بنك الخليج الدولي يعلن عن وظيفة مسؤول حماية البيانات الشخصية في الخبر
تفاصيل الوظيفة
بنك الخليج الدولي يعلن عن وظيفة مسؤول حماية البيانات الشخصية (Personal Data Protection Officer) في الخبر، السعودية.
نبذة عن الوظيفة
يتولى مسؤول حماية البيانات الشخصية الإشراف على أجندة حماية البيانات الشخصية داخل الكيان ومراقبة الامتثال لقانون حماية البيانات الشخصية واللوائح ذات الصلة. يضمن المسؤول معالجة البيانات الشخصية وفقاً للمتطلبات القانونية والتنظيمية، والسياسات التنظيمية، وأفضل الممارسات المعترف بها. ويعمل كنقطة اتصال رئيسية مع الجهات التنظيمية والأفراد وأصحاب المصلحة الداخليين بشأن الأمور المتعلقة بحماية البيانات الشخصية.
المهام والمسؤوليات
- إعلام وتوجيه البنك (بصفته المتحكم في البيانات أو معالجها) وموظفيه بالتزاماتهم بالامتثال لقانون حماية البيانات الشخصية السعودي وقوانين حماية البيانات الأخرى السارية داخل المنظمة.
- يكون نقطة الاتصال الأولى للسلطات وللأفراد الذين تتم معالجة بياناتهم الشخصية (الموظفون، المستخدمون، إلخ). كما يتولى مسؤولية تنفيذ أحكام قانون حماية البيانات الشخصية السعودي، واللوائح التنفيذية، ولائحة نقل البيانات الشخصية خارج المملكة، وتنفيذ القرارات والتعليمات الصادرة عن الجهة المختصة.
- الحفاظ على سجل أنشطة المعالجة (RoPA) وتحديثه بانتظام وفقاً للمتطلبات التنظيمية، من خلال تحديد وتقييم ومراقبة المخاطر المرتبطة بمعالجة البيانات الشخصية.
- قيادة والإشراف على إكمال تقييمات تأثير حماية البيانات، والتوصية بالإجراءات التصحيحية، وضمان تنفيذ تدابير تخفيف المخاطر عبر منظومة الخصوصية في البنك.
- دعم والتنسيق مع أصحاب المصلحة المعنيين (بما فيهم وحدة الامتثال) لتحديد حوادث أو انتهاكات البيانات الشخصية والإبلاغ عنها وإدارتها، وضمان الامتثال للمتطلبات التنظيمية.
- مراقبة الإدارة العليا والإبلاغ دورياً عن امتثال المنظمة للخصوصية والوضع الحالي.
- الإشراف على معالجة الانتهاكات وعدم الامتثال عبر أنشطة خصوصية البيانات، وضمان تنفيذ التدابير التصحيحية.
- إدارة والرد على حقوق أصحاب البيانات وفقاً للوائح الخصوصية، بالتعاون مع الوحدات التجارية لمعالجة الطلبات ضمن الأطر الزمنية التنظيمية، والاحتفاظ بسجلات جميع الطلبات.
- العمل مع فرق القانون والموارد البشرية لتطوير عقوبات مناسبة لعدم الامتثال لسياسات وإجراءات الخصوصية.
- التنسيق مع الوحدات التجارية (بما فيها المشتريات) لمراجعة وتقديم المشورة بشأن اتفاقيات معالجة البيانات مع الأطراف الثالثة للنقل المحلي/الدولي، وتقديم المشورة للوحدات التجارية لضمان الامتثال المستمر لهذه الاتفاقيات.
- تقييم طلبات نقل البيانات الشخصية عبر الحدود وضمان الامتثال للمتطلبات التنظيمية والضمانات.
- الإشراف على تصميم وتنفيذ وصيانة والامتثال المستمر لسياسات وإجراءات الخصوصية في البنك.
- مراجعة وتحديث الإجراءات المنصوص عليها في سياسة الخصوصية بشكل دوري عند الحاجة.
- تحديد المسؤوليات وتثقيف الموظفين حول متطلبات الامتثال الهامة، وتدريب العاملين على معالجة البيانات الشخصية، وتطوير خطة تخفيف مخاطر الخصوصية، وإنشاء برنامج تدقيق خصوصية داخلي بالتنسيق مع وظيفة التدقيق الداخلي لتقييم الامتثال لأنشطة خصوصية البيانات في البنك.
- دعم وتقديم المشورة للوحدات التجارية المسؤولة عن تطوير وتشغيل الأنظمة التكنولوجية الحديثة لضمان الامتثال للوائح السارية.
الشروط والمتطلبات
- بكالوريوس في القانون (LLB)
- شهادة مهنية: مسؤول حماية بيانات معتمد (CDPO)
- خبرة لا تقل عن 4 سنوات في المجال القانوني
المهارات المطلوبة
- البحث القانوني
- حوكمة المخاطر والرقابة
عرض النص الأصلي للإعلان
|
Job Purpose |
|
Personal Data Protection Officer responsible for overseeing the Personal Data Protection agenda within the entity and monitors compliance with Personal Data Protection Law and applicable regulations. Personal Data Protection officer ensures that personal data is processed in accordance with legal and regulatory requirements, organizational policies and recognized best practices. The PDPO acts as the main point of contact with regulators, individuals, and internal stakeholders on matters relating to personal data protection. |
|
Key Accountabilities |
|
|
1 |
Inform and advise GIB, which acts as Data Controller or Data Processor, and its employees about their obligations to comply with the KSA PDPL and other applicable data protection laws within the organization. |
|
2 |
Be the first point of contact for the authorities and for individuals whose personal data is processed (employees, users, etc.). Furthermore, responsible for implementing the provisions of the Saudi Arabia Personal Data Protection Law, the Implementation regulations, and the Regulation of Personal Data - Transfer Outside the Kingdom. As well as, executing the decisions and instructions issued by the Competent Authority. |
|
3 |
Maintain and regularly update the Record of Processing Activities (RoPA), as per regulatory requirements. Through identifying, assessing and monitoring risks associated with personal data processing. |
|
4 |
Lead and supervise the completion of data protection impact assessments and recommend corrective actions and ensure risk mitigation measures are implemented across GIB's privacy ecosystem. |
|
5 |
Support and coordinate with Relevant Stakeholders (including Compliance Unit) to identify, reporting and manage personal data incidents or breaches, as well as ensure compliance with regulatory requirements. |
|
6 |
Monitor and report to top management on the organization's privacy compliance and current status periodically.. |
|
7 |
Oversee the resolution of violations and non-compliance across data privacy activities and ensure corrective measures are implemented. |
|
8 |
Manage and respond to data subject rights in line with the privacy regulations, whilst collaborating with Business Units to process requests within the regulatory timelines, and maintaining records of all requests. |
|
9 |
Work with legal and HR teams to develop appropriate sanctions for failure to comply with the privacy policies and procedures. |
|
10 |
Coordinate with Business Units, including procurement, to review and advise on third party data processing agreements for local/ international transfers, and advise Business Units on ensuring on-going compliance with such agreements. |
|
11 |
Evaluate personal data cross-border transfer requests and ensure compliance with regulatory requirements and safeguards. |
|
12 |
Oversee the design, implementation, maintenance and ongoing compliance of GIB's privacy policies and procedures. |
|
13 |
Periodically reviewing and, where necessary, updating the procedures set forth in GIB's Privacy Policy. |
|
14 |
Assign responsibilities and educate the employees on important compliance requirements and training staff involved in personal data processing and Develop Data privacy mitigation plan to mitigate identified privacy risks. Establish and maintain an internal privacy audit program in coordination with the internal audit function to assess the compliance of GIB’s data privacy activities. |
|
15 |
Supporting and advising Business Units responsible for developing and operating modern technological systems to ensure compliance with the applicable regulations. |
|
Qualifications, Experience & Skills required |
|
|
Qualifications |
Bachelors in Law (LLB) |
|
Professional Certifications |
Certified Data Protection Officer (CDPO) |
|
Experience |
4 years of legal background |
|
Skills |
|
|
Competencies |
Please refer to “Appendix I - Competencies” below |
رقم الإعلان لدى المصدر: 1100088318