We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
This role is based in Cairo, regional scope is Arabian countries
PURPOSE AND OBJECTIVES
When processing personal data as part of its business operations, SAP must comply with the requirements of the EU's General Data Protection Regulation (GDPR), Egypt's Data Protection Law No. 151 of 2020, UAE's Federal Decree-Law No. 45 of 2021, Saudi Arabia's PDPL (Personal Data Protection Law), and other applicable data protection and privacy laws in the countries where SAP operates.
To support the local SAP entities in meeting their data protection and privacy compliance obligations, SAP has established a global network of Data Protection and Privacy professionals. This network consists of local Data Protection Officers (DPOs) and Data Protection and Privacy Coordinators (DPPCs) that report to the management of the SAP entities by which they are hired and to SAP's global Data Protection & Privacy team, reporting to SAP's Group Data Protection Officer.
We are looking for an experienced Lead Senior Legal Counsel to serve as the local Data Protection Officer (DPO) for Egypt and as Data Protection and Privacy Coordinator (DPPC) for Arabian countries including the UAE and Saudi Arabia, responsible for leading data protection compliance strategy across the assigned country responsibility.
EXPECTATIONS AND TASKS
The role is responsible for ensuring SAP's compliance with Egypt's data protection regulations, GDPR, and data protection laws across assigned Arabian countries. This role involves collaborating closely with the global data protection and privacy team, local business units, senior management, and external regulatory authorities to manage data protection risks and drive data protection and privacy awareness across the organization.
Under Law No. 151 of 2020, the local DPO is a legally recognized role that requires formal registration with the regulator. The candidate must meet the following statutory requirements:
Official Registration: The candidate must be registered (or eligible for immediate registration) in the official DPO Register held by the Egyptian Personal Data Protection Center (PDPC).
Legal Capability Demonstration (Mandatory Exam):
To finalize registration with the PDPC, the candidate must successfully demonstrate legal and technical capabilities in data privacy.
Requirement: The candidate must pass the official PDPC accreditation examination (or equivalent authorized evaluation) proving deep knowledge of Egyptian Law No. 151 of 2020, its executive regulations, and international data transfer frameworks.
Note: Continued employment in this role is contingent upon successfully passing this exam and securing/maintaining active registration with the PDPC .
Key Responsibilities:
Regulatory Compliance & Strategy:
Ensure compliance with Egypt's Personal Data Protection Law No. 151 of 2020, UAE Federal Decree-Law No. 45 of 2021, Saudi Arabia's Personal Data Protection Law (PDPL), GDPR, and other relevant regional regulations.
Act as the officially registered and certified Data Protection Officer (DPO) for SAP's legal entities in Egypt in front of the Egyptian Personal Data Protection Center (PDPC), ensuring all local registration and licensing requirements are met.
Develop and implement a comprehensive data protection compliance strategy for Egypt and assigned Arabian countries.
Monitor, interpret, and assess changes in data protection legislation, regulations, and industry standards across all assigned jurisdictions.
Provide timely updates, guidance, and legal opinions on regulatory developments and best practices.
Conduct and document the mandatory periodic evaluations, system inspections, and data protection audits as required by Article 9(1) of the Egyptian PDPL, and support the implementation of remediation measures.
Strategic Advice & Representation:
Provide legal and compliance advice on data protection issues and conduct Data Protection Impact Assessments (DPIAs) for new projects, initiatives, and emerging technologies, including AI/ML applications, ensuring alignment with the guidelines of the Egyptian PDPC and regional regulators.
Represent SAP's Group Data Protection Officer within the assigned region and serve as the direct, primary point of contact for the Egyptian PDPC and other regional supervisory authorities.
Drive the development, implementation, and maintenance of local data protection and privacy policies, standards, and procedures aligned with global requirements in accordance with SAP Global Data Protection and Privacy Strategy.
EDUCATION AND QUALIFICATIONS / SKILLS AND COMPETENCIES
Required skills
University degree in Law with specialization in data protection, privacy, or information technology law
Minimum 10 years of professional experience as a Data Protection Officer, Chief Privacy Officer, or in a senior legal/compliance role focused on data protection
Thorough knowledge and practical experience with GDPR and other global data protection regulations
Demonstrated expertise in Egypt's Data Protection Law No. 151 of 2020 and/or UAE/Saudi Arabian data protection frameworks
Professional experience in managing cross-jurisdictional compliance initiatives
Strong project management capabilities with ability to lead complex, multi-stakeholder initiatives
Exceptional written and oral presentation skills with ability to communicate complex legal and technical concepts to non-specialist audiences
Strong communication skills at all organizational levels, including C-suite executives
Ability to build and maintain relationships with internal and external stakeholders, including regulatory authorities
Desired Candidate Profile
- University degree in Law with specialization in data protection, privacy, or information technology law
- Minimum 10 years of professional experience as a Data Protection Officer, Chief Privacy Officer, or in a senior legal/compliance role focused on data protection
- Thorough knowledge and practical experience with GDPR and other global data protection regulations
- Demonstrated expertise in Egypt's Data Protection Law No. 151 of 2020 and/or UAE/Saudi Arabian data protection frameworks
- Professional experience in managing cross-jurisdictional compliance initiatives
- Strong project management capabilities with ability to lead complex, multi-stakeholder initiatives
- Exceptional written and oral presentation skills with ability to communicate complex legal and technical concepts to non-specialist audiences
- Strong communication skills at all organizational levels, including C-suite executives
- Ability to build and maintain relationships with internal and external stakeholders, including regulatory authorities
- Deep understanding of data protection principles, frameworks, and regulatory requirements across assigned jurisdictions
- Proficiency in conducting DPIAs and risk assessments
- Experience with data breach management and incident response protocols
- Strong analytical and problem-solving skills with strategic thinking capability
- Ability to work independently, manage multiple priorities, and lead cross-functional teams
- Strong interpersonal skills and ability to influence at senior levels
- Fluency in Modern Standard Arabic and Egyptian Arabic (written and spoken)
- Fluency in English (written and spoken)
- CIPP-E (Certified Information Privacy Professional - Europe) certification
- AIGP (AI Governance Professional) certification or equivalent
- CIPM (Certified Information Privacy Manager) certification
- Prior experience working with multinational organizations or in regulated industries
- Experience with AI/ML governance and privacy by design principles
نساعد العالم على العمل بشكل أفضل. في SAP، نجعله بسيطاً: أنت تقدم لنا أفضل ما لديك، وسنبرز الأفضل فيك. نحن بنّاؤون نغطي أكثر من 20 صناعة و80% من التجارة العالمية، ونحتاج مواهبك الفريدة للمساعدة في تشكيل ما هو قادم. العمل صعب ولكنه مهم. ستجد مكاناً يمكنك فيه أن تكون نفسك، وتولي رفاهيتك الأولوية، وتنتمي حقاً. ما الذي ستجنيه؟ تعلم مستمر، نمو في المهارات، مزايا رائعة، وفريق يريدك أن تنمو وتنجح.
هذا الدور مقره في القاهرة، النطاق الإقليمي هو الدول العربية
الغرض والأهداف
عند معالجة البيانات الشخصية كجزء من عمليات الأعمال الخاصة بالشركة، يجب على SAP الامتثال لمتطلبات اللائحة العامة لحماية البيانات (GDPR) التابعة للاتحاد الأوروبي، وقانون حماية البيانات المصري رقم 151 لسنة 2020، والمرسوم الاتحادي الإماراتي رقم 45 لسنة 2021، ونظام حماية البيانات الشخصية السعودي (PDPL)، وغيرها من القوانين المعنية بحماية البيانات والخصوصية في الدول التي تعمل بها SAP.
لدعم كيانات SAP المحلية في تلبية التزاماتها بالامتثال لحماية البيانات والخصوصية، أنشأت SAP شبكة عالمية من محترفي حماية الخصوصية والبيانات. تتكون هذه الشبكة من مسؤولي حماية البيانات (DPOs) المحليين ومنسقي حماية البيانات والخصوصية (DPPCs) الذين يبلغون إلى إدارة كيانات SAP التي يعملون لديها وإلى فريق حماية البيانات والخصوصية العالمي في SAP، والذي يقدم تقاريره إلى مسؤول حماية البيانات في المجموعة في SAP.
نبحث عن مستشار قانوني رفيع الخبرة لخدمة كمسؤول حماية البيانات المحلي (DPO) لمصر وكمنسق حماية البيانات والخصوصية (DPPC) للدول العربية بما فيها الإمارات العربية المتحدة والسعودية، حيث سيكون مسؤولاً عن قيادة استراتيجية امتثال حماية البيانات عبر الدولة المعنية.
التوقعات والمهام
الدور مسؤول عن ضمان امتثال SAP لمعايير حماية البيانات في مصر وقانون GDPR وحماية البيانات في الدول العربية المخصصة. ويتضمن هذا الدور التعاون عن كثب مع فريق حماية البيانات والخصوصية العالمي ووحدات الأعمال المحلية والإدارة العليا والجهات التنظيمية الخارجية لادارة مخاطر حماية البيانات وتعزيز الوعي بحماية البيانات والخصوصية عبر المؤسسة.
وفقاً للقانون رقم 151 لسنة 2020، يعتبر DPO المحلي دوراً ذو تسجيل رسمي يتطلب تسجيلاً رسمياً لدى الجهة التنظيمية. يجب أن يستوفي المرشح المتطلبات القانونية التالية:
التسجيل الرسمي: يجب تسجيل المرشح (أو أهلية التسجيل الفوري) في سجل DPO الرسمي الذي تحمله مركز حماية البيانات الشخصية المصري (PDPC).
إثبات القدرة القانونية (اختبار إلزامي):
لإكمال التسجيل مع PDPC، يجب أن يثبت المرشح كفاءة قانونية وتقنية في خصوصية البيانات بنجاح.
المتطلب: يجب أن يجتاز المرشح اختبار الاعتماد الرسمي PDPC (أو تقييم مخول مكافئ) يظهر معرفة عميقة بقانون مصر رقم 151 لسنة 2020، وأنظمته التنفيذية، وأطر نقل البيانات الدولية.
ملاحظة: استمرار التوظيف في هذا الدور مشروط باجتياز هذا الاختبار بنجاح وضمان/الحفاظ على التسجيل النشط لدى PDPC.
المسؤوليات الرئيسية:
الامتثال التنظيمي والاستراتيجية:
ضمان الامتثال لقانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020، والمرسوم الاتحادي الإماراتي رقم 45 لسنة 2021، وقانون حماية البيانات الشخصية السعودي (PDPL)، وGDPR، وغيرها من التنظيمات الإقليمية ذات الصلة.
العمل كسجل رسمي ومعتمد لمسؤول حماية البيانات (DPO) لكيانات SAP القانونية في مصر أمام مركز حماية البيانات الشخصية المصري (PDPC)، مع ضمان استيفاء جميع متطلبات التسجيل والترخيص المحلي.
تطوير وتنفيذ خطة امتثال حماية البيانات شاملة لمصر والدول العربية المعينة.
مراقبة وتفسير وتقييم التغيرات في تشريعات حماية البيانات واللوائح والمعايير الصناعية في جميع الاختصاصات المعينة.
تقديم تحديثات فورية وإرشادات وآراء قانونية حول التطورات التنظيمية وأفضل الممارسات.
إجراء وتوثيق التقييمات الدورية الإلزامية، فحوصات النظام، وعمليات تدقيق حماية البيانات كما يقتضيها المادة 9(1) من PDPL المصري، ودعم تنفيذ إجراءات الإصلاح.
النصح الاستراتيجي والتمثيل:
تقديم المشورة القانونية والالتزامية في قضايا حماية البيانات وإجراء تقييمات أثر حماية البيانات (DPIAs) للمشروعات والمبادرات والتقنيات الناشئة، بما في ذلك تطبيقات AI/ML، مع ضمان التوافق مع إرشادات PDPC المصري والجهات التنظيمية الإقليمية.
تمثيل مسؤول حماية البيانات للمجموعة SAP ضمن المنطقة المعتمدة والعمل كنقطة الاتصال المباشرة والأولية لـ PDPC المصري والجهات الرقابية الإقليمية الأخرى.
قيادة تطوير وتنفيذ وصيانة سياسات وخصوصية البيانات محلياً، والمعايير والإجراءات بما يتماشى مع المتطلبات العالمية وفق استراتيجية حماية البيانات والخصوصية العالمية لـ SAP.
التعليم والمؤهلات / المهارات والكفاءات
المهارات المطلوبة
درجة جامعية في القانون مع تخصص في حماية البيانات أو الخصوصية أو قانون تكنولوجيا المعلومات
حد أدنى 10 سنوات خبرة مهنية كمسؤول حماية بيانات، رئيس خصوصية، أو في دور قانوني/التزامي رفيع يركز على حماية البيانات
معرفة عميقة وخبرة عملية مع GDPR وغيرها من لوائح حماية البيانات العالمية
خبرة محترفة في إدارة مبادرات امتثال عبر ولايات قضائية مختلفة
قدرات قوية في إدارة المشاريع مع القدرة على قيادة مبادرات معقدة ومتعددة الأطراف
مهارات عرض مكتوبة وشفوية استثنائية لشرح مفاهيم قانونية وتقنية معقدة لجمهور غير متخصص
مهارات اتصال قوية على جميع المستويات التنظيمية، بما في ذلك التنفيذيين من مستوى C-suite
القدرة على بناء والحفاظ على علاقات مع أصحاب المصلحة الداخليين والخارجيين، بما في ذلك السلطات التنظيمية
الملف المرغوب للمرشح
- درجة جامعية في القانون مع تخصص في حماية البيانات أو الخصوصية أو قانون تكنولوجيا المعلومات
- حد أدنى 10 سنوات من الخبرة المهنية كمسؤول حماية بيانات، رئيس خصوصية، أو في دور قانوني/التزامي رفيع يركز على حماية البيانات
- معرفة وخبرة عملية واسعة بـ GDPR وغيرها من لوائح حماية البيانات العالمية
- خبرة مثبتة في قانون حماية البيانات المصري رقم 151 لسنة 2020 أو أطر حماية البيانات الإماراتية/السعودية
- خبرة مهنية في إدارة مبادرات امتثال عبر ولايات قضائية متعددة
- قدرات قوية في إدارة المشروعات مع القدرة على قيادة مبادرات معقدة متعددة الجهات
- مهارات مكتوبة وشفوية استثنائية في توصيل مفاهيم قانونية وتقنية معقدة لجمهور غير متخصص
- مهارات تواصل قوية على جميع المستويات التنظيمية، بما في ذلك التنفيذيين من مستوى C-suite
- القدرة على بناء والحفاظ على العلاقات مع أصحاب المصلحة الداخليين والخارجيين، بما في ذلك السلطات التنظيمية
- فهم عميق لمبادئ حماية البيانات والأطر والمتطلبات التنظيمية في الاختصاصات الموكلة
- الكفاءة في إجراء DPIAs وتقييمات المخاطر
- خبرة في إدارة خروقات البيانات وبروتوكولات الاستجابة للحوادث
- مهارات تحليلية وحل مشاكل قوية مع قدرة تفكير استراتيجي
- القدرة على العمل بشكل مستقل، إدارة أولويات متعددة، وقيادة فرق عبر وظائف
- مهارات شخصية قوية والقدرة على التأثير على المستويات العليا
- الطلاقة في العربية الفصحى والعربية المصرية كتابة وتحدثاً
- الطلاقة في الإنجليزية كتابة وتحدثاً
- شهادة CIPP-E (مختص حماية الخصوصية - أوروبا)
- شهادة AIGP (أخصائي حوكمة الذكاء الاصطناعي) أو ما يعادلها
- شهادة CIPM (مدير حماية الخصوصية المعتمد)
- خبرة سابقة في العمل مع منظمات متعددة الجنسيات أو في صناعات خاضعة للرقابة
- خبرة في حوكمة AI/ML ومبادئ الخصوصية بالتصميم