Data Protection Officer job at The Nairobi Hospital
New
Website :
1 Day Ago
Linkedid Twitter Share on facebook
Data Protection Officer
2025-12-04T17:49:40+00:00
The Nairobi Hospital
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_2742/logo/The%20Nairobi%20Hospital.png
FULL_TIME
 
Nairobi
Nairobi
00100
Kenya
Health Care
Legal, Management, Business Operations, Computer & IT, Healthcare
KES
 
MONTH
2025-12-15T17:00:00+00:00
 
Kenya
8

Background information about the job or company (e.g., role context, company overview)

Opened in 1954, The Nairobi Hospital has excelled in medical expertise and services provision and has deservedly earned recognition throughout East Africa and beyond as an advanced diagnostic, treatment and referral centre. Expansive investment in latest technology and medical equipment has enabled us establish leadership in medical procedures both in Kenya ...

Reporting to the Company Secretary, the successful candidate will be responsible for implementing and enforcing Hospital wide data protection compliance framework and systems to ensure the Hospital is compliant with the Data protection laws and regulations.

Responsibilities or duties

  • Act as the primary point of contact within the Hospital for members of staff, regulators, and any relevant public bodies on issues related to data protection.
  • Advise the Hospital and employees on data processing requirements provided under this Act or any other written laws.
  • Establishing a Data Protection framework and implementation plan, amend existing internal data protection policies, guidelines, and procedures, in consultation with key stakeholders including developing templates for data collection and assisting with data mapping.
  • Support the Hospital in preparation of privacy statements for each processing operation, and ensuring processes are put in place to ensure that the privacy statement is provided to data subjects on all Hospital forms and/or literature, websites and other communication or data collection mediums.
  • Promote a culture of data protection compliance across all units of the Hospital.
  • Collaborating with the Information Security function to maintain records of all data assets and exports and maintaining a data security incident management plan to ensure timely remediation of incidents including impact assessments, security breach response, complaints, claims or notifications and responding to subject access requests.
  • Promptly informing the direct supervisor about possible threats and incidents impacting normal workflow and data processing.
  • Hold trainings with staff members across different Hospital units who are involved in data handling or processing.
  • Perform Data Protection Impact Assessments for projects and any new products and services where personal data will be processed.
  • Proactively conduct audits to ensure compliance and address potential issues regarding data privacy.
  • Maintain records of all data processing activities carried out by the Hospital.
  • Serving as a point of contact between the Hospital and Regulatory Authorities and co-operating with them during inspections and co-operate with the data Commissioner and any other authority on matters relating to data protection.
  • Interfacing with data controllers and data subjects to inform them about the use of their data, their data protection rights, obligations, responsibilities, the measures the Hospital has put in place to protect their personal information and to raise awareness on the above.
  • Review vendor contracts to drive achievement of 100% inclusion of data protection clauses in partnership with Supply Chain, Information Security, and legal function.
  • Ensure all queries from data subjects seeking to exercise their rights are responded to within required timeframes and required reports are timely filed with the regulator.
  • Coordinate reporting of data breaches to data protection commissioner.
  • Respond to all data protection queries on behalf of the Hospital
  • Respond to any notice on data breach and make follow up for adequate reporting with lessons learnt for all identified data breaches.
  • Work with management to prioritize business and information security needs.
  • Identify and define new process improvement opportunities on data protection.
  • Report on compliance gaps noted and ensure that the needed improvements are recommended.
  • Work with legal team to ensure full compliance on all data protection laws.
  • Providing quarterly status updates to senior and middle management and drawing immediate attention to any failure to comply with the applicable data protection rules.
  • Any other responsibilities that may be assigned to the job holder by the supervisor from time to time.

Qualifications or requirements (e.g., education, skills)

  • Law Degree from an accredited University.
  • Possess current Practising Certificate as an Advocate of the High Court.
  • Certified Information Systems Auditor (CISA) certification/ Certified Information Systems Security Professional (CISSP)/ Certified Information Security Manager (CISM) certification.
  • Strong analytical skills and ability to make decisions.
  • Ability to work well under pressure and manage sensitive and confidential information
  • Excellent verbal and written communication skills, with strong attention to detail
  • Great interpersonal skills and ability to work well both independently and as part of a team

Experience needed

12 months

Any other provided details (e.g., benefits, work environment, team info, or additional notes)

CORE COMPETENCIES

  • Ability to provide legal advice and opinions
  • Negotiation skills
  • Drafting skills
  • Communication skills
  • Interpersonal skills
  • Keen on learning new skills
  • Team working skills
  • Judgement and decision-making skills
  • Planning and organising skills
  • Integrity
  • Confidentiality
  • Act as the primary point of contact within the Hospital for members of staff, regulators, and any relevant public bodies on issues related to data protection.
  • Advise the Hospital and employees on data processing requirements provided under this Act or any other written laws.
  • Establishing a Data Protection framework and implementation plan, amend existing internal data protection policies, guidelines, and procedures, in consultation with key stakeholders including developing templates for data collection and assisting with data mapping.
  • Support the Hospital in preparation of privacy statements for each processing operation, and ensuring processes are put in place to ensure that the privacy statement is provided to data subjects on all Hospital forms and/or literature, websites and other communication or data collection mediums.
  • Promote a culture of data protection compliance across all units of the Hospital.
  • Collaborating with the Information Security function to maintain records of all data assets and exports and maintaining a data security incident management plan to ensure timely remediation of incidents including impact assessments, security breach response, complaints, claims or notifications and responding to subject access requests.
  • Promptly informing the direct supervisor about possible threats and incidents impacting normal workflow and data processing.
  • Hold trainings with staff members across different Hospital units who are involved in data handling or processing.
  • Perform Data Protection Impact Assessments for projects and any new products and services where personal data will be processed.
  • Proactively conduct audits to ensure compliance and address potential issues regarding data privacy.
  • Maintain records of all data processing activities carried out by the Hospital.
  • Serving as a point of contact between the Hospital and Regulatory Authorities and co-operating with them during inspections and co-operate with the data Commissioner and any other authority on matters relating to data protection.
  • Interfacing with data controllers and data subjects to inform them about the use of their data, their data protection rights, obligations, responsibilities, the measures the Hospital has put in place to protect their personal information and to raise awareness on the above.
  • Review vendor contracts to drive achievement of 100% inclusion of data protection clauses in partnership with Supply Chain, Information Security, and legal function.
  • Ensure all queries from data subjects seeking to exercise their rights are responded to within required timeframes and required reports are timely filed with the regulator.
  • Coordinate reporting of data breaches to data protection commissioner.
  • Respond to all data protection queries on behalf of the Hospital
  • Respond to any notice on data breach and make follow up for adequate reporting with lessons learnt for all identified data breaches.
  • Work with management to prioritize business and information security needs.
  • Identify and define new process improvement opportunities on data protection.
  • Report on compliance gaps noted and ensure that the needed improvements are recommended.
  • Work with legal team to ensure full compliance on all data protection laws.
  • Providing quarterly status updates to senior and middle management and drawing immediate attention to any failure to comply with the applicable data protection rules.
  • Any other responsibilities that may be assigned to the job holder by the supervisor from time to time.
  • Ability to provide legal advice and opinions
  • Negotiation skills
  • Drafting skills
  • Communication skills
  • Interpersonal skills
  • Keen on learning new skills
  • Team working skills
  • Judgement and decision-making skills
  • Planning and organising skills
  • Integrity
  • Confidentiality
  • Law Degree from an accredited University.
  • Possess current Practising Certificate as an Advocate of the High Court.
  • Certified Information Systems Auditor (CISA) certification/ Certified Information Systems Security Professional (CISSP)/ Certified Information Security Manager (CISM) certification.
  • Strong analytical skills and ability to make decisions.
  • Ability to work well under pressure and manage sensitive and confidential information
  • Excellent verbal and written communication skills, with strong attention to detail
  • Great interpersonal skills and ability to work well both independently and as part of a team
bachelor degree
12
JOB-6931c9b425fbd

Vacancy title:
Data Protection Officer

[Type: FULL_TIME, Industry: Health Care, Category: Legal, Management, Business Operations, Computer & IT, Healthcare]

Jobs at:
The Nairobi Hospital

Deadline of this Job:
Monday, December 15 2025

Duty Station:
Nairobi | Nairobi | Kenya

Summary
Date Posted: Thursday, December 4 2025, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about The Nairobi Hospital
The Nairobi Hospital jobs in Kenya

JOB DETAILS:

Background information about the job or company (e.g., role context, company overview)

Opened in 1954, The Nairobi Hospital has excelled in medical expertise and services provision and has deservedly earned recognition throughout East Africa and beyond as an advanced diagnostic, treatment and referral centre. Expansive investment in latest technology and medical equipment has enabled us establish leadership in medical procedures both in Kenya ...

Reporting to the Company Secretary, the successful candidate will be responsible for implementing and enforcing Hospital wide data protection compliance framework and systems to ensure the Hospital is compliant with the Data protection laws and regulations.

Responsibilities or duties

  • Act as the primary point of contact within the Hospital for members of staff, regulators, and any relevant public bodies on issues related to data protection.
  • Advise the Hospital and employees on data processing requirements provided under this Act or any other written laws.
  • Establishing a Data Protection framework and implementation plan, amend existing internal data protection policies, guidelines, and procedures, in consultation with key stakeholders including developing templates for data collection and assisting with data mapping.
  • Support the Hospital in preparation of privacy statements for each processing operation, and ensuring processes are put in place to ensure that the privacy statement is provided to data subjects on all Hospital forms and/or literature, websites and other communication or data collection mediums.
  • Promote a culture of data protection compliance across all units of the Hospital.
  • Collaborating with the Information Security function to maintain records of all data assets and exports and maintaining a data security incident management plan to ensure timely remediation of incidents including impact assessments, security breach response, complaints, claims or notifications and responding to subject access requests.
  • Promptly informing the direct supervisor about possible threats and incidents impacting normal workflow and data processing.
  • Hold trainings with staff members across different Hospital units who are involved in data handling or processing.
  • Perform Data Protection Impact Assessments for projects and any new products and services where personal data will be processed.
  • Proactively conduct audits to ensure compliance and address potential issues regarding data privacy.
  • Maintain records of all data processing activities carried out by the Hospital.
  • Serving as a point of contact between the Hospital and Regulatory Authorities and co-operating with them during inspections and co-operate with the data Commissioner and any other authority on matters relating to data protection.
  • Interfacing with data controllers and data subjects to inform them about the use of their data, their data protection rights, obligations, responsibilities, the measures the Hospital has put in place to protect their personal information and to raise awareness on the above.
  • Review vendor contracts to drive achievement of 100% inclusion of data protection clauses in partnership with Supply Chain, Information Security, and legal function.
  • Ensure all queries from data subjects seeking to exercise their rights are responded to within required timeframes and required reports are timely filed with the regulator.
  • Coordinate reporting of data breaches to data protection commissioner.
  • Respond to all data protection queries on behalf of the Hospital
  • Respond to any notice on data breach and make follow up for adequate reporting with lessons learnt for all identified data breaches.
  • Work with management to prioritize business and information security needs.
  • Identify and define new process improvement opportunities on data protection.
  • Report on compliance gaps noted and ensure that the needed improvements are recommended.
  • Work with legal team to ensure full compliance on all data protection laws.
  • Providing quarterly status updates to senior and middle management and drawing immediate attention to any failure to comply with the applicable data protection rules.
  • Any other responsibilities that may be assigned to the job holder by the supervisor from time to time.

Qualifications or requirements (e.g., education, skills)

  • Law Degree from an accredited University.
  • Possess current Practising Certificate as an Advocate of the High Court.
  • Certified Information Systems Auditor (CISA) certification/ Certified Information Systems Security Professional (CISSP)/ Certified Information Security Manager (CISM) certification.
  • Strong analytical skills and ability to make decisions.
  • Ability to work well under pressure and manage sensitive and confidential information
  • Excellent verbal and written communication skills, with strong attention to detail
  • Great interpersonal skills and ability to work well both independently and as part of a team

Experience needed

12 months

Any other provided details (e.g., benefits, work environment, team info, or additional notes)

CORE COMPETENCIES

  • Ability to provide legal advice and opinions
  • Negotiation skills
  • Drafting skills
  • Communication skills
  • Interpersonal skills
  • Keen on learning new skills
  • Team working skills
  • Judgement and decision-making skills
  • Planning and organising skills
  • Integrity
  • Confidentiality

 

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure
Interested in applying for this job? Click here to submit your application now.

 Only shortlisted candidates will be contacted. We shall ONLY accept ONLINE applications and contact SHORTLISTED candidates.

The Nairobi Hospital does NOT charge recruitment fees.

Ag. Head of Human Resources

The Nairobi Hospital

P. O. Box 30026 – 00100

NAIROBI

 

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Data, Monitoring, and Research jobs in Kenya
Job Type: Full-time
Deadline of this Job: Monday, December 15 2025
Duty Station: Nairobi | Nairobi | Kenya
Posted: 04-12-2025
No of Jobs: 1
Start Publishing: 04-12-2025
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.