This role is responsible for designing and implementing privacy and compliance-related policies, controls, and processes. The Privacy and Compliance Program Manager will work with the BAL Information Security and Privacy Council (ISPC) to modify or develop policies and processes, and manage all applicable privacy activities and processes associated with ongoing maintenance and care of privacy compliance requirements such as EU-US DPF, GDPR, etc. The position involves facilitating project scope, goals, and deliverables, communicating with internal and external clients regarding privacy program actions (including breach processes), and advising on various privacy topics like incident response, leading privacy controls, and data subject access requests. The role also requires identifying, assessing, and communicating key privacy risks, monitoring and reporting on privacy program initiatives to the Senior Manager of Enterprise Security & Privacy, and leading Data Privacy Impact Assessments (DPIA) to minimize data protection risks. Additionally, the manager will monitor and document regulatory changes, support the third-party risk management program, assist with privacy audits and compliance checks, participate in contract reviews for privacy terms, supervise internal audits for ISO 27001 and 27701 compliance, lead critical ISO compliance activities, and own the Data Governance program, including updates to data maps and policy compliance. The role also includes serving as the administrator and subject matter expert for the OneTrust tool.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Manager