Reporting to the Head of Risk & Compliance, the successful candidate will be responsible for implementing and enforcing Hospital wide data protection compliance framework and systems to ensure the Hospital is compliant with the Data protection laws and regulations.
ROLES AND RESPONSIBILITIES
- Act as the primary point of contact within the Hospital for members of staff, regulators, and any relevant public bodies on issues related to data protection.
- Advise the Hospital and employees on data processing requirements provided under this Act or any other written laws.
- Establishing a Data Protection framework and implementation plan, amend existing internal data protection policies, guidelines, and procedures, in consultation with key stakeholders including developing templates for data collection and assisting with data mapping.
- Support the Hospital in preparation of privacy statements for each processing operation, and ensuring processes are put in place to ensure that the privacy statement is provided to data subjects on all Hospital forms and/or literature, websites and other communication or data collection mediums.
EDUCATION AND EXPERIENCE
- Law degree from an accredited law school or Bachelor of Science in Computer Science or an equivalent of the two.
- Certified Information Systems Auditor (CISA) certification/ Certified Information Systems Security Professional (CISSP)/ Certified Information Security Manager (CISM) certification
- Have carried out at least one Data Protection Impact Assessment exercise
- Minimum of three years’ experience working in a data protection compliance or a related field
- Strong project management skills
Comment