Job description
We help the world run better
At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed.
This role is based in Cairo, regional scope is Arabian countries
PURPOSE AND OBJECTIVES
When processing personal data as part of its business operations, SAP must comply with the requirements of the EU's General Data Protection Regulation (GDPR), Egypt's Data Protection Law No. 151 of 2020, UAE's Federal Decree-Law No. 45 of 2021, Saudi Arabia's PDPL (Personal Data Protection Law), and other applicable data protection and privacy laws in the countries where SAP operates.
To support the local SAP entities in meeting their data protection and privacy compliance obligations, SAP has established a global network of Data Protection and Privacy professionals. This network consists of local Data Protection Officers (DPOs) and Data Protection and Privacy Coordinators (DPPCs) that report to the management of the SAP entities by which they are hired and to SAP's global Data Protection & Privacy team, reporting to SAP's Group Data Protection Officer.
We are looking for an experienced Lead Senior Legal Counsel to serve as the local Data Protection Officer (DPO) for Egypt and as Data Protection and Privacy Coordinator (DPPC) for Arabian countries including the UAE and Saudi Arabia, responsible for leading data protection compliance strategy across the assigned country responsibility.
EXPECTATIONS AND TASKS
The role is responsible for ensuring SAP's compliance with Egypt's data protection regulations, GDPR, and data protection laws across assigned Arabian countries. This role involves collaborating closely with the global data protection and privacy team, local business units, senior management, and external regulatory authorities to manage data protection risks and drive data protection and privacy awareness across the organization.
Under Law No. 151 of 2020, the local DPO is a legally recognized role that requires formal registration with the regulator. The candidate must meet the following statutory requirements:
- Official Registration: The candidate must be registered (or eligible for immediate registration) in the official DPO Register held by the Egyptian Personal Data Protection Center (PDPC).
- Legal Capability Demonstration (Mandatory Exam):
- To finalize registration with the PDPC, the candidate must successfully demonstrate legal and technical capabilities in data privacy.
- Requirement: The candidate must pass the official PDPC accreditation examination (or equivalent authorized evaluation) proving deep knowledge of Egyptian Law No. 151 of 2020, its executive regulations, and international data transfer frameworks.
Note: Continued employment in this role is contingent upon successfully passing this exam and securing/maintaining active registration with the PDPC.
Key Responsibilities:
- Regulatory Compliance & Strategy:
- Ensure compliance with Egypt's Personal Data Protection Law No. 151 of 2020, UAE Federal Decree-Law No. 45 of 2021, Saudi Arabia's Personal Data Protection Law (PDPL), GDPR, and other relevant regional regulations.
- Act as the officially registered and certified Data Protection Officer (DPO) for SAP's legal entities in Egypt in front of the Egyptian Personal Data Protection Center (PDPC), ensuring all local registration and licensing requirements are met.
- Develop and implement a comprehensive data protection compliance strategy for Egypt and assigned Arabian countries.
- Monitor, interpret, and assess changes in data protection legislation, regulations, and industry standards across all assigned jurisdictions.
- Provide timely updates, guidance, and legal opinions on regulatory developments and best practices.
- Conduct and document the mandatory periodic evaluations, system inspections, and data protection audits as required by Article 9(1) of the Egyptian PDPL, and support the implementation of remediation measures.
- Strategic Advice & Representation:
- Provide legal and compliance advice on data protection issues and conduct Data Protection Impact Assessments (DPIAs) for new projects, initiatives, and emerging technologies, including AI/ML applications, ensuring alignment with the guidelines of the Egyptian PDPC and regional regulators.
- Represent SAP's Group Data Protection Officer within the assigned region and serve as the direct, primary point of contact for the Egyptian PDPC and other regional supervisory authorities.
- Drive the development, implementation, and maintenance of local data protection and privacy policies, standards, and procedures aligned with global requirements in accordance with SAP Global Data Protection and Privacy Strategy.
- Assist local Legal Representatives (who carry statutory and criminal liability under Egyptian law) and Chief Finance Officers in fulfilling their local data protection responsibilities and dedicated legal entity processes.
- Compliance Monitoring, Risk Management & Operations:
- Monitor and advise LoBs implementing local procedures (Records of Processing Activities - ROPA) of data processing operations for the Egyptian entity, ensuring it is available for inspection by the PDPC.
- Establish and monitor compliance with data protection policies, procedures, and regulatory requirements across all assigned entities.
- Manage data breach response protocols, according to SAP’s established processes, ensuring that any personal data breach affecting Egyptian data subjects is reported to the PDPC and affected individuals within the statutory 72-hour window, in compliance with Article 9(6) of the PDPL.
- Act as the dedicated point of contact for data subjects, establishing clear channels to receive, investigate, and resolve requests, complaints, and inquiries regarding their rights under Egyptian law and regional frameworks.
- Support the execution of cross-border data transfer impact assessments and obtain necessary data transfer licenses and permits from the PDPC as required by Egyptian law.
- Awareness, Training & Organizational Development:
- Conduct targeted data protection and privacy training programs for various organizational levels, tailored to the compliance requirements of Egypt, Saudi Arabia, and the UAE.
- Develop and maintain data protection awareness materials and communications.
- Strengthen and expand SAP's global data protection community within the assigned region.
- Regional Coordination & Harmonization:
- Harmonize data protection documentation, processes, and compliance approaches across Egypt and assigned Arabian countries in alignment with global DPP standards, while strictly respecting local localization and sovereign cloud requirements (e.g., KSA and Egypt cloud regulations).
- Coordinate data protection initiatives and ensure consistency in implementation across multiple jurisdictions.
- Build and maintain collaborative relationships with local and regional stakeholders, including government authorities (specifically the PDPC in Egypt, SDAIA in KSA, and the UAE Data Office), industry partners, and external legal counsel.
EDUCATION AND QUALIFICATIONS / SKILLS AND COMPETENCIES
Required skills
- University degree in Law with specialization in data protection, privacy, or information technology law
- Minimum 10 years of professional experience as a Data Protection Officer, Chief Privacy Officer, or in a senior legal/compliance role focused on data protection
- Thorough knowledge and practical experience with GDPR and other global data protection regulations
- Demonstrated expertise in Egypt's Data Protection Law No. 151 of 2020 and/or UAE/Saudi Arabian data protection frameworks
- Professional experience in managing cross-jurisdictional compliance initiatives
- Strong project management capabilities with ability to lead complex, multi-stakeholder initiatives
- Exceptional written and oral presentation skills with ability to communicate complex legal and technical concepts to non-specialist audiences
- Strong communication skills at all organizational levels, including C-suite executives
- Ability to build and maintain relationships with internal and external stakeholders, including regulatory authorities
Technical & Legal Expertise:
- Deep understanding of data protection principles, frameworks, and regulatory requirements across assigned jurisdictions
- Proficiency in conducting DPIAs and risk assessments
وصف الوظيفة
نساعد العالم على العمل بشكل أفضل
في SAP، نُبسط الأمور: ائتِلِمْنا أفضل ما لديك، وسنُبرز أفضل ما لديك. نحن بنّاءون نخدم أكثر من 20 صناعة و80% من التجارة العالمية، ونحتاج مواهبك الفريدة للمساعدة في تشكيل ما هو القادم. العمل يتسم بالتحدي – ولكنه ذو أهمية. ستجد مكاناً يمكنك فيه أن تكون نفسك، تولي رفاهيتك الأولوية، وتنتمي حقاً. ما الذي تحصل عليه؟ تعلم مستمر، نمو في المهارات، فوائد رائعة، وفريق يريدك أن تنمو وتنجح.
هذا الدور مقره في القاهرة، النطاق الإقليمي يشمل الدول العربية
الغرض والأهداف
عند معالجة البيانات الشخصية كجزء من عمليات الأعمال الخاصة بالشركة، يجب على SAP الامتثال لمتطلبات النظام العام لحماية البيانات (GDPR) في الاتحاد الأوروبي، وقانون حماية البيانات المصري رقم 151 لسنة 2020، والم decree-law الإماراتي الاتحادي رقم 45 لسنة 2021، ونظام حماية البيانات الشخصية PDPL في السعودية، وغيرها من القوانين ذات الصلة بحماية البيانات والخصوصية في الدول التي تعمل فيها SAP.
لدعم كيانات SAP المحلية في الالتزام بحماية البيانات والخصوصية، أنشأت SAP شبكة عالمية من متخصصي حماية البيانات والخصوصية. تتكون هذه الشبكة من مديري حماية البيانات المحليين (DPOs) ومنسقي حماية البيانات والخصوصية (DPPCs) الذين يرفعون إلى إدارة كيانات SAP التي يعملون لديها وإلى فريق حماية البيانات والخصوصية العالمي في SAP، الذي يرفع إلى مسؤول حماية البيانات بالمجموعة في SAP.
نبحث عن مستشار قانوني أول رفيع المستوى ليعمل كمسؤول حماية البيانات المحلي (DPO) لمصر وكمنسق حماية البيانات والخصوصية (DPPC) للدول العربية بما فيها الإمارات والسعودية، مسؤول عن قيادة استراتيجية امتثال حماية البيانات عبر بلد المسؤولية المحدد.
التوقعات والمهام
الدور مسؤول عن ضمان امتثال SAP لأنظمة حماية البيانات في مصر والقوانين المرتبطة بـ GDPR وحماية البيانات في الدول العربية المعينة. ينطوي هذا الدور على تعاون وثيق مع فريق حماية البيانات والخصوصية العالمي ووحدات الأعمال المحلية والإدارة العليا والجهات التنظيمية الخارجية لإدارة مخاطر حماية البيانات ودفع الوعي بالحماية والخصوصية عبر المنظمة.
وفقاً للقانون رقم 151 لسنة 2020، فإن DPO المحلي هو دور معترف به قانونياً ويتطلب تسجيلاً رسمياً لدى الجهة التنظيمية. يجب أن يستوفي المرشح المتطلبات القانونية التالية:
- التسجيل الرسمي: يجب أن يكون المرشح مسجلاً (أو مؤهلاً للتسجيل الفوري) في السجل الرسمي DPO المحفوظ من قبل مركز حماية البيانات الشخصية المصري (PDPC).
- إثبات القدرة القانونية (امتحان إجباري):
- لإتمام التسجيل مع PDPC، يجب أن يثبت المرشح بفعالية القدرات القانونية والتقنية في خصوصية البيانات.
- المتطلب: يجب أن يجتاز المرشح الامتحان الرسمي لـاعتماد PDPC (أو تقييم معتمد مكافئ) الذي يثبت معرفة عميقة باللائحة المصرية رقم 151 لسنة 2020، ولوائحها التنفيذية، وأطر نقل البيانات الدولية.
ملاحظة: استمرار التوظيف في هذا الدور مشروط بالنجاح في اجتياز هذا الامتحان والحصول/الحفاظ على التسجيل النشط مع PDPC.
المسؤوليات الأساسية:
- الامتثال والاستراتيجية التنظيمية:
- ضمان الامتثال لقانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020، وقانون الإمارات الاتحادي رقم 45 لسنة 2021، وقانون حماية البيانات الشخصية PDPL في السعودية، وGDPR، وغيرها من الأنظمة الإقليمية ذات الصلة.
- العمل كمسؤول حماية البيانات (DPO) المعتمد والمسجل رسميًا لجهات SAP القانونية في مصر أمام مركز حماية البيانات الشخصية المصري (PDPC)، مع ضمان استيفاء جميع متطلبات التسجيل والتراخيص المحلية.
- وضع وتنفيذ استراتيجية امتثال حماية البيانات شاملة لمصر والدول العربية المخصصة.
- مراقبة وتفسير وتقييم التغييرات في تشريعات حماية البيانات واللوائح والمعايير الصناعية عبر جميع الاختصاصات المعينة.
- تقديم تحديثات وتوجيهات وآراء قانونية بشأن التطورات التنظيمية وأفضل الممارسات في الوقت المناسب.
- إجراء وتوثيق التقييمات الدورية الإلزامية، فحص الأنظمة، وتدقيق حماية البيانات كما هو مطلوب بموجب المادة 9(1) من PDPL المصري، ودعم تنفيذ إجراءات الإصلاح.
- النصح الاستراتيجي والتمثيل:
- تقديم النصح القانوني والامتثالي حول قضايا حماية البيانات وإجراء تقييمات أثر حماية البيانات (DPIAs) للمشروعات الجديدة والمبادرات والتقنيات الناشئة، بما فيها تطبيقات AI/ML، لضمان التوافق مع إرشادات PDPC المصري والجهات التنظيمية الإقليمية.
- تمثيل مسؤول حماية البيانات لمجموعة SAP ضمن المنطقة المعينة والعمل كنقطة اتصال مباشرة ورئيسية لـ PDPC المصري والجهات التنظيمية الإقليمية الأخرى.
- قيادة تطوير وتنفيذ وصيانة سياسات واشتراطات حماية البيانات والخصوصية المحلية، والمعايير والإجراءات المتوافقة مع المتطلبات العالمية وفق استراتيجية حماية البيانات والخصوصية العالمية لـ SAP.
- مساعدة الممثلين القانونيين المحليين (الذين يحملون المسؤولية القانونية والجنائية وفق القانون المصري) ومديري الشؤون المالية في الوفاء بمسؤوليات حماية البيانات المحلية والعمليات القانونية الخاصة بالكيانات.
- الامتثال، إدارة المخاطر والعمليات:
- مراقبة وتقديم المشورة إلى وحدات الأعمال حول تنفيذ الإجراءات المحلية (سجلات أنشطة المعالجة - ROPA) لعمليات معالجة البيانات للكيان المصري، مع ضمان أنها متاحة للفحص من PDPC.
- إنشاء ومراقبة الامتثال لسياسات وإجراءات حماية البيانات والمتطلبات التنظيمية عبر جميع الكيانات المعينة.
- إدارة بروتوكولات استجابة لاختراق البيانات وفق عمليات SAP المعتمدة، وضمان أن أي اختراق بيانات شخصية يؤثر على أصحاب البيانات المصريين يُبلغ إلى PDPC والأشخاص المتأثرين خلال النافذة القانونية البالغة 72 ساعة، وفقاً للمادة 9(6) من PDPL.
- العمل كنقطة اتصال مخصصة للأفراد الخاضعين للبيانات، وتأسيس قنوات واضحة لاستقبال والتحقيق وحل طلباتهم وشكاواهم واستفساراتهم المتعلقة بحقوقهم وفق القانون المصري والإطارات الإقليمية.
- دعم تنفيذ تقييمات أثر نقل البيانات عبر الحدود والحصول على التراخيص اللازمة من PDPC حسب ما يتطلبه القانون المصري.
- التوعية والتدريب والتطوير التنظيمي:
- تنفيذ برامج تدريب مركزة بشأن حماية البيانات والخصوصية لمستويات تنظيمية مختلفة، مصممة لتلبية متطلبات الامتثال في مصر والسعودية والإمارات.
- تطوير والاحتفاظ بمواد ومواد التوعية بحماية البيانات والاتصالات.
- تقوية وتوسيع مجتمع حماية البيانات العالمي لشركة SAP ضمن المنطقة المعينة.
- التنسيق الإقليمي والتوحيد:
- وضع توائم لوثائق حماية البيانات والعمليات وطرق الامتثال عبر مصر والدول العربية المعينة بما يتماشى مع معايير DPP العالمية، مع احترام صارم لمتطلبات التوطين والسحابة السيادية المحلية (مثلاً لوائح سحابة السعودية ومصر).
- تنسيق مبادرات حماية البيانات وضمان الاتساق في التنفيذ عبر عدة ولايات قضائية.
- بناء والحفاظ على علاقات تعاونية مع أصحاب المصلحة المحليين والإقليميين، بما في ذلك الجهات الحكومية (خاصة PDPC في مصر، SDAIA في السعودية، ومكتب بيانات الإمارات)، وشركاء صناعيين، ومستشارين قانونيين خارجيين.
التعليم والمؤهلات / المهارات والكفاءات
المهارات المطلوبة
- درجة جامعية في القانون مع تخصص في حماية البيانات، الخصوصية، أو قانون تكنولوجيا المعلومات
- خبرة مهنية لا تقل عن 10 سنوات كمسؤول حماية البيانات، رئيس حماية الخصوصية، أو في دور قانوني/امتثالي رفيع يركز على حماية البيانات
- معرفة عملية ونظرية شاملة بالـ GDPR ولوائح حماية البيانات العالمية الأخرى
- خبرة موثقة في قانون حماية البيانات المصري رقم 151 لسنة 2020 و/أو أطر حماية البيانات الإماراتية والسعودية
- خبرة مهنية في إدارة مبادرات امتثال عبر ولايات قضائية متعددة
- قدرات إدارة مشاريع قوية مع قدرة على قيادة مبادرات معقدة تضم عدة أصحاب مصلحة
- مهارات عرض كتابي وشفهي استثنائية مع القدرة على تبسيط المفاهيم القانونية والتقنية المعقدة لجمهور غير متخصص
- مهارات تواصل قوية على جميع المستويات التنظيمية، بما في ذلك التنفيذيون من المستوى C
- القدرة على بناء والحفاظ على علاقات مع أصحاب المصلحة الداخليين والخارجيين، بما في ذلك الجهات التنظيمية
الخبرة الفنية والقانونية:
- فهم عميق لمبادئ حماية البيانات والأطر والمتطلبات التنظيمية في الولايات القضائية المعينة
- القدرة على إجراء DPIAs وتقييمات المخاطر