Data Protection Officer (Level 8)
The Real Estate Board invites applications from suitably qualified individuals to fill the following post that is to be assigned to the upcoming Real Estate Authority of Jamaica (REAJ):
Data Protection Officer (Level 8)
Vacant Post – Three-year contract
Salary Range: $5,198,035 – $6,990,779 per annum
Job Summary
Reporting to the Chief Executive Officer, the Data Protection Officer (DPO) will be responsible for overseeing and monitoring the Real Estate Authority of Jamaica’s (REAJ) compliance with the provisions of the Data Protection Act (DPA). The DPO will lead compliance efforts across branches/units to ensure adherence to relevant policies and processes and the Real Estate Authority of Jamaica’s legal and regulatory obligations.
The DPO will provide specialist advice and support to the Authority’s senior management, work closely with key internal stakeholders such as Legal, MIS, HRM, Operations, Procurement and Marketing, and manage relationships with key external stakeholders.
Key Responsibilities
- Ensure that the Real Estate Authority of Jamaica processes personal data in compliance with the data protection standards, the Data Protection Act and good practice.
- Consult with the Office of the Information Commissioner to resolve any doubt about how the provisions of the Data Protection Act and any regulations made thereunder are to be applied.
- Ensure that any contravention of the data protection standards or any provisions of the Data Protection Act by the Real Estate Authority of Jamaica is dealt with in accordance with the provisions of the Data Protection Act.
- Notify the Real Estate Authority of Jamaica of any contravention of the data protection standards or any provisions of the Data Protection Act.
- Report any contravention of the data protection standards or any provisions of the Data Protection Act to the Office of the Information Commissioner.
- Assist data subjects in the exercise of their rights under the Data Protection Act in relation to the Real Estate Authority of Jamaica.
- Assist the Real Estate Authority of Jamaica with the development of internal policies and procedures related to the processing of personal data.
- Make recommendations for the appropriate organisational and technical measures to ensure the security of personal data.
- Act as the primary contact point for the Office of the Information Commissioner on issues relating to the processing of data and consult, where appropriate, regarding any other matter.
- Monitor changes to local privacy laws and make recommendations where necessary.
Required Competencies
Core
- Excellent interpersonal and stakeholder management skills
- Excellent communication skills
- Strong analytical and problem-solving skills
- Strong leadership skills
- Strong customer relations skills
- Excellent planning and organising skills
- Excellent judgement and decision-making skills
- Proficiency in the use of relevant computer applications
Technical
- Knowledge of existing local, regional and other relevant data protection laws, and the ability to draft policies and other agreements.
- Practical knowledge of IT systems, infrastructure and the relevant security measures needed for data protection and privacy.
- Knowledge of new technologies and potential risks they present to data security.
- High level of confidentiality in the execution of duties with the ability to act in an independent manner and free of any real or perceived conflicts of interest.
- Ability to work well under pressure and manage sensitive and confidential information.
Minimum Education & Experience
Qualifications:
- Undergraduate Degree in Information Security, Law, Computer Science, Information Technology, Data Privacy, or a related field.
- At least one (1) International Association of Privacy Professionals (IAPP) certification:
- Certified Information Privacy Professional (CIPP)
- Certified Information Privacy Manager (CIPM)
- Certified Information Privacy Technologist (CIPT)
OR
- At least one (1) ISACA certification in governance and risk management:
- Certified in Risk and Information Systems Control (CRISC)
- Certified in Governance of Enterprise IT (CGEIT)
- Certified Information Security Manager (CISM)
Relevant Experience:
- Three (3) to five (5) years’ work experience
in privacy, compliance, information security, auditing, or a relevant field (finance, law, business administration, information technology). - Sound knowledge of the Access to Information Act and anti-corruption laws.
- Experience in the following areas is an asset: Mapping and understanding business processes and data handling or processing needs in a relevant or related industry. Cybersecurity, including experience in managing security incidents, conducting risk assessments, implementing countermeasures and conducting data protection impact assessments.
Application & Deadline:
Applications accompanied by résumés should be submitted no later than Friday, September 11, 2026, via https://rebcsc.bamboohr.com/jobs.
We thank all applicants for their interest. However, only shortlisted candidates will be contacted.