Key Responsibilities:
1.) Data Privacy Compliance
- Assist the Data Protection Officer (DPO) in implementing and maintaining DITO's Privacy Management Program (PMP).
- Monitor and ensure compliance with relevant data protection regulations, including, but not limited to, the Data Privacy Act of 2012.
- Conduct regular testing and assessments to validate or verify DITO's continued adherence to data protection requirements and standards.
- Assisting the DPO and the privacy team to stay updated in relation to developments in data protection laws and regulations and implement necessary changes to relevant company procedures, policies, and practices.
- Ensure the timely preparation of reports to be submitted via the relevant platforms of the NPC, including, but not limited to the NPCRS and the DBNMS.
- Serve as the liaison between DITO and the National Privacy Commission.
- Serve as DITO's representative to the telecommunications sector for privacy-related concerns.
2.) Privacy Policy Development and Implementation
- Assist the DPO in conceptualizing, developing, reviewing, and updating privacy-centric policies, procedures, and guidelines in accordance with regulatory requirements and relevant industry standards and best practices.
- Review and keep the Privacy Manual updated in accordance with regulatory requirements and best practices.
- Communicate privacy-centric policies and procedures to employees and both internal and external stakeholders to ensure that there is understanding and compliance across DITO.
3.) Privacy Impact Assessments (PIAs)
- Lead the conduct of PIAs for new processes, technologies, systems, or products to identify and assess potential privacy risks and recommend measures to mitigate such risks.
- Collaborate with project proponents to ensure that privacy by design is observed in the design and development of new initiatives involving the processing of personal data.
- Lead the review of previously conducted PIAs to ensure that the findings and recommendations remain relevant and up to date.
4.) Data Subject Rights Management
- Assess the validity of data subject requests received by DITO and respond to them within the period provided by the National Privacy Commission and internal.
5.) Incident Response and Data Breach Management
- Work closely with relevant stakeholders, especially the Security Operations Center in maintaining and optimizing incident response plans for addressing security incidents and personal data breaches.
- Assist the DPO in investigating security incidents and data breaches, coordinating with the relevant internal and external stakeholders, and deploying remediation measures where necessary.
- Serve as the point of contact for the National Privacy Commission and the data subjects in case of a personal data breach.
- Serve as DITO's representative in response to subpoenas and warrants, including appearing when required to testify or to attest to DITO's response letters relating to the preservation, verification, or certification of personal data.
6.) Advisory and Support Functions
- Assist the DPO in providing guidance to business units on lawful data processing, data subject rights, and data protection principles.
- Review and provide inputs on contracts, forms, privacy notices, consent statements, and data privacy agreements.
7.) Training and Awareness
- Assist the DPO in developing and delivering training programs and awareness campaigns to educate employees and other relevant stakeholders on data protection rules and regulations and internal policies and procedures on privacy.
- Assist the DPO in leading initiatives that will foster a culture of privacy awareness and accountability throughout DITO.
8.) Vendor and Third-Party Management
- Evaluate the data protection practices of vendors and third-party service providers to ensure that such vendors and providers meet DITO's privacy requirements.
- Lead the negotiation and review of contracts with third parties to ensure that appropriate data protection clauses and safeguards are included.
Employment Standards:
- Must have at least 3 years worth of experience as a lawyer.
- Must at least have 2 years worth of experience in privacy and data protection.
- Experience in a similar role within the telecommunications sector or in a highly regulated sector is a plus.
Job Skills & Qualifications:
- Relevant privacy trainings and certifications are a plus, such as Certified Information Privacy manager (CIPM) and Certified Information Privacy Professional (CIPP).
- Has excellent analytical and problem-solving skills, with a keen attention to detail.
- Must possess outstanding writing ability and oral communications skills.
- Expertise in writing lengthy, detailed reports under tight deadlines.
- Must possess the highest level of work ethic and the ability to maintain confidential information.
- Ability to solve practical problems and carry out responsibilities under minimal supervision.
- Must have the ability to lead a team effectively and efficiently.
- Excellent analytical, research, interpersonal and facilitative skills.
- Ability to adapt as organization evolves.
We regret to inform that only shortlisted candidates will be notified.