Description :
Senior Analyst, Data Privacy Reporting to Director, Data Privacy within client GTO Information Security group, this role will serve as the Senior Analyst, Data Privacy for the GTO Privacy Office, and thus requires a very strong understanding and interest in data privacy specifically, and IT security / cybersecurity in general. The role focuses on assessing the appropriate use of personal information in projects & vendor agreements and providing subject matter expertise on privacy and data protection to business stakeholders to ensure incorporation of privacy-by-design into all required business processes, critical projects and initiatives. The resource in this role will primarily perform review and advisory duties, including conducting Privacy Impact Assessments on projects, conducting Vendor Due Diligence on new and existing vendors, leading data inventorying efforts, and collaborating with business units to identify solutions to minimize data privacy risks. This resource will also assist in developing the privacy program via creating / updating data security policies, authoring guidelines and playbooks to document Privacy Program processes and requirements, and improve the Privacy risk register and associated metrics / KPI reporting for assessing overall privacy compliance wellness. Duties include :
- Assess and manage review process of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs), analyzing responses to identify risks involving the collection, access, use, protection, storage and destruction of personal and / or sensitive information. Communicate data privacy related risks and develop and advise on the implementation of risk mitigation plans.
- Assess and manage data privacy area in vendor management process, which includes conducting Vendor Due Diligence (VDD) assessments of vendors, analyzing their responses to highlight privacy issues, and proposing steps to reduce risk to client . Partner with Security team to help identify security risks for further analysis.
- Lead data inventorying, data processing, business process documentation projects with data owners across the organization, and other efforts to maintain proper Records of Processing Activities (RoPAs)
- Collaborate with the Privacy Program Manager in applicable parts of issuing and managing vendor and third-party service provider questionnaires, creating status reports, providing content for Privacy Program documentation, and completing consumer rights requests (DSARs, DNS’s, etc.)
- Work closely with the Legal Privacy team to gather global regulatory and legal requirements, document them, and translate them to business unit and region-specific guidelines and standards for allowed technology and business processes
- Act as a subject matter expert in day-to-day privacy operational matters, providing data privacy and data protection expertise. This includes working closely with internal stakeholders in various corporate functions and lines of business to analyze and respond to their privacy-related issues and questions.
- Lead meetings and regularly liaise with product and business teams to ensure the Privacy Office remains abreast on new projects / products and that privacy-by-design principles being followed for them
- Enforce data privacy standards in advanced technology projects and the development of connected products, websites, and mobile apps.
- Oversee the maintenance of the overall picture of data collection and processing practices for employee and consumer data. This includes documenting data inventories, data maps, and data flows.
- Support the development of privacy policies and procedures for the Privacy Office
- Support the Director, Data Privacy in client enterprise Data Governance Committee in governance activities surrounding consumer data. This includes leading working groups concerning the management and use of consumer data and analytics.
- Collaborates with client GTO Security team on activities involving PII such as potential breach incidents, vendor transmission of PII, or company-wide risk assessments. Qualifications :
Minimum
Must have at least one of the following professional certifications : CIPP / US, CIPP / E, CIPT, CIPM, CIPP / C, CISSP.Degree from an accredited institution5+ years of Privacy experience, with the ability to apply critical thinking to a Data Protection & Privacy objective8+ years of analytical experience, preferably in Information Technology, such as in a business analyst role. Able to rigorously document and keep up to date data and business process flowsAdvanced hands-on experience in operational and technical aspects of data privacy and protection. This includes, experience reviewing Privacy Impact Assessments and experience conducting Vendor risk assessments for a large corporationExcellent working knowledge of privacy and data protection laws & regulations, including COPPA, CCPA / CPRA, the EU GDPR, the UK GDPR, CAN-SPAM, CASL, HIPAA, etc.Familiar with Privacy issues related to digital ad tech, such tags, cookies, pixels, and tag management systems such as Tealium, Google Tag Manager, Adobe Dynamic Tag Manager, etc.Knowledge of the use of various privacy compliance platforms (OneTrust, TrustArc) for privacy managementExperience with enforcing enterprise level information management principles and privacy by designExtremely strong Microsoft Visio, LucidChart, or other diagramming program skills. Will need to document data and business process flowsStrong Microsoft Powerpoint, Excel, and Office skills. These will need to be utilized collectively to convey insights and project progressProficiency in other often Microsoft Business Applications—Teams, SharePoint, OneDrive, Powerpoint, OneNote is essential for communication and organizing artifactsExhibits strong critical / analytical thinking and creative problem-solving skills. Resource will be expected to spot a problem and come up with suggested solutions to present to the Director, Data PrivacyStrong persuasion and negotiation ability, exhibiting diplomatic skills that can foster collaborative relationships across client in order to deliver results on Privacy complianceStrong verbal and written skills, with the ability to understand the intended audience to communicate effectivelyIndependent and self-motivated with the ability to operate autonomously but also take directionExtremely organized, and possessing keen attention to detail to found needs / issues, track them for continued awareness, and escalate appropriatelyHigh ethical standards, operating with integrity and professionalismPreferred
Business Analyst certifications, including but not limited to CIPP, CIPM, and / or CIPTPossesses knowledge of information technology (IT) systems and applications, and an understanding of how data, particularly PII, flows from system to systemPrevious experience using the various modules of TrustArcAdditional Qualifications : (Not required or preferred, a plus)
Additional Privacy certificationsCOPPA expertiseCybersecurity certifications such as CISSP, CISA, CISMCompliance or auditing experience in the area of data protection