We’re accepting applications for the position of PoPIA and PDPR Specialist. The purpose of this position will be to identify all processes, products, assets and third parties within a business area (global records or local records) where there is processing of personal information so that risk assessments can be performed and appropriate control measures implemented so that the organization can become compliant to applicable privacy legislations; to document processing activities according to their process/product hierarchies (process or product catalogues) in order to ensure that the correct data flow maps/diagrams can be created and kept up to date within the Record of Processing Activities (RoPA); to conduct assessments of existing organisational processes, products, services, apps and systems; and to conduct re-assessments of high and medium risk assessments of processing activities in order to re-evaluate the risk levels and adequacy and effectiveness of controls. (Contract role based in Johannesburg).
Duties and Responsibilities:
- Identifying all processes, products, assets and third parties within a business area (global records or local records) where there is processing of personal information so that risk assessments can be performed and appropriate control measures implemented so that the organization can become compliant to applicable privacy legislations
- Documenting processing activities according to their process/product hierarchies (process or product catalogues) in order to ensure that the correct data flow maps/diagrams can be created and kept up to date within the Record of Processing Activities (RoPA)
- Conducting assessments of existing organisational processes, products, services, apps and systems
- Conducting re-assessments of high and medium risk assessments of processing activities in order to re-evaluate the risk levels and adequacy and effectiveness of controls
- Conducting privacy impact assessments (Privacy by Design and Assurance) of new processes, products and systems to be launched or changes to existing processes, products or assets to ensure that all critical and high new business risks have been identified and mitigated before any product, service, promotion or campaign is launched
- Identifying the primary record according to the PRM reference model and linking the process or sub-process to the primary record accordingly
- Ensuring that there is an appropriate product catalogue with standard references and keeping it up to date per each business area in the Personal Data Processing Register (PDPR)
- Identifying and conducting re-assessments of processes, products, and assets every three years or when something significant changes Up-to-date processing activity records information is being maintained in the Personal Data Processing Register (PDPR)
- Making sure that all Organisational Privacy Impact Assessments (OPIA) and Privacy by Design (PDA) assessments being performed meet the quality criteria in their respective areas
- Furthermore, in every business area where there is personal information processing, keeping up-to-date data flow diagrams/maps that show standard reference numbers (PRM reference model) for personal information flowing from or to other business areas
- Lastly, ensuring that all assets associated with a processing activity are being assessed and risk-rated accordingly
Minimum Requirements:
- Relevant Degree at NQF Level 7 essential, further industry certifications advantageous
- At least 5 years experience in risk and compliance, business process reviews and re-engineering
- Experience in conducting privacy impact assessments using clearly defined methodologies or tools
- Experience in ensuring compliance with privacy laws and regulations, applicable professional standards and accepted business practices
- Ability to map business processes according to their hierarchical levels and knowledge of telecoms processes and functions will be an advantage
