Demo

Data Protection Officer (GMG/SEG 3) (Band 9) (vacant)

Ministry of Health
Oregon, IL Full Time
POSTED ON 3/19/2025
AVAILABLE BEFORE 4/18/2025

Data Protection Officer (GMG / SEG 3) (Band 9) (vacant)

Published : May 28, 2024

Do not pass up this chance, apply quickly if your experience and skills match what is in the following description.

JOB PURPOSE

Under the general leadership and direction of the Permanent Secretary, the Data Protection Officer will be responsible for monitoring compliance and data practices in an independent manner for the Ministry, the Regional Health Authorities, and its other agencies regarding the provisions of the Data Protection Act 2020 of the Government of Jamaica. The incumbent will also serve as the primary point of contact within the Ministry for all data subjects, including members of staff, clients / patients, suppliers, and any relevant public bodies on issues related to data privacy and data protection. The Data Protection Officer also reviews policies that enforce compliance with applicable legislation and trains staff to increase awareness of data privacy and protection requirements.

KEY OUTPUT

  • Internal DPA compliance monitored
  • Advice regarding Data Protection Impact Assessments (DPIAs) provided
  • Data protection and compliance training developed
  • Compliance Gap Assessment Report produced
  • Data Subject Access Request (DSAR) Log reviewed
  • Monthly / Quarterly DPA Compliance Status Reports submitted
  • Legislative advice on Data Protection and privacy-related issues provided
  • Robust and comprehensive Data Quality and Protection controls established
  • Technical advice / information provided
  • Reports, Cabinet Submissions / Notes, technical papers, and publications prepared and issued
  • Annual / Quarterly / Monthly performance Reports prepared

Key responsibility areas INCLUDE :

  • Establishes and maintains various Data Protection / Privacy Policy Committees / Technical Working Groups that provide policy insight and make recommendations for the implementation of improved procedures and systems;
  • Prepares and delivers presentations related to Data Protection / Privacy Policy as needed;
  • Participates in meetings, seminars, workshops, and conferences as required;
  • Prepares reports and programme documents as required; Leads and directs internal reviews to ensure compliance with applicable standards and address potential issues.
  • Reviews internal policies and procedures to support compliance with applicable laws, regulations, and standards;
  • Recommends corrective measures necessary to address areas of non-compliance with the Authority’s data privacy and data protection obligations and monetary fines / penalties applicable;
  • Implements strategies and a privacy governance framework to manage personal and sensitive personal data used in compliance with the Data Protection Act 2020;
  • Reviews data protection impact assessments by applying data quality controls as prescribed in the Data Governance Framework to determine compliance with regulatory requirements;
  • Collaborates with the Information Communication and Technology (ICT) Teams in the maintenance of a cyber-security incident management plan to ensure timely remediation of incidents including impact assessments, security breach response, complaints, claims, or notifications and responding to subject access requests;
  • Monitors to ensure that the Ministry’s ICT Systems and procedures comply with the relevant data privacy and protection law, regulation, and policy;
  • Monitors to ensure that the Ministry’s procedures and policies for processing personal and sensitive personal data are in compliance with the data protection standards of the Act and its Regulations and the Good Practice guidelines of the Ministry;
  • Evaluates existing policies and procedures to coordinate internal practices and to ensure compliance with regulations;
  • Reviews the Ministry’s internal control mechanisms to ensure that they are aligned with standards and provisions outlined in the Data Protection Act;
  • Reviews and documents the legal basis for processing personal and sensitive personal data;
  • Provides legislative advice and guidance to the Executive Management Team as to gaps identified from the outcome of the Data Protection and Privacy Impact Assessment process;
  • Serves as the primary point of contact for the Information Commissioner on all data protection matters;
  • Establishes a process for receiving, documenting, tracking, investigating, and taking action on all complaints concerning the organization’s privacy policies and procedures;
  • Identifies compliance breaches as they arise and advises management on rules and controls and escalates to the Information Commissioner as the need arises;
  • Consults with the Office of the Information Commissioner to resolve any doubt about how the provisions of the Act and its regulations are to be applied;
  • Receives and responds to comments and queries from data subjects related to the processing of personal data;
  • Provides guidance and assistance to data subjects, RHAs, and BPOs in exercising their rights under the Act (Section 6-13) as it relates to : The right to Access , The right to prevent processing , The right in relation to automated decision making , and The right to rectification ;
  • Provides advice / information to the Ministry and its employees on their obligations under the Act and data protection provisions;
  • Develops and implements approved certification mechanisms to demonstrate compliance;
  • Keeps abreast of amendments to policies, procedures, and legislation and any pertinent developments within the dynamic environments;
  • Monitors and evaluates the Ministry’s efforts at corrective actions to ensure that findings and recommendations (weaknesses and or deficiencies) are effectively dealt with;
  • Prepares reports and presentations on findings and analysis;
  • Facilitates the training of staff on the components of the Act, Regulations, and policies;
  • Minimum Required Education and Experience

  • Undergraduate Degree in Information Security, Law, Computer Science, Information Technology, Data Privacy, or a related field.
  • At least one (1) International Association of Privacy Professionals (IAPP) certification :
  • Certified Information Privacy Professional (CIPP)

  • Certified Information Privacy Manager (CIPM)
  • Certified Information Privacy Technologist (CIPT)
  • At least one (1) ISACA certification in Governance and Risk Management :
  • Certified in Risk and Information Systems Control (CRISC)

  • Certified in Governance of Enterprise IT (CGEIT)
  • Certified Information Security Manager (CISM)
  • At least 3-5 years’ work experience in Privacy, Compliance, Information Security, Auditing, or a relevant field (Finance, Law, Business Administration, Information Technology).
  • Sound knowledge of the Access to Information Act and anti-corruption.
  • Experience in the following areas is an asset :
  • Mapping / understanding business processes and data handling or processing needs in a relevant / related industry.

  • Cybersecurity – dealing with real security incidents, risk assessments, countermeasures, and data protection impact assessments.
  • Applications with résumés are to be submitted no later than Friday, June 14, 2024 to :

    The Ministry of Health thanks all applicants for their interest; however, please note that only short-listed candidates will be contacted.

    J-18808-Ljbffr

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Data Protection Officer (GMG/SEG 3) (Band 9) (vacant)?

    Sign up to receive alerts about other jobs on the Data Protection Officer (GMG/SEG 3) (Band 9) (vacant) career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $88,359 - $121,264
    Income Estimation: 
    $93,716 - $124,745
    Income Estimation: 
    $118,976 - $146,289
    Income Estimation: 
    $112,672 - $149,113
    Income Estimation: 
    $98,475 - $115,895
    Income Estimation: 
    $135,811 - $184,429
    Income Estimation: 
    $176,131 - $238,730
    Income Estimation: 
    $172,979 - $241,697
    Income Estimation: 
    $123,246 - $161,441
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Not the job you're looking for? Here are some other Data Protection Officer (GMG/SEG 3) (Band 9) (vacant) jobs in the Oregon, IL area that may be a better fit.

    Armed Security Officer

    State Protection Service, Inc., Rockford, IL

    Unarmed Security Officer

    State Protection Service, Inc., Rochelle, IL

    AI Assistant is available now!

    Feel free to start your new journey!