CrawlJobs Logo

Data Protection Officer

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United Kingdom, London

Category Icon
Category:
Legal

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

Serves as a senior compliance risk officer for Independent Compliance Risk Management (ICRM) responsible for establishing internal strategies, policies, procedures, processes, and programs to prevent violations of law, rule, or regulation and design and deliver a risk management framework that maintains risk levels within the firm's risk appetite and protect the franchise. In addition, engages with the ICRM product and function coverage teams, in order to partner to develop and apply CRM program solutions that meet business and customer needs in a manner consistent with the Citi program framework.

Job Responsibility:

  • Implementing measures and a privacy governance framework to manage data use in compliance with the regulations, including developing templates for data collection, assisting with data mapping, and vendor management reviews
  • Working with key internal stakeholders in the review of projects and related data to ensure compliance with local data privacy laws, and where necessary, complete and advise on privacy impact assessments
  • Serving as the primary point of contact and liaison for the ICO and Jersey Channel Islands Data Protection Authorities on all data protection related matters under the regulations
  • Serving as the primary point of contact for queries in the business
  • Participating in the Data Privacy governance forums and committees where applicable
  • Managing and conducting ongoing reviews of Citi's privacy governance framework [including Binding Corporate Rules (BCR)3]
  • Monitoring changes to local privacy laws and making recommendations to senior management when appropriate
  • Setting standards and reviewing policies and procedures globally that meet the requirements under the regulations and any localization requirements in countries of operation
  • Developing and delivering privacy training to various business functions
  • Developing strategies and initiatives to ensure engagement with key internal and external stakeholders
  • Coordinating and conducting data privacy audits
  • Collaborating with the Information Security function(s) to raise employee awareness of data privacy and security issues and providing training on the subject matter
  • Collaborating with the Information Security function(s) to maintain records of all data assets and exports and maintaining a data security incident management plan to ensure timely remediation of incidents including impact assessments, security breach response, complaints, claims or notifications, and responding to subject access requests (SARs)
  • Working with designated privacy law attorneys across the Citi's offices and, where necessary, outside counsel to help advise on local data privacy law issues
  • Promoting effective work practices, working as a team member, and showing respect for co-workers

Requirements:

  • Substantial experience within a compliance, legal, audit and/or risk function, with recent experience in privacy compliance
  • Experience in developing policy and compliance training
  • Experience working in a regulated industry
  • Strong knowledge of data privacy and data protection regulation, and a good understanding of other major privacy frameworks and evolving legislation worldwide
  • Sufficient knowledge of information technology and data management systems required
  • Well-developed and professional interpersonal skills
  • ability to interact effectively with people at all organisational levels of the firm
  • Experience of working in a large, global organisation
  • Ability to work unsupervised, exercise leadership, and influence change
  • Excellent writing and presentation skills
  • Strong change and project management skills, including the ability to manage time well, prioritize effectively, and handle multiple deadlines
  • Ability to undertake large, long-term projects, develop alternative methods to complete them, and implement solutions
  • Ability to use independent judgment and discretion when making majority of decisions
  • Detail-oriented approach needed to recommend and implement strategic improvements on a range of data privacy and data protection issues
  • Ability to handle confidential and sensitive information with the appropriate discretion
  • Knowledge of PC applications, including MS Office

Nice to have:

Preferably hold at least one Data Protection and/or Privacy certification such as, CIPP/E, CIPM, AIGP

What we offer:
  • Generous holiday allowance starting at 27 days plus bank holidays
  • increasing with tenure
  • A discretional annual performance related bonus
  • Private medical insurance packages to suit your personal circumstances
  • Employee Assistance Program
  • Pension Plan
  • Paid Parental Leave
  • Special discounts for employees, family, and friends
  • Access to an array of learning and development resources

Additional Information:

Job Posted:
June 06, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.