About the job
As the Data Protection Officer (DPO) at gsstech-group, you will play a pivotal role in ensuring our organization's adherence to data protection and privacy laws. You will oversee the lawful processing of personal and sensitive data while serving as the primary liaison with regulators concerning data privacy issues.
Key Responsibilities:
1. Regulatory Compliance & Governance:
- Ensure compliance with UAE Federal Decree-Law No. 45 of 2021 (Personal Data Protection Law – PDPL), UAE Data Office regulations, and applicable CBUAE requirements.
- Develop, implement, and maintain comprehensive data protection policies, standards, and procedures.
- Integrate privacy governance across insurance operations including underwriting, claims, customer service, digital channels, and analytics platforms.
2. Advisory & Oversight:
- Provide guidance to senior management and business units regarding data protection obligations and associated risks.
- Support the implementation of Privacy-by-Design and Privacy-by-Default principles across systems and processes.
- Review new initiatives involving personal data, cloud services, AI/ML, and third-party integrations.
3. Data Subject Rights Management:
- Oversee the processes for managing data subject access, correction, erasure, restriction, objection, and portability requests.
- Act as an escalation authority for data privacy complaints and disputes.
4. Incident & Breach Management:
- Lead the assessment and response to data breaches and privacy incidents.
- Coordinate regulatory notifications and remediation actions within statutory timelines.
5. Risk Assessments & Documentation:
- Conduct Data Protection Impact Assessments (DPIAs).
- Maintain Records of Processing Activities (RoPA).
- Identify, assess, and mitigate privacy risks associated with systems, applications, and vendors.
6. Third-Party & Cross-Border Data Management:
- Review and approve Data Processing Agreements (DPAs).
- Ensure compliance with PDPL and regulatory requirements for cross-border data transfers.
7. Training, Awareness & Audit Support:
- Drive organization-wide data privacy awareness and training initiatives.
- Assist with internal and external audits, as well as regulatory inspections.
8. Regulatory Liaison & Reporting:
- Serve as the primary contact with the UAE Data Office and other regulatory bodies.
- Prepare and provide periodic compliance reports to senior management and the Board.

