
ACE Data Privacy/Data Protection Officer
- Uxbridge, Greater London
- Permanent
- Full-time
- Lead the Company’s privacy programs for ACE to strategically manage potential privacy risks and develop appropriate privacy controls to support business initiatives and use of emerging technologies to ensure compliance with the General Data Protection Regulation (GDPR) and related data protection and privacy matters in accordance with laws and regulations in force in all ACE markets in which Gilead operates.
- Serve as a resource to ACE country counsel for privacy-related issues and escalations and help maintain a harmonized, global approach to issues.
- Manage appropriate privacy and confidentiality consents, authorization forms and information notices and materials.
- Work with IT Security to manage procedures for vetting and auditing vendors for compliance with the privacy and data security policies and legal requirements.
- Manage the process for addressing complaints and requests from data subjects with respect to the enforcement of their rights under applicable laws.
- Provide advice on Data Protection Impact Assessments (DPIAs)
- Manage the relationship with the appropriate regulating bodies to ensure that programs, policies and procedures are consistent with law and regulations.
- Serve as registered Data Protection Officer for purposes of GDPR and other similar legal compliance requirements.
- Evaluate and improve upon process for receiving, documenting, investigating and reporting unauthorized access or disclosure of protected information.
- Manage breach response, including notification to data subjects, law enforcement and regulators as needed.
- Continue to implement, maintain and improve corporate privacy policies, procedures, and infrastructure.
- Develop and deliver privacy training materials and other communications to increase employee understanding of company privacy policies, data handling practices and procedures and legal obligations.
- Work with business teams and senior management to increase awareness of “best practices” on privacy and data security issues.
- Serve as information privacy resource to the organization regarding release of information and to all departments for all privacy related issues.
- Professional with strong privacy experience; experience in a life sciences industry preferred.
- Qualified solicitor preferred.
- CIPP certification (or equivalent) preferred.
- Knowledge of European privacy laws regulations and best practices.
- Proven track record of project and process development, implementation and project management.
- Results oriented, proactive, responsible and pragmatic with a passion to solve complex problems in creative, efficient and cost-effective way and to translate global compliance environments into actionable policies, processes and programs that enable business objectives.
- Proven track record of getting things done in complex organizational context, often without formal authority in a highly matrixed environment.
- Strong knowledge and interest in emerging technologies.
- Excellent communication skills and outstanding interpersonal skills.
- Ability to work independently and demonstrated experience prioritizing conflicting demands from multiple business clients in an extremely fast-paced environment.
- Strong people management skills
- Self-starter with a high level of initiative and strong work ethic.