Job Description
Senior Officer Data Protection & Legal Advisory
Job Purpose
To facilitate the development of the Commission and Department’s mechanisms in adhering to data protection and privacy laws and policies and further evaluate those specific tools in assessing their relevance, adequacy, and effectiveness in data protection and privacy-related matters.
Primary Tasks and Responsibilities
1. Facilitate the Commission in complying with all data protection and privacy laws and policies.
2. Build the capacity of the Commission’s staff through sensitisation, training and communication of updates on all data protection and privacy issues.
3. Create tools and periodically review and evaluate the effectiveness of the Commission systems to ensure the relevance, adequacy, and effectiveness of the data protection laws and policies.
4. Conduct independent assessments and audits to ensure compliance of all the Commission units with the data protection laws and policies.
5. Monitor the compliance of the Commission with the telecommunication sector’s data protection and privacy obligations.
6. Implement privacy controls and management policies and procedures in the Commission.
7. Provide technical advisory on data protection and privacy issues.
8. Provide expert legal advisory services to the Commission’s Departments on applying the Communications Act and all attendant laws and advise on contractual matters and partnerships.
9. Draft and review all MoUs, agreements and contracts per the requirements of the Departments of the Commission to ensure compliance with statutory provisions and safeguard the Commission’s interest.
10. Research and analyse legal issues, stay updated with legal trends and developments and submit legal briefs as required on subject matters raised by user departments.
11. Maintain flexibility to accommodate any other duties that may be assigned by the supervisor from time to time.
Key Performance Indicators
1. Percentage of adherence to data protection and privacy laws and policies.
2. Knowledge assessments and incident response improvement.
3. Relevance and adequacy assessment completed.
4. Independent assessments and audits on data protection laws and policies are done.
5. Technical advisory on data protection and privacy.
6. Access controls to limit data exposure.
7. The success rate in phishing simulation tests and employee awareness.
8. Zero costs in financial losses resulting from data breaches.
Education and Professional Qualifications
· Master’s degree in a related field.
· Bachelor’s degree in Law (LLB).
· Enrolled as an advocate of the high court of Uganda.
· Membership in the relevant professional body.
Working Experience
Minimum of four (4) years’ experience in legal practice.
Skills, Knowledge and Abilities
Technical
· Knowledge of the data & privacy field.
· Intellectual and analytical ability.
· Risk assessment skills.
· Data protection training and awareness
Behavioural
· Communication skills
· Problem-solving
· Collaboration and Teamwork