
Privacy Associate
- Cape Town, Western Cape
- Permanent
- Full-time
- Implementing and maintaining company-wide data protection policies and standard operating procedures to ensure compliance with global privacy laws and regulations.
- Providing clear and pragmatic privacy advice to teams working on new products, services and business processes.
- Support internal business stakeholders to perform data protection impact assessments on new and existing products, services and business processes to identify and mitigate risks to individuals.
- Collaborate with business stakeholders to maintain the record of processing activities and other compliance documentation such as privacy notices, transfer impact assessments and safeguards, legitimate interest assessments, consent forms, etc.
- Manage responses to data subject rights requests and complaints.
- Support the development and delivery of data protection training and play a key role in raising awareness of privacy and data protection within the company.
- Support the response to security incidents and personal data breaches, including assessing risk posed by incidents, providing advice to senior management and reporting to regulators.
- Perform privacy due diligence on vendors and third parties, including reviewing and providing advice on vendor terms of service, data processing agreements and data sharing agreements.
- Relevant experience (which can include articles of clerkship, but it is not compulsory) in privacy compliance in a legal, compliance or IT security role with a solid grounding in one or more data protection laws (such as the EU GDPR, South Africa's POPIA, Malaysia's PDPA, etc.).
- Strong academic credentials, preferably with a bachelor's degree in a relevant field such as law, information technology or cybersecurity. Articles beneficial but not essential for lawyers.
- Meaningful experience handling data subject rights requests, conducting data protection impact or similar risk assessments, managing security incidents and personal data breaches and reviewing vendor contracts.
- Experience advising on privacy aspects of new products, services, business partnerships and marketing initiatives (beneficial).
- Experience with privacy operations software such as OneTrust, Trustworks, etc. (beneficial).
- Knowledge of and experience working with data protection compliance frameworks.
- Excellent communication skills, analytical rigour, and high attention to detail.
- The ability to manage and deliver on multiple projects with competing deadlines.
- Sound business judgement, and a pragmatic approach, producing top quality, concise and practical privacy advice across a broad range of matters.
- Willingness and flexibility to learn and adapt in an exciting and evolving industry.
- The ability to think critically and creatively to solve complex problems, while protecting Luno from unacceptable risk.
- The ability to work across teams, functions and geographies, with high autonomy.
- Remote but reachable work policy gives you the freedom to choose between working from home or the office.
- Plus the option to buy and sell up to 5 days leave
- Improve body and mind, with excellent private medical insurance
- Access to Learnably and our additional learning platforms for your personal and professional development
- 6 months primary care-giver leave
- Paw-ternity leave for your furry friend
- Annual Inspiration Day in addition to your annual leave which increases based on your length of service!
- A collaborative, friendly work community, with regular social events and virtual cooking, dancing, drawing and house planting classes hosted by our Lunauts
- Free lunch and snacks
- 0 fees up to a certain amount with Luno from the day you start.*