Job Responsibilities
The Data Protection Officer (DPO) will serve in a part-time capacity to oversee BTGT Europe’s compliance with GDPR and other relevant data protection laws. The DPO will act as an independent advisor and key point of contact for all data protection matters, facilitating cooperation between the company and relevant stakeholders.
Key Responsibilities
- Development and Maintenance of Data Protection Framework
- Establish and regularly update a GDPR compliance system, including policies, procedures, standards, and training materials.
- Documentation Management and Review
- Draft, review, and revise data protection policies, consent mechanisms, and other related documentation.
- Staff Training and Awareness
- Deliver regular training sessions and promote a culture of data protection awareness across the organization.
- Data Subject Request Handling
- Implement and manage procedures for processing access, correction, and deletion requests from data subjects.
- Data Breach Response
- Identify, report, investigate, and coordinate response plans for data breaches; ensure timely notification to relevant authorities and affected data subjects.
- Data Protection Impact Assessments (DPIAs)
- Conduct DPIAs for new data processing activities and periodically review existing ones.
- Vendor and Third-Party Management
- Monitor data protection practices of third-party vendors and oversee data processing agreements.
- Ongoing Monitoring and Auditing
- Perform regular audits and assessments of data processing activities to ensure compliance.
- Liaison with Authorities
- Serve as the primary contact with data protection authorities and facilitate cooperation when required.
- Cross-Border Data Transfers
- Ensure compliance with GDPR requirements regarding international data transfers.
- Legal and Regulatory Updates
- Stay up to date with changes in data protection legislation and industry best practices.
- Cross-Departmental Collaboration
- Work closely with IT, HR, Marketing, and the Asia Legal team to ensure enterprise-wide compliance with data protection standards.
Qualifications