We are looking for a Corporate Lawyer / Data Protection Officer (DPO) to support Tagaddod’s legal and regulatory compliance while taking ownership of the company’s personal data protection requirements.
The role will work closely with the Personal Data Protection Center (PDPC) and will be responsible for ensuring that the company’s collection, processing, storage, sharing, and transfer of personal data comply with Egyptian Personal Data Protection Law No. 151 of 2020, its Executive Regulations, and applicable PDPC requirements.
In addition, the role will provide day-to-day corporate legal support, including contract drafting and review, corporate governance, regulatory monitoring, and legal advice to internal stakeholders.
Key ResponsibilitieS
1. Data Protection & PDPC Compliance
Act as the primary point of contact between Tagaddod and the Personal Data Protection Center (PDPC).
Manage the company’s registration, licensing, permits, and other regulatory requirements applicable to data controllers and processors.
Ensure the company maintains the required registrations, licenses, records, and documentation under the applicable data protection framework.
Monitor the company’s personal data processing activities and ensure compliance with Law No. 151 of 2020, its Executive Regulations, and PDPC directives.
Conduct regular internal compliance reviews and identify areas requiring corrective action.
2. Data Privacy & Governance
Maintain an overview of the personal data collected, processed, stored, and shared across the company.
Maintain and update Records of Processing Activities (ROPA) and other statutory records required for regulatory inspection.
Conduct or coordinate Privacy Impact Assessments (PIAs) for high-risk personal data processing activities.
Develop and maintain internal data protection policies, procedures, and guidelines.
Work with HR, IT, Marketing, Sales, Product, and other departments to ensure privacy requirements are incorporated into business processes.
3. Data Subject Rights
Manage and coordinate data subject requests in accordance with Egyptian law, including requests relating to:
Access
Rectification
Erasure/forgetting
Objection
Ensure requests are properly documented, reviewed, and handled within the applicable statutory deadlines.
4. Data Breach Management
Lead the company’s personal data breach response process in coordination with IT, Information Security, and relevant stakeholders.
Assess and document personal data breaches and coordinate the required response.
Ensure applicable breaches are reported to the PDPC within the required statutory timelines, including the 72-hour notification requirement where applicable.
Coordinate notifications to affected individuals within the prescribed timelines.
Maintain records of incidents, actions taken, and corrective measures.
5. Cross-Border Data Transfers
Review and assess cross-border transfers of personal data.
Ensure international data transfers comply with applicable Egyptian statutory requirements and PDPC licensing requirements.
Review relevant contracts and agreements involving international data transfers.
Coordinate with internal stakeholders and external parties to ensure compliant data-transfer arrangements.
6. Privacy Awareness & Training
Deliver privacy and data protection training to employees across different departments.
Develop awareness materials and guidelines to help employees understand their responsibilities when handling personal data.
Promote a culture of data privacy and responsible data handling across the organization.
Corporate Legal Responsibilities
7. Contract Drafting & Review
Draft, review, and negotiate commercial and corporate agreements, including:
Vendor Agreements
Service Level Agreements (SLAs)
Non-Disclosure Agreements (NDAs)
Master Service Agreements (MSAs)
Ensure contracts adequately protect the company’s legal and commercial interests.
Review contractual risks and provide practical recommendations to relevant stakeholders.
8. Data Processing Agreements
Draft, review, and negotiate Data Processing Agreements (DPAs).
Ensure appropriate data protection and processing clauses are incorporated into commercial agreements.
Review third-party contracts to ensure appropriate personal data protection obligations are addressed.
9. Corporate Governance & Compliance
Support corporate secretarial activities and governance requirements.
Assist with preparing and maintaining General Assembly and Board meeting minutes.
Support Commercial Registry updates and required corporate filings.
Assist with filings and regulatory requirements before the General Authority for Investment and Free Zones (GAFI).
Maintain accurate corporate legal records and documentation.
10. Internal Legal Advisory
Provide clear and practical legal advice to internal stakeholders across all departments.
Identify legal and regulatory risks and recommend practical solutions that support business objectives.
Review business initiatives and processes from a legal and compliance perspective.
11. Regulatory Monitoring
Monitor developments and changes in Egyptian legislation and regulations relevant to the company.
Track updates related to data protection and privacy, corporate law, labor law, consumer protection, technology and digital regulations
Communicate relevant regulatory changes to stakeholders and support the implementation of required updates.
Desired Candidate Profile
Bachelor’s degree in Law from a recognized university.
1–3 years of relevant legal experience, preferably in corporate law, data protection, privacy, compliance, or a related field.
Strong interest and/or practical exposure to data protection and privacy regulations.
Good understanding of Egyptian Personal Data Protection Law No. 151 of 2020 and its regulatory framework is highly preferred.
Familiarity with the PDPC and data protection compliance requirements is a strong advantage.
Experience drafting and reviewing commercial contracts.
Good understanding of corporate governance and regulatory filings.
Strong legal research and analytical skills.
Excellent attention to detail and documentation skills.
Strong written and verbal communication skills.
Ability to work with multiple departments and translate legal requirements into practical business actions.
Strong organizational skills and ability to manage confidential information.
Fluency in Arabic and English.
نحن نبحث عن محامي شركات / مسؤول حماية البيانات (DPO) لدعم الامتثال القانوني والتنظيمي لشركة تجدد (Tagaddod)، مع تولي مسؤولية متطلبات حماية البيانات الشخصية للشركة.
سيعمل هذا الدور عن كثب مع المركز القومي لحماية البيانات الشخصية (PDPC)، وسيكون مسؤولاً عن ضمان أن جمع البيانات الشخصية ومعالجتها وتخزينها ومشاركتها ونقلها بالشركة يتوافق مع قانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020، ولائحته التنفيذية، ومتطلبات المركز القومي لحماية البيانات الشخصية ذات الصلة.
بالإضافة إلى ذلك، سيقدم هذا الدور دعماً قانونياً يومياً للشركة، بما في ذلك صياغة العقود ومراجعتها، وحوكمة الشركات، والمراقبة التنظيمية، وتقديم المشورة القانونية لأصحاب المصلحة الداخليين.
المسؤوليات الرئيسية
1. حماية البيانات والامتثال لمتطلبات المركز القومي لحماية البيانات الشخصية
العمل كنقطة اتصال رئيسية بين شركة "تجدد" والمركز القومي لحماية البيانات الشخصية (PDPC).
إدارة التسجيل والترخيص والتصاريح الخاصة بالشركة وغيرها من المتطلبات التنظيمية المطبقة على متحكمي ومعالجي البيانات.
ضمان احتفاظ الشركة بالتسجيلات والتراخيص والسجلات والوثائق المطلوبة بموجب إطار حماية البيانات المعمول به.
مراقبة أنشطة معالجة البيانات الشخصية بالشركة وضمان الامتثال للقانون رقم 151 لسنة 2020 ولائحته التنفيذية وتوجيهات المركز القومي لحماية البيانات الشخصية.
إجراء مراجعات امتثال داخلية منتظمة وتحديد المجالات التي تتطلب إجراءات تصحيحية.
2. خصوصية البيانات وحوكمتها
الحفاظ على نظرة عامة شاملة على البيانات الشخصية التي يتم جمعها ومعالجتها وتخزينها ومشاركتها عبر مختلف إدارات الشركة.
الاحتفاظ بسجلات أنشطة المعالجة (ROPA) وتحديثها والسجلات القانونية الأخرى المطلوبة للتفتيش التنظيمي.
إجراء أو تنسيق تقييمات الأثر على الخصوصية (PIAs) لأنشطة معالجة البيانات الشخصية ذات المخاطر العالية.
تطوير وصيانة السياسات والإجراءات والإرشادات الداخلية لحماية البيانات.
العمل مع إدارات الموارد البشرية، وتكنولوجيا المعلومات، والتسويق، والمبيعات، والمنتجات، والإدارات الأخرى لضمان دمج متطلبات الخصوصية في عمليات العمل.
3. حقوق أصحاب البيانات
إدارة وتنسيق طلبات أصحاب البيانات وفقاً للقانون المصري، بما في ذلك الطلبات المتعلقة بـ:
الوصول والاطلاع
التصحيح والتعديل
المحو/النسيان
الاعتراض
ضمان توثيق الطلبات ومراجعتها والتعامل معها بشكل صحيح ضمن المهل القانونية المحددة.
4. إدارة انتهاكات البيانات
قيادة عملية الاستجابة لانتهاكات البيانات الشخصية بالشركة بالتنسيق مع إدارة تكنولوجيا المعلومات وأمن المعلومات وأصحاب المصلحة المعنيين.
تقييم وتوثيق انتهاكات البيانات الشخصية وتنسيق الاستجابة المطلوبة.
ضمان الإبلاغ عن الانتهاكات ذات الصلة إلى المركز القومي لحماية البيانات الشخصية خلال المهل القانونية المطلوبة، بما في ذلك شرط الإخطار خلال 72 ساعة حيثما ينطبق ذلك.
تنسيق الإخطارات الموجهة للأفراد المتأثرين خلال الأطر الزمنية المحددة.
الاحتفاظ بسجلات الحوادث والإجراءات المتخذة والتدابير التصحيحية.
5. نقل البيانات عبر الحدود
مراجعة وتقييم عمليات نقل البيانات الشخصية عبر الحدود.
ضمان امتثال عمليات نقل البيانات الدولية للمتطلبات القانونية المصرية ومتطلبات الترخيص الخاصة بالمركز القومي لحماية البيانات الشخصية.
مراجعة العقود والاتفاقيات ذات الصلة التي تتضمن نقل البيانات دولياً.
التنسيق مع أصحاب المصلحة الداخليين والأطراف الخارجية لضمان ترتيبات نقل بيانات متوافقة.
6. التوعية بالخصوصية والتدريب
تقديم تدريبات على الخصوصية وحماية البيانات للموظفين في مختلف الإدارات.
إعداد مواد توعوية وإرشادات لمساعدة الموظفين على فهم مسؤولياتهم عند التعامل مع البيانات الشخصية.
تعزيز ثقافة خصوصية البيانات والتعامل المسؤول مع البيانات عبر المؤسسة.
المسؤوليات القانونية للشركة
7. صياغة العقود ومراجعتها
صياغة ومراجعة والتفاوض بشأن الاتفاقيات التجارية وعقود الشركات، بما في ذلك:
اتفاقيات الموردين
اتفاقيات مستوى الخدمة (SLAs)
اتفاقيات عدم الإفصاح (NDAs)
اتفاقيات الخدمة الرئيسية (MSAs)
ضمان حماية العقود للمصالح القانونية والتجارية للشركة بشكل كافٍ.
مراجعة المخاطر التعاقدية وتقديم توصيات عملية لأصحاب المصلحة المعنيين.
8. اتفاقيات معالجة البيانات
صياغة ومراجعة والتفاوض بشأن اتفاقيات معالجة البيانات (DPAs).
ضمان إدراج بنود حماية ومعالجة البيانات المناسبة في الاتفاقيات التجارية.
مراجعة عقود الأطراف الخارجية لضمان معالجة التزامات حماية البيانات الشخصية المناسبة.
9. حوكمة الشركات والامتثال
دعم أنشطة أمانة سر الشركات ومتطلبات الحوكمة.
المساعدة في إعداد وحفظ محاضر اجتماعات الجمعية العامة ومجلس الإدارة.
دعم تحديثات السجل التجاري والإيداعات المؤسسية المطلوبة.
المساعدة في الإيداعات والمتطلبات التنظيمية أمام الهيئة العامة للاستثمار والمناطق الحرة (GAFI).
الاحتفاظ بسجلات ووثائق قانونية دقيقة للشركة.
10. الاستشارات القانونية الداخلية
تقديم مشورة قانونية واضحة وعملية لأصحاب المصلحة الداخليين في جميع الإدارات.
تحديد المخاطر القانونية والتنظيمية والتوصية بحلول عملية تدعم أهداف العمل.
مراجعة المبادرات والعمليات التجارية من منظور قانوني ومنظور امتثال.
11. المراقبة التنظيمية
متابعة التطورات والتغييرات في التشريعات واللوائح المصرية ذات الصلة بالشركة.
تتبع التحديثات المتعلقة بحماية البيانات والخصوصية، وقانون الشركات، وقانون العمل، وحماية المستهلك، والتكنولوجيا واللوائح الرقمية.
توصيل التغييرات التنظيمية ذات الصلة إلى أصحاب المصلحة ودعم تنفيذ التحديثات المطلوبة.
المؤهلات والشروط المطلوبة في المتقدم
درجة البكالوريوس/الليسانس في القانون من جامعة معترف بها.
خبرة قانونية ذات صلة من سنة إلى 3 سنوات، ويفضل أن تكون في قانون الشركات، أو حماية البيانات، أو الخصوصية، أو الامتثال، أو مجال ذي صلة.
اهتمام قوي و/أو خبرة عملية باللوائح والأنظمة المتعلقة بحماية البيانات والخصوصية.
يُفضل بشكل كبير وجود فهم جيد لقانون حماية البيانات الشخصية المصري رقم 151 لسنة 2020 وإطاره التنظيمي.
تعد المعرفة بالمركز القومي لحماية البيانات الشخصية ومقتضيات الامتثال لحماية البيانات ميزة إضافية قوية.
خبرة في صياغة ومراجعة العقود التجارية.
فهم جيد لحوكمة الشركات والإيداعات التنظيمية.
مهارات ممتازة في البحث والتحليل القانوني.
اهتمام ممتاز بالتفاصيل ومهارات توثيق عالية.
مهارات اتصال شفهية وكتابية قوية.
القدرة على العمل مع إدارات متعددة وترجمة المتطلبات القانونية إلى إجراءات عمل عملية.
مهارات تنظيمية قوية والقدرة على إدارة المعلومات السرية.
إتقان اللغتين العربية والإنجليزية.