Data Protection Officer (DPO)
Legal & Compliance
K sh 180,000 – 320,000 gross / month
Openings: 1 Location: Nairobi – Kileleshwa (Siaya Rd, near Kasuku Centre) Overview: Our client is on the lookout for a Data Protection Officer (DPO) to own privacy across their Nairobi operations. From RoPA upkeep to vendor DPAs, you’ll make sure the business treats personal data not as a checkbox, but as a daily discipline. Think of it as turning legalese into practical, enforceable routines that everyone can follow. Day-to-day, you’ll run DPIAs, handle DSARs, and coordinate with ODPC, Security, Product, and HR. You’ll review cross-border transfers, embed privacy-by-design into workflows, and ensure that consent, retention, and deletion practices are airtight. Training, audits, and reporting will be your stage to shine. You’ll coach teams, track KPIs, and close compliance gaps before they escalate. It’s the perfect mix of advisory, enforcement, and influence across functions. In short, this role blends regulatory rigor with hands-on implementation, giving you real sway over how the organization treats data while keeping it agile and compliant. Key Responsibilities: - Maintain RoPA; oversee DPIAs and mitigation tracking. - Draft privacy notices, consent flows, retention & deletion schedules. - Handle DSARs, breach response, and ODPC liaison. - Review vendor DPAs, SCCs, and transfer mechanisms. - Train teams; audit compliance; report KPIs to EXCO. - Embed privacy-by-design in product and marketing workflows. Education & Experience: - LL.B/IT/InfoSec; CIPP/E or similar is a plus. - 4–6 years privacy/GRC with Kenyan DPA exposure. Skills & Tools: - Policy drafting, privacy tools, DSAR workflows, risk analysis, comms. KPIs: - DSAR SLA, DPIA completion rate, privacy incidents, and audit findings closed. Compensation (Kenya): KES 180,000–320,000 + annual bonus. Figures are estimates shared by our clients and vary with your experience, interview performance, certifications, and company pay bands. Benefits: - Medical, pension, training, professional fees (privacy association). Growth Path: - Senior DPO → Head of Privacy/GRC → Chief Risk & Compliance Officer. Ideal hierarchy and expected promotion cycle.