Role Overview
This position sits at the intersection of legal compliance, business enablement, and data governance. You will lead the organisation's global privacy programme, ensuring that every processing activity across multiple operating licences and legal jurisdictions adheres to data protection law while still supporting commercial objectives. A core part of your daily work involves building practical frameworks that permit data to move lawfully between business units and regions, allowing a single, consistent view of each customer without eroding privacy standards or exposing the company to regulatory action.
You will act as the senior adviser to leadership and operational teams on all matters of data protection, translating complex legislative requirements into policies, controls, and training that people actually use. You will also oversee the organisation's response to data breaches, regulatory inquiries, and privacy risks, ensuring that privacy is not a bottleneck but a strategic enabler of growth and customer trust.
Key Responsibilities
- Design and maintain a comprehensive global privacy governance framework, including policies, standards, and procedures that align with applicable laws in every territory where the organisation operates.
- Lead the strategy for lawful cross-border and cross-entity data sharing, developing mechanisms that support the "One Customer View" model while satisfying data minimisation, purpose limitation, and consent requirements.
- Conduct data protection impact assessments (DPIAs) for new products, systems, and partnerships, and advise on mitigating technical and organisational risks before launch.
- Own the privacy compliance monitoring programme, including periodic audits, control testing, and reporting on key risk indicators to senior management and boards where required.
- Direct the response to personal data incidents, from initial triage and containment through to regulatory notification, customer communication, and post-incident remediation.
- Deliver role-based privacy training and awareness campaigns across the organisation, tailoring content for executives, engineers, customer-facing staff, and third-party processors.
- Act as the primary point of contact for data protection authorities and lead the preparation of responses to regulatory enquiries, complaints, and investigations.
- Enhance operational processes such as data subject rights handling, records of processing, and vendor due diligence to ensure they remain effective as the regulatory landscape changes.
Requirements & Qualifications
- Bachelor's degree in law, information technology, information management, or a related discipline; a Master's degree or legal qualification is strongly preferred.
- Professional privacy certification is mandatory — CIPP/E, CIPP/A, CIPM, CIPT, or equivalent (FIP designation is an advantage).
- Minimum 8–10 years of progressive experience in data protection and privacy roles, ideally within a multi-jurisdictional financial services, payments, or technology company.
- Deep, practical knowledge of global privacy regulations, with particular expertise in the GDPR and African data protection laws (e.g., SA POPIA, Nigeria NDPR, Kenya DPA), and the ability to interpret how these laws interact in a cross-border context.
- Proven track record of building and implementing enterprise-wide privacy programmes, not just advising on them — including drafting policies, running risk assessments, and driving cultural change.
- Strong grasp of IT security concepts, including encryption, pseudonymisation, access controls, and privacy-enhancing technologies (PETs), and the ability to discuss technical controls credibly with engineers and security teams.
- Exceptional stakeholder communication skills, with experience presenting to executives, regulators, and legal counsel, and the ability to translate legal requirements into clear operational guidance.
225 open positions on Semasocial right now
· 8789 open positions in Nairobi County, Kenya
· 6 posted in the last 7 days
Contact Information