Group Data Protection Officer
2025-12-10T03:08:24+00:00
Summit Recruitment and Search
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_8022/logo/Summit%20Recruitment%20and%20Search.png
https://www.summitrecruitment-search.com/
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Research
Management, Computer & IT, Business Operations, Legal, Recruitment
2025-12-18T17:00:00+00:00
Kenya
8
Our client, a leading organization in the hospitality industry with operations across East Africa, is seeking an experienced and highly competent Group Data Protection Officer (DPO) to oversee data privacy and compliance across its hotels, lodges, travel services, and regional corporate functions.
The DPO will ensure that all personal data relating to guests, employees, suppliers, and partners is processed in full compliance with regional data protection laws and international standards.
The ideal candidate is a compliance expert with excellent stakeholder management skills, and a proven ability to implement practical, organization-wide data protection frameworks.
Key Responsibilities
- Ensure all business units comply with the Kenya DPA (2019), Tanzanian PDPA (2022), Rwandan Law No. 058/2021, and applicable international data protection standards.
- Lead and support Data Protection Impact Assessments (DPIAs) for new guest management systems, booking platforms, digital tools, loyalty programs, and high-risk data processing activities.
- Develop, implement, and enforce data protection policies, SOPs, and privacy guidelines tailored to hospitality operations such as guest check-ins, reservations, CCTV, payments, and marketing.
- Oversee data subject rights requests (DSARs) from guests, employees, and partners, ensuring timely, secure, and legally compliant responses.
- Serve as the primary liaison with ODPC, PDPC, NCSA, and other regulators, coordinating audits, inspections, and compliance submissions.
- Lead data breach incident response, assessing impact, notifying regulators and affected individuals, and driving corrective actions.
- Maintain and update Records of Processing Activities (ROPA) and data flow maps for all hotel systems, departments, and third-party service providers (e.g., PMS, POS, CRM, and booking engines).
- Deliver data privacy training and awareness programs to hotel staff, front-office teams, reservations, marketing, HR, and management to embed a strong culture of data protection.
Key Qualifications.
- Bachelor’s degree in Law, Information Security, Computer Science, or a related field; specialized training or a postgraduate qualification in Data Protection is an added advantage.
- Experience in data protection, compliance, information security, or regulatory roles, preferably within the hospitality, travel, or service industry.
- Strong understanding of regional data protection laws (Kenya DPA, Tanzanian PDPA, Rwandan Law No. 058/2021) and international frameworks such as GDPR and ISO 27701.
- Demonstrated experience conducting DPIAs, managing DSARs, and driving data privacy programs in operational environments.
- Knowledge of hospitality systems (PMS, POS, booking engines, CRM platforms) and data flows within hotel and guest service operations is highly desirable.
- Strong risk management, analytical, and documentation skills with the ability to interpret legal requirements into practical operational controls.
- Excellent communication, training, and stakeholder engagement skills, capable of working with multi-functional teams across different countries.
- Ensure all business units comply with the Kenya DPA (2019), Tanzanian PDPA (2022), Rwandan Law No. 058/2021, and applicable international data protection standards.
- Lead and support Data Protection Impact Assessments (DPIAs) for new guest management systems, booking platforms, digital tools, loyalty programs, and high-risk data processing activities.
- Develop, implement, and enforce data protection policies, SOPs, and privacy guidelines tailored to hospitality operations such as guest check-ins, reservations, CCTV, payments, and marketing.
- Oversee data subject rights requests (DSARs) from guests, employees, and partners, ensuring timely, secure, and legally compliant responses.
- Serve as the primary liaison with ODPC, PDPC, NCSA, and other regulators, coordinating audits, inspections, and compliance submissions.
- Lead data breach incident response, assessing impact, notifying regulators and affected individuals, and driving corrective actions.
- Maintain and update Records of Processing Activities (ROPA) and data flow maps for all hotel systems, departments, and third-party service providers (e.g., PMS, POS, CRM, and booking engines).
- Deliver data privacy training and awareness programs to hotel staff, front-office teams, reservations, marketing, HR, and management to embed a strong culture of data protection.
- Strong understanding of regional data protection laws (Kenya DPA, Tanzanian PDPA, Rwandan Law No. 058/2021) and international frameworks such as GDPR and ISO 27701.
- Demonstrated experience conducting DPIAs, managing DSARs, and driving data privacy programs in operational environments.
- Knowledge of hospitality systems (PMS, POS, booking engines, CRM platforms) and data flows within hotel and guest service operations is highly desirable.
- Strong risk management, analytical, and documentation skills with the ability to interpret legal requirements into practical operational controls.
- Excellent communication, training, and stakeholder engagement skills, capable of working with multi-functional teams across different countries.
- Bachelor’s degree in Law, Information Security, Computer Science, or a related field; specialized training or a postgraduate qualification in Data Protection is an added advantage.
- Experience in data protection, compliance, information security, or regulatory roles, preferably within the hospitality, travel, or service industry.
JOB-6938e428585ed
Vacancy title:
Group Data Protection Officer
[Type: FULL_TIME, Industry: Research, Category: Management, Computer & IT, Business Operations, Legal, Recruitment]
Jobs at:
Summit Recruitment and Search
Deadline of this Job:
Thursday, December 18 2025
Duty Station:
Nairobi | Nairobi | Kenya
Summary
Date Posted: Wednesday, December 10 2025, Base Salary: Not Disclosed
Similar Jobs in Kenya
Learn more about Summit Recruitment and Search
Summit Recruitment and Search jobs in Kenya
JOB DETAILS:
Our client, a leading organization in the hospitality industry with operations across East Africa, is seeking an experienced and highly competent Group Data Protection Officer (DPO) to oversee data privacy and compliance across its hotels, lodges, travel services, and regional corporate functions.
The DPO will ensure that all personal data relating to guests, employees, suppliers, and partners is processed in full compliance with regional data protection laws and international standards.
The ideal candidate is a compliance expert with excellent stakeholder management skills, and a proven ability to implement practical, organization-wide data protection frameworks.
Key Responsibilities
- Ensure all business units comply with the Kenya DPA (2019), Tanzanian PDPA (2022), Rwandan Law No. 058/2021, and applicable international data protection standards.
- Lead and support Data Protection Impact Assessments (DPIAs) for new guest management systems, booking platforms, digital tools, loyalty programs, and high-risk data processing activities.
- Develop, implement, and enforce data protection policies, SOPs, and privacy guidelines tailored to hospitality operations such as guest check-ins, reservations, CCTV, payments, and marketing.
- Oversee data subject rights requests (DSARs) from guests, employees, and partners, ensuring timely, secure, and legally compliant responses.
- Serve as the primary liaison with ODPC, PDPC, NCSA, and other regulators, coordinating audits, inspections, and compliance submissions.
- Lead data breach incident response, assessing impact, notifying regulators and affected individuals, and driving corrective actions.
- Maintain and update Records of Processing Activities (ROPA) and data flow maps for all hotel systems, departments, and third-party service providers (e.g., PMS, POS, CRM, and booking engines).
- Deliver data privacy training and awareness programs to hotel staff, front-office teams, reservations, marketing, HR, and management to embed a strong culture of data protection.
Key Qualifications.
- Bachelor’s degree in Law, Information Security, Computer Science, or a related field; specialized training or a postgraduate qualification in Data Protection is an added advantage.
- Experience in data protection, compliance, information security, or regulatory roles, preferably within the hospitality, travel, or service industry.
- Strong understanding of regional data protection laws (Kenya DPA, Tanzanian PDPA, Rwandan Law No. 058/2021) and international frameworks such as GDPR and ISO 27701.
- Demonstrated experience conducting DPIAs, managing DSARs, and driving data privacy programs in operational environments.
- Knowledge of hospitality systems (PMS, POS, booking engines, CRM platforms) and data flows within hotel and guest service operations is highly desirable.
- Strong risk management, analytical, and documentation skills with the ability to interpret legal requirements into practical operational controls.
- Excellent communication, training, and stakeholder engagement skills, capable of working with multi-functional teams across different countries.
Work Hours: 8
Experience in Months: 12
Level of Education: bachelor degree
Job application procedure
Are You Interested? Click Here To Apply
All Jobs | QUICK ALERT SUBSCRIPTION