- Company Name
- H&M
- Job Title
- Regional Data Privacy Manager
- Job Description
-
**Job Title**
Regional Data Privacy Manager
**Role Summary**
Lead and manage privacy governance for the Americas region, ensuring compliance with local laws and alignment with global data privacy standards. Serve as the primary regional liaison for privacy matters across all brands and functions, overseeing policy development, risk management, training, and vendor oversight.
**Expectations**
- Own regional privacy strategy and execution across the Customer and Employee areas.
- Translate global privacy requirements into actionable regional policies and guidelines.
- Maintain up‑to‑date knowledge of regulatory developments in the United States, Canada, Mexico, Colombia, and Ecuador.
- Champion a risk‑based, pragmatic approach to privacy compliance.
**Key Responsibilities**
- Develop and enforce Regional Privacy Guidelines, encompassing privacy policy/notice, regulatory response, consent management, cookie/tracking compliance, and data subject rights.
- Lead privacy monitoring and testing across all brands and markets.
- Drive awareness, training, and cultural adoption of privacy principles regionally.
- Provide hands‑on consulting to business units on personal data use, future initiatives, and privacy‑by‑design integration.
- Manage regional privacy risk identification, assessment, and mitigation, including data retention and deletion policies.
- Report status, risks, and action plans to regional and global stakeholders, including the Group Data Protection Officer.
- Oversee third‑party vendor privacy compliance, contract safeguards, and ongoing monitoring.
- Direct regional data breach response strategy and coordination with global teams.
- Maintain relationships with local regulators and manage regulatory interactions.
**Required Skills**
- 4–5 years of experience as a Data Protection Officer (DPO) or Privacy Compliance Lead.
- Proven experience in privacy and security risk assessments, mitigation, and best‑practice implementation.
- Strong understanding of GDPR and local data protection legislation (US, Canada, Mexico, Colombia, Ecuador).
- Knowledge of information security standards (ISO/IEC 27001, NIST, etc.).
- Excellent stakeholder management, communication, and cross‑functional collaboration.
- Ability to translate global standards into regional guidelines and operate in a risk‑based framework.
- Proficient in developing and delivering training and awareness programs.
**Required Education & Certifications**
- Bachelor’s degree (preferred in law, information security, or related field).
- CIPP/US certification preferred.
- Relevant privacy certifications and information security standard certifications.