Position: Mid-Senior level

Job type: Full-time

Loading ...

Job content

Job Description

Key Responsibilities:
  • Assess and manage the impact of data protection risk, within the current business as usual process (BAU), to ensure it is within risk appetite.
  • Provide assessment and recommendations to improve controls within the BAU process across the three lines of defence.
  • Monitor and review all aspects of data protection obligations to ensure control, governance and assurance frameworks are compliant with regulatory expectations.
  • Engage the Group on their Risk and Control Self-Assessment (RCSA) activity to make sure data protection risks are appropriately identified, assessed, control tested and reported.
  • Provide ongoing monitoring and guidance against the maturity of the control framework
  • Promote and facilitate data protection risk awareness and understanding across the Group through generic and specifically targeted training and communication.
  • Remain aware of leading practices on managing data protection risk and include these within the Data Protection Office BAU Operating Model.
  • Develop and maintain key stakeholder relationships across the Group.
  • Develop and maintain appropriate MI to demonstrate adequacy of control effectiveness and escalation in all activities, in alignment with the Enterprise Risk Management Framework.
  • Provide SME oversight, advice and guidance to help colleagues and suppliers achieve desired data protection controls through their BAU activities.
  • Provide support, guidance, advice and review of the Data Protection Impact Assessment (DPIA) process – including Legitimate Interest Assessment’s (LIA) and Transfer Impact Assessments (TIA).
  • Oversee the Data Protection Third Party Management Process including, for example, review of contracts, assessment of due diligence responses, risk scoring et al.
  • Focused and clear articulation and consideration of threats and impacts in making data related risk decisions within the Group.
  • Maintain the library of policy and guidance documents to support the Group.
  • Provide support and advice to the business in the identification, management and resolution of data related incidents.
  • Manage correspondence with the Information Commissioner’s Office (ICO), where required.
  • Deputise for the DPO where required.
  • Provide matrix management to a team of Data Protection Champions across multiple Group functions.
Loading ...
Loading ...

Deadline: 16-07-2024

Click to apply for free candidate

Apply

Loading ...
Loading ...

SIMILAR JOBS

Loading ...
Loading ...