The BIHL Group exists to improve livelihoods for and with Batswana. This is the purpose that guides us, and the compass that all our businesses work by. We are looking for a new member of the team, a Group Data Protection Officer, to help ensure our compass is perfectly calibrated
Role Description
Provide overall assurance to the BIHL Group and Audit & Risk Committee of BIHL and subsidiaries on matters that relate to the Data Protection Act of Botswana and BIHL Group Data Protection standards in line with international best practice. The Data Protection Officer (DPO) is responsible for ensuring that the BIHL Group an subsidiaries processes the personal data of its staff, customers, providers, or any other individuals in compliance with applicable data protection laws (e.g., GDPR, Botswana Data Protection Act). The DPO acts as the key point of contact for the Data Protection Commission, other regulatory bodies and individuals whose data is processed.
Role Responsibilities
Compliance Monitoring
- Monitor internal compliance with data protection laws and policies.
- Conduct regular audits to ensure adherence to applicable legislation an follow up and closure of issues.
Advisory Role
- Provide expert advice and guidance to BIHL Management and staff on data protection obligations.
- Inform and advise BIHL of its obligations under data protection laws.
- Advise intermediaries of BIHL on data protection laws an ensure compliance through a compliance program.
- Develops, implements and maintains effective data protection governance structures, processes, procedures and internal control mechanisms for BIHL to ensure good data protection compliance management.
- Develop and manage policies and objectives of data protection management to promote an ethical and professional environment for the business and its partners.
- Report and present quarterly updates to Management and Board Committees as required to provide assurance on Internal Compliance.
Training and Awareness
- Develop and deliver data protection training and awareness programs.
- Promote a culture of data privacy within the organization.
Incident Management
- Lead or support investigations of data breaches and ensure timely reporting to authorities.
- Develop and implement data breach response procedures.
- Liaise and present business proposals relating to data protection with the Data Protection Commissioner and institute escalation measures as necessary.
Qualifications & Experience
- Minimum of Bachelor’s degree in Law, Information Security, IT, or related field.
Certifications (advantage): CIPP/E, CIPM, GDPR Practitioner, or equivalent. - A minimum of 3 years of experience in data protection, compliance, IT security, or legal advisory.
- Strong understanding of GDPR, Data Protection Act of Botswana and industry best practices.
- A good understanding of the insurance industry, regulatory environment and relevant legislative framework would be an advantage.
- A good understanding of business operations, processes, and procedures.
Competencies
- Excellent communication and interpersonal skills.
- Strong analytical and problem-solving abilities.
- Demonstrate sound knowledge of financial services laws.
- High ethical standards and attention to detail.
- Ability to manage confidential information with discretion.
- Ability to make confident informed decisions on behalf of the company.
Closing date: 14 July 2025