Senior Analyst (Data Protection)
Malta Financial Services Authority View all jobs
- Birkirkara, Malta Island
- Permanent
- Full-time
- Maintain, review, and enhance the Authority's Records of Processing Activities;
- Monitor compliance with applicable data protection legislation, internal policies, and established data protection standards, and escalate risks, gaps, and recommendations to the Data Protection Officer;
- Provide informed advice and guidance to internal stakeholders on the interpretation and practical application of data protection laws;
- Advise on and monitor the conduct of Data Protection Impact Assessments (DPIAs), ensuring that high-risk processing activities are properly assessed and that identified mitigation measures are documented and followed up;
- Oversee and coordinate the handling of data subject rights requests (including access, rectification and erasure), ensuring compliance with statutory deadlines and procedural requirements;
- Review and advise on Data Processing Agreements (DPAs), data sharing arrangements, and other contractual instruments involving the processing or transfer of personal data, ensuring appropriate safeguards are incorporated;
- Provide guidance on the application of privacy by design and privacy by default principles in projects, systems, and operational processes involving personal data;
- Support and advise on personal data breach management, including breach assessment, documentation, coordination of containment measures, and preparation of notifications to the supervisory authority and/or affected data subjects where required;
- Serve as a point of contact for internal stakeholders on data protection;
- Contribute to the development and periodic review of data protection policies, procedures, training, and awareness initiatives to promote accountability and a strong data protection culture across the Authority;
- Undertake any other duties as assigned by the Data Protection Officer or Senior Management and/or as may be required by the MFSA from time to time based on the exigencies of the Authority.
Candidates without the necessary formal academic qualifications and minimum years' experience but with at least 10 years of substantial relevant experience will also be considered.Skills and competencies:
- Strong knowledge of data protection laws, GDPR requirements, and related regulatory frameworks.
- Knowledge of IT systems, data flows, and information security concepts, sufficient to assess technical and organisational risks during Data Protection Impact Assessments.
- Proven ability to provide independent advice and guidance on data protection matters, monitor compliance, and support data protection accountability.
- Analytical and detail-oriented, with the ability to assess risks, review processing activities, evaluate system designs, and interpret legal and regulatory requirements.
- Experience or aptitude in reviewing IT architectures, databases, cloud services, software applications, and data sharing arrangements in the context of impact assessments.
- Ability to communicate findings clearly to both technical and non-technical stakeholders, including project owners.
- High level of integrity, discretion, and professional judgment when handling sensitive personal data and confidential information.
- Competence in handling data subject rights requests, reviewing contractual agreements, and assisting with personal data breach management.
- Excellent report writing and presentation skills.