privacy governance, risk, and compliance.
- Knowledge of data management, data governance, information security, and IT environments.
- Strong understanding of personal and sensitive data protection requirements.
- Ability to conduct and document PIAs, DPIAs, RoPA, data flow mapping, and privacy risk assessments.
- Strong third-party/vendor privacy assessment and contract review skills.
- Excellent analytical, problem-solving, and decision-making capabilities.
- Strong stakeholder management and influencing skills.
- Excellent written and verbal communication skills in Arabic and English.
- Strong attention to detail and ability to handle confidential and sensitive information with a high degree of integrity.
- Proficiency in Microsoft Office Suite, including Word, Excel, PowerPoint, and related reporting tools.
Preferred Certifications
Candidates with one or more of the following certifications will be preferred:
- CIPP/E, CIPP/MENA, CIPM, CIPT
- CDMP
- ISO/IEC 27701
- ISO/IEC 27001
- CISA / CISM / CISSP
- Other recognized Data Privacy, Data Protection, Data Governance, or Information Security certifications.
Key Candidate Criteria:
- Experience: 5-10 years
- Relevant Privacy Experience: Minimum 5 years
- Location: Saudi Arabia
- Language: Arabic & English - Fluent
- Industry: Banking / Financial Services preferred
- PDPL: Strong hands-on expertise required
- SAMA: Relevant experience required
- Notice Period: Immediate to 30 days maximum
- Data Privacy: Strong practical experience in RoPA, PIA, DPIA, DSR, data mapping, breach management, vendor privacy, and cross-border transfers
If interested pls reply with updated cv to balaguru@hastraa.com
WR
Balaguru
رقم الإعلان لدى المصدر: 4466187354