Data Privacy Lead

Application deadline closed.

Job Description

As Safaricom Ethiopia, we are a purpose-led technology company dedicated to transforming lives through digital connectivity and inclusive financial services. In under four years, we have grown to serve over 10 million customers, with our network now reaching 55% of Ethiopia’s population – a testament to our bold vision and trusted partnerships.

Guided by core values such as customer obsession, innovation, integrity, and get it done together, we are building a workplace that is dynamic, inclusive, and empowering. We believe our greatest strength lies in our people. That’s why, for two consecutive years, we have proudly get earned the Top Employer Award – in recognition for our unwavering commitment to fostering a supportive, innovative, and inclusive environment to people.

Join Safaricom Ethiopia and be part of a team that is shaping the digital future of Ethiopia. Here, your work has meaning, your voice matters, and your growth is our priority. Together, we are transforming lives for a digital future

Job Description
The Data Privacy Lead will ensure compliance with data protection laws, lead regulator engagement, and foster a culture of data privacy across Safaricom Ethiopia

Role purpose:

Reporting to the EHOD – Compliance, the position holder will proactively engage regulators and other stakeholders to embed tailored, timely data privacy capabilities across Safaricom Ethiopia. Independently review and offer advice on data governance, processing activities and/or data breaches.

Monitor compliance with applicable national and international laws and regulations pertaining to data protection and privacy and work with teams to close gaps identified. Proactively support all efforts towards Regulator engagement, registration, breach notification and reporting. Provide appropriate policies and guidelines to establish and maintain data protection compliance. Contribute towards establishing a strong culture of data protection across stakeholders through appropriate training and awareness

Key Responsibilities

Enabling the company by creating tailored data privacy and protection training campaigns and awareness sessions,
Obtaining overall data/information process map/flow in products, assets, processes, services, and critical auxiliary systems,
Ensures the development and implementations of high-risk guiding frameworks i.e., Policy, Procedure and Processes to manage data subject information’s [Customer, Employee, Candidates, and Suppliers],
Execute customized implementation of Global Data Protection Regulation [GDPR] through Risk Control Matrix [RCM],
Enable the business to operate in a conducive environment by creating Compliance Risks Management Plan [CRMP] to capture regulatory requirements,
Consulting, assisting, and aligning with business unit needs and requirements regarding data processing activities when processing data subject information,
Applying a proactive mechanism to tackle high and medium privacy risks through effective Data Protection Impact Assessment (DPAI), Legitimate Impact Assessment (LIA), Human Impact Assessment (HIA) and Transfer Impact Assessment (TIA),
Enhance the first line business operation by developing and enforcing Data Subject Requests [DSRs],
Periodically reporting the overall program implementation to Executive Committee,
Create enabling environment to work closely with cybersecurity and technology standards i.e., ISO27001 Framework,
Embed data protection clauses in Master Procurement Agreements (MPA) with vendors to manage legal and regulatory risks,
Enforce Data Processing Agreements (DPAs) to control outsourcing risks when exporting data processing activities to third parties,
Conduct third-party risk assessment.

Number Of Vacancies
1