Compliance Officer

Kempinski
Dubai
Workplace: OnsiteFull timeFunction: Legal, Risk & ComplianceExperience: 5+ yearsEducation: bachelorsSkills: ["Privacy by design","Ethical and legal integrity","Internal auditing","Risk assessment","Stakeholder advisory"]

Serve as the primary steward of guest and employee privacy across Kempinski’s luxury hotel portfolio. Develop and maintain privacy and data protection policies, ensure corporate privacy framework alignment, and maintain records of processing. Monitor GDPR compliance via audits and gap analyses, lead DPIAs, manage third-party privacy risk, and oversee DSAR and “Right to be Forgotten” handling. Lead breach response and remediation post-mortems, and deliver privacy-by-design training.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Kempinski
Kempinski
3 days ago

Compliance Officer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Serve as the primary steward of guest and employee privacy across Kempinski’s luxury hotel portfolio. Develop and maintain privacy and data protection policies, ensure corporate privacy framework alignment, and maintain records of processing. Monitor GDPR compliance via audits and gap analyses, lead DPIAs, manage third-party privacy risk, and oversee DSAR and “Right to be Forgotten” handling. Lead breach response and remediation post-mortems, and deliver privacy-by-design training.
Location: Dubai
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Draft, update, and implement data protection policies, standards, and procedures for hotels.
  • •Maintain Records of Processing Activities (ROPA) across corporate and property-level functions.
  • •Monitor GDPR compliance through regular gap analyses and internal audits; lead DPIAs.
  • •Evaluate third-party/vendor privacy posture and ensure Data Processing Agreements (DPAs) are in place.
  • •Oversee DSAR and “Right to be Forgotten” handling, and lead breach response and remediation post-mortems.

Pay and Benefits

Perks:Health InsurancePaid LeaveAnnual BonusHotel Discounts

Key Requirements

  • •Create, update, and implement data protection policies, standards, and procedures tailored to hospitality.
  • •Ensure local practices align with the corporate privacy framework and maintain Records of Processing Activities (ROPA).
  • •Monitor compliance with GDPR and other relevant privacy laws through gap analyses and internal audits.
  • •Lead and document Data Protection Impact Assessments (DPIAs) for new technologies, guest loyalty programs, and marketing initiatives.
  • •Oversee the legal handling of Data Subject Access Requests (DSARs) and “Right to be Forgotten” queries; lead breach response and remediation post-mortems.
Experience:5+ yearsHospitalityTravel sectorCorporate compliance
Education:Bachelor's in Law, IT, or Business Administration
Skills:Privacy by designEthical and legal integrityInternal auditingRisk assessmentStakeholder advisory
Certifications:CIPP/ECIPMCIPTIAPP
Languages:English

Company Brief

Kempinski
Kempinski is a luxury hotel management company operating five-star hotels, residences and restaurants worldwide. The group provides high-end hospitality services, managing properties and bespoke guest experiences across major cities and resort destinations.
Industry: Hotels & Resorts
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: Munich, Germany
Founded: 1862
Glassdoor
Glassdoor: 4.0
WebsiteLinkedInGlassdoor