DATA PROTECTION OFFICER
CIRCULAR NO. 2 OF 2026
Location: Gaborone, Botswana
About
Thuto SACCOS
Thuto SACCOS is a member-owned Savings and Credit Cooperative Society committed to delivering secure, innovative, and member-focused financial services. To strengthen its governance and regulatory compliance framework, the Society invites applications from suitably qualified and experienced individuals for the position of Data Protection Officer, on a 3-5 years fixed term contract.
Main
Purpose of the Position
Reporting to the Risk and Compliance Manager, the Data Protection Officer (DPO) is responsible for ensuring that the Society complies with the Data Protection Act and all applicable data protection and privacy regulations. The DPO will develop and oversee data protection policies, promote a culture of privacy, monitor compliance, and serve as the primary liaison with regulatory authorities on data protection matters.
Key Responsibilities
The successful candidate will be responsible for:
Regulatory Compliance
- -- Ensure the Society
complies with the Data Protection Act and other applicable privacy
legislation.
- -- Monitor developments
in data protection laws and recommend appropriate policy and procedural
changes.
- -- Serve as the primary
point of contact with regulatory and supervisory authorities on data
protection matters.
Data Privacy Management
- -- Develop, implement,
and maintain the Society's data protection policies, procedures, and
privacy framework.
- -- Conduct regular
compliance audits and reviews of data processing activities.
- -- Coordinate and oversee
Data Protection Impact Assessments (DPIAs) where required.
Risk Management
- -- Identify, assess, and
mitigate data privacy risks across the Society.
- -- Develop incident
response procedures for data breaches and oversee investigations and
reporting.
- -- Monitor the implementation of appropriate data security and privacy controls.
Training and Awareness
- -- Design and deliver
staff awareness programmes on data protection and privacy obligations.
- -- Promote a culture of
data privacy and compliance throughout the Society.
- -- Develop educational
materials and guidance for employees.
Data Subject Rights
- -- Manage requests
relating to access, correction, deletion, restriction, and other rights of
data subjects.
- -- Ensure all requests
and complaints are handled within statutory timelines and legal requirements.
Documentation and Record Management
- -- Maintain accurate
records of processing activities.
- -- Ensure data processing
agreements with third parties comply with applicable legal requirements.
- -- Prepare compliance
reports for Management and regulators.
Data Governance
- -- Collaborate with
Management and Information Technology teams to strengthen data governance
and information security.
- -- Ensure personal
information is processed securely and in accordance with approved policies
and legislation.
Regulatory Liaison
- -- Coordinate
communication with regulatory authorities regarding compliance matters and
breach notifications.
- -- Represent the Society
on matters relating to data protection compliance.
Qualifications
and Experience
Applicants should possess:
- -- A Bachelor's Degree in
Law, Information Technology, Business Administration, Information
Security, or a related field.
- -- A minimum of three
(3) years' experience in data protection, privacy, information
governance, compliance, or information security.
- -- Demonstrated knowledge
of the Data Protection Act and internationally recognised data
protection principles and best practices.
- -- Experience in
developing and implementing data protection policies and compliance
programmes.
- -- Strong analytical,
investigative, and problem-solving skills.
- -- Excellent
communication, report writing, and stakeholder engagement skills.
- -- High standards of
integrity, confidentiality, and professionalism.
- -- Experience within the financial services sector, particularly a
Savings and Credit Cooperative Society (SACCOS), banking, insurance, or
other regulated financial institution, will be an added advantage.
- -- Professional certification in Data Protection, Privacy, Information
Security, or Compliance (such as CIPP, CIPM, CDPSE, ISO 27001 Lead Implementer/Auditor,
or equivalent) will be an added advantage.
Key
Competencies
- -- Knowledge of Data Protection and Privacy Laws
- -- Compliance and Regulatory Management
- -- Risk Assessment
- -- Information Governance
- -- Policy Development and Implementation
- -- Analytical and Critical Thinking
- -- Communication and Influencing Skills
- -- Planning and Organising
- -- Confidentiality and Ethical Conduct
- -- Attention to Detail
Remuneration
An attractive and competitive remuneration package, commensurate with
qualifications and experience, will be offered to the successful candidate.
How to Apply
Interested candidates should submit:
- -- A detailed Curriculum Vitae;
- -- Certified copies of academic and professional qualifications;
- -- Certified copy of a valid identity document; and
- -- Names and contact details of three (3) professional referees.
Data Protection Notice
Thuto SACCOS collects and processes
applicants' personal information solely for recruitment and selection purposes
in accordance with the Data Protection Act, 2024. By submitting an application,
you consent to the processing of your personal data, including verification of
qualifications, employment history and references where necessary. Your
information will be accessed only by authorised personnel, kept secure, and
retained only for the period required by law or for legitimate recruitment
purposes. Applicants may exercise their rights under the Data Protection Act by
contacting Thuto SACCOS.
Applications should be addressed to:
The Chairperson
Management Board
Thuto SACCOS
PO BOX 45821,
RIVERWALK
GABORONE
OR EMAIL: recruitment@thutosaccos.co.bw
Only
shortlisted candidates will be contacted.
Closing date 31st July 2026
