الغرض الوظيفي
قيادة والإشراف وضمان الامتثال التنظيمي لقانون حماية البيانات الشخصية المصري (PDPL - القانون رقم 151 لسنة 2020)، والعمل كحلقة وصل رسمية ومعترف بها قانونياً بين الشركة، ومركز حماية البيانات الشخصية المصري (PDPC)، والجهات المعنية بالبيانات (مع التركيز بشكل أساسي على سجلات الموظفين والعائلات).
المسؤوليات الرئيسية
1. الامتثال والإشراف الفني
إدارة ROPA: وضع وصيانة سجل أنشطة المعالجة (ROPA) للسجلات الرقمية والمادية للموظفين.
تقييم المخاطر: مراجعة وتقديم المشورة بشأن تقييمات أثر حماية البيانات (DPIAs) وتقييمات المصلحة المشروعة (LIAs).
الضمانات والتدريب: تقديم المشورة للفرق التقنية حول ضوابط الوصول، ومسارات التدقيق، والضمانات الوقائية من خروقات البيانات، مع قيادة تدريب خصوصية الموظفين.
2. التنظيم وعلاقات أصحاب البيانات
التواصل مع PDPC: العمل كنقطة اتصال مسجلة وحيدة للمركز خلال عمليات التدقيق والاستفسارات.
الخروق والتبليغ: إدارة والإبلاغ عن خروقات البيانات إلى PDPC ضمن الإطارات الزمنية المنصوص عليها، وتقديم تقارير الامتثال السنوية الإلزامية.
حل حقوق البيانات: الحفاظ على قنوات آمنة لتلقي وحل طلبات واحتجاجات أصحاب البيانات من الموظفين ضمن الأطر القانونية الزمنية.
المتطلبات
• الاعتماد: يجب اجتياز امتحان DPO Lead لدى PDPC بدرجة أعلى من 80%.
• السجل الرسمي: تسجيل نشط في سجل DPO لدى PDPC برمز DPO صالح.
• التعليم: شهادة جامعية (يفضل في القانون، علوم الحاسوب، الأمن السيبراني، أو الأعمال).
• الخبرة: من 3 إلى 5 سنوات من الخبرة المثبتة في خصوصية البيانات، الأمن السيبراني، الامتثال، أو الحوكمة المؤسسية (يفضّل الخلفية التنفيذية العليا أو الاستشارية).
• الشهادات (مفضل): شهادات معترف بها (مثل IAPP، ISC2، PECB، أو شهادات ISO مكافئة).
Job Purpose
To lead, oversee, and guarantee organizational compliance with the Egyptian Personal Data Protection Law (PDPL - Law No. 151 of 2020), serving as the official, legally recognized liaison between the company, the Egyptian Personal Data Protection Center (PDPC), and data subjects (primarily focusing on employee and family records).
Key Responsibilities
1. Compliance & Technical Oversight
ROPA Management: Develop and maintain the Record of Processing Activities (ROPA) for digital and physical employee records.
Risk Assessment: Review and advise on Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs).
Safeguards & Training: Advise technical teams on access controls, audit trails, and data breach prevention safeguards, while driving staff privacy training.
2. Regulatory & Data Subject Relations
PDPC Liaison: Act as the registered, sole point of contact for the PDPC during audits and inquiries.
Breach & Reporting: Manage and report data breaches to the PDPC within statutory deadlines, and submit mandated annual compliance reports.
Rights Resolution: Maintain secure channels to receive and resolve employee data subject requests and complaints within legal timeframes.
Requirements
• Accreditation: Must pass the PDPC Lead DPO Exam with a score above 80%.
• Official Registry: Active registration in the PDPC DPO Registry with a valid "DPO Code".
• Education: University degree (preferably in Law, Computer Science, Cybersecurity, or Business).
• Experience: 3 to 5 years of proven experience in data privacy, cybersecurity, compliance, or corporate governance (senior executive or consultant background preferred).
• Certifications (Preferred): Recognized credentials (e.g., IAPP, ISC2, PECB, or equivalent ISO certifications).