# Data Protection Officer

**Company:** [CARMA](http://jobs.workable.com/companies/6FMrbipXcabxwHYxuEg1RB.md)
**Location:** Cairo, Egypt
**Workplace:** on site
**Employment type:** Full-time
**Department:** Finance

[Apply for this job](http://jobs.workable.com/view/c3c28732-f796-4c17-a2a0-148ab6414979)

## Description

**CARMA** is a globally trusted media intelligence leader with decades of experience helping PR and communications professionals monitor what matters, measure what’s meaningful, and demonstrate the value of their work. We combine cutting-edge technology, including AI-enabled media monitoring across print, online, broadcast, and social channels in 100+ languages, with deep human expertise to deliver actionable insights that inform strategy and drive business-critical decisions. With a diverse global team supporting thousands of organisations worldwide, **CARMA** empowers partners to turn complex media data into clarity and context, elevate the impact of earned media, and deepen understanding of stakeholder influence across markets.

**Role overview**

**CARMA** is seeking an experienced **Data Protection Officer** to lead its global privacy programme across MENA, Europe and Asia. The role will ensure compliance with applicable data protection laws, oversee privacy governance, DPIAs, data subject requests, breach response, third-party compliance and privacy training, and act as the main point of contact for regulators and supervisory authorities. The ideal candidate will have five to seven years of relevant experience, including at least three years in privacy, with strong knowledge of GDPR and international data protection regulations.

**Role & Responsibilities**

**Data Protection Governance**

**•** Develop, implement and continuously improve the company's global privacy programme.

• Maintain privacy governance policies, standards and procedures.

• Ensure privacy controls are embedded across all business functions.

• Develop regional privacy compliance frameworks appropriate for MENA, EU and Asia.

• Establish privacy governance committees and reporting mechanisms.

**Regulatory Compliance**

Maintain and evidence compliance with the data protection regimes applicable across the company's markets:

• **European Union and United Kingdom:** EU General Data Protection Regulation (GDPR), UK GDPR, ePrivacy requirements and national implementing legislation.

• **MENA:** UAE PDPL, Saudi Personal Data Protection Law (PDPL), Oman Personal Data Protection Law and other applicable regional legislation.

• **Asia:** Singapore PDPA, Hong Kong PDPO, Japan APPI and other applicable regional legislation.

**Data Protection Impact Assessments**

**•** Lead Data Protection Impact Assessments (DPIAs) and Privacy Impact Assessments.

• Identify and mitigate privacy risks.

• Advise the business on high-risk processing activities.

• Maintain DPIA registers.

• Review high-risk technologies.

**Data Subject Rights (Clients, Prospects and Internal)**

**Oversee the processes relating to:**

• Access requests

• Correction requests

• Erasure requests

• Portability requests

• Restriction requests

• Objection requests

• Automated decision-making requests

**Incident and Breach Management**

• Lead privacy incident response.

• Assess whether breaches are reportable.

• Coordinate investigations.

• Advise management on notification obligations.

• Liaise with regulators where required.

• Conduct post-incident reviews.

**Third Party Privacy Compliance**

• Review Data Processing Agreements (DPAs).

• Conduct vendor privacy assessments.

• Monitor third-party compliance.

• Review subprocessors.

**Training**

• Develop annual privacy training programmes.

• Conduct awareness campaigns.

**Audit**

**•** Conduct privacy compliance monitoring.

• Perform internal audits.

• Review regional compliance.

• Monitor remediation actions.

**Regulatory Engagement**

Serve as the primary point of contact for:

• Supervisory authorities

• Data protection regulators

• Government enquiries and licence requirements

• Regulatory inspections

• External auditors

**Policy Development**

Develop and maintain the following policies, and ensure they are business-centric and implemented in practice:

• Global Privacy Policy

• Employee Privacy Notice

• Customer Privacy Notice

• Cookie Policy

• Data Retention Policy

• Data Breach Procedure

• Data Subject Rights Procedure

• Vendor Privacy Standard

• AI and Data Governance Policies

## Requirements

### Technical Skills

### Privacy and Regulatory Knowledge

-   Strong knowledge of the GDPR and applicable privacy laws across CARMA’s operating markets, including the UAE PDPL and the Egyptian Personal Data Protection Law.
-   Knowledge of ePrivacy requirements and cookie regulations.
-   Understanding of cross-border data transfer mechanisms, including Standard Contractual Clauses, the UK International Data Transfer Agreement and adequacy decisions.
-   Strong understanding of lawful bases for processing, data subject rights and sensitive personal data.
-   Practical knowledge of privacy-by-design principles and regulatory compliance requirements.

### Information Security Literacy

The role does not require advanced IT expertise; however, the job holder should have a working understanding of:

-   Information security and privacy-by-design principles.
-   ISO/IEC 27001 and the NIST Cybersecurity Framework.
-   Access controls, identity management and cloud security fundamentals.
-   Data protection controls and data-loss prevention.
-   Data breach management and incident-response processes.

### Education

-   Bachelor’s degree in Law, Information Technology, Information Security, Business Administration or a related discipline.
-   A postgraduate qualification or specialised training in data protection, privacy law or information governance is an advantage.

### Experience

-   At least two years of experience in data protection, privacy, legal or compliance roles, including a minimum of three years dedicated to privacy.
-   Demonstrated experience managing a privacy programme across multiple jurisdictions.
-   Practical experience leading Data Protection Impact Assessments, data breach response and data subject rights processes.
-   Experience reviewing Data Processing Agreements and conducting vendor privacy assessments.
-   Experience engaging with supervisory authorities, regulators and external auditors.
-   Experience developing and delivering privacy training and awareness programmes.
-   Experience developing and implementing privacy policies, procedures and compliance controls.

### Preferred Certifications

The following certifications are advantageous but not required:

-   Certified Information Privacy Professional/Europe — CIPP/E.
-   Certified Information Privacy Manager — CIPM.
-   Certified Information Privacy Technologist — CIPT.
-   ISO/IEC 27701 Lead Implementer or Lead Auditor.
-   ISO/IEC 27001 Lead Auditor.
