Job Summary
- Type: contract
- Location: Gaborone
- Category: Legal/Compliance
- Closing Date: 2026-07-31
Key Responsibilities
- Reporting to the Risk and Compliance Manager, the Data Protection Officer (DPO) is responsible for ensuring that the Society complies with the Data Protection Act and all applicable data protection and privacy regulations. The DPO will develop and oversee data protection policies, promote a culture of privacy, monitor compliance, and serve as the primary liaison with regulatory authorities on data protection matters.
- **REGULATORY COMPLIANCE**
- Ensure the Society complies with the Data Protection Act and other applicable privacy legislation.
- Monitor developments in data protection laws and recommend appropriate policy and procedural changes.
- Serve as the primary point of contact with regulatory and supervisory authorities on data protection matters.
- **DATA PRIVACY MANAGEMENT**
- Develop, implement, and maintain the Society’s data protection policies, procedures, and privacy framework.
- Conduct regular compliance audits and reviews of data processing activities.
- Coordinate and oversee Data Protection Impact Assessments (DPIAs) where required.
- **RISK MANAGEMENT**
- Identify, assess, and mitigate data privacy risks across the Society.
- Develop incident response procedures for data breaches and oversee investigations and reporting.
- Monitor the implementation of appropriate data security and privacy controls.
- **TRAINING AND AWARENESS**
- Design and deliver staff awareness programmes on data protection and privacy obligations.
- Promote a culture of data privacy and compliance throughout the Society.
- Develop educational materials and guidance for employees.
- **DATA SUBJECT RIGHTS**
- Manage requests relating to access, correction, deletion, restriction, and other rights of data subjects.
- Ensure all requests and complaints are handled within statutory timelines and legal requirements.
- **DOCUMENTATION AND RECORD MANAGEMENT**
- Maintain accurate records of processing activities.
- Ensure data processing agreements with third parties comply with applicable legal requirements.
- Prepare compliance reports for Management and regulators.
- **DATA GOVERNANCE**
- Collaborate with Management and Information Technology teams to strengthen data governance and information security.
- Ensure personal information is processed securely and in accordance with approved policies and legislation.
- Regulatory Liaison
- Coordinate communication with regulatory authorities regarding compliance matters and breach notifications.
- Represent the Society on matters relating to data protection compliance.
Requirements
- A Bachelor’s Degree in Law, Information Technology, Business Administration, Information Security, or a related field.
- A minimum of three (3) years’ experience in data protection, privacy, information governance, compliance, or information security.
- Demonstrated knowledge of the Data Protection Act and internationally recognised data protection principles and best practices.
- Experience in developing and implementing data protection policies and compliance programmes.
- Strong analytical, investigative, and problem-solving skills.
- Excellent communication, report writing, and stakeholder engagement skills.
- High standards of integrity, confidentiality, and professionalism.
- Experience within the financial services sector, particularly a Savings and Credit Cooperative Society (SACCOS), banking, insurance, or other regulated financial institution, will be an added advantage.
- Professional certification in Data Protection, Privacy, Information Security, or Compliance (such as CIPM, CIPP, CDPSE, ISO 27001 Lead Implementer/ Auditor, or equivalent) will be an added advantage.
- **KEY COMPETENCIES**
- Knowledge of Data Protection and Privacy Laws
- Compliance and Regulatory Management
- Risk Assessment
- Information Governance
- Policy Development and Implementation
- Analytical and Critical Thinking
- Communication and Influencing Skills
- Planning and Organising
- Confidentiality and Ethical Conduct
- Attention to Detail
Salary
Attractive and competitive remuneration package
How to Apply
Address: The Chairperson, Management Board, THUTO SACCOS, PO BOX 45821, RIVERWALK, GABORONE
Vacancy Circular No: 2 OF 2026
About the Company
Thuto SACCOS Limited is a cooperative financial institution deeply rooted in Botswana, structured to serve its members. Operating as a member-owned entity, it delivers crucial financial services to support the economic well-being of its constituents. Eligibility for membership is specifically extended to employees working for the Government of Botswana and various Parastatals across the nation. This targeted approach ensures that Thuto SACCOS effectively caters to the distinct financial needs of Botswana's public sector workforce.
A cooperative financial institution for Botswana's public sector employees.
Website: https://www.thutosaccos.co.bw/
Frequently Asked Questions
What are the typical qualifications, certifications, or education needed for a Data Protection Officer role in Botswana?
Candidates usually require a degree in Law, IT, Information Security, or Business Administration, often coupled with relevant experience in legal, compliance, or information security fields. Professional certifications like CIPP/E, CIPM, or relevant IT security certifications are highly valued as they demonstrate specialized knowledge. A strong understanding of the Data Protection Act 2018 of Botswana is crucial.
What are the common day-to-day responsibilities of a Data Protection Officer in a financial institution like a Saccos in Botswana?
Day-to-day tasks involve advising management on data protection compliance, conducting data protection impact assessments, and handling data subject access requests. You would also monitor internal compliance, manage data breach incidents, and provide training to staff on data protection best practices. Ensuring adherence to the Botswana Data Protection Act 2018 and other relevant regulations is a core duty.
How does the local work culture and regulatory environment in Botswana typically influence the Data Protection Officer role?
The DPO in Botswana operates within a culture that emphasizes compliance and good governance, especially following the introduction of the Data Protection Act 2018. There's an expectation for proactive engagement with local regulatory bodies and a need to adapt global best practices to the specific local context and resource availability. Building strong internal relationships and providing clear, practical guidance for local staff is vital.
What are the realistic career progression or growth paths for a Data Protection Officer in Botswana?
A DPO can advance into broader compliance management, risk management, or information security leadership roles within larger organizations. Opportunities may also arise in consulting firms specializing in data privacy, or even in regulatory bodies or government departments focused on data protection. Continuous professional development and staying updated with evolving privacy laws are key to career growth.
What typical benefits can a Data Protection Officer expect in Botswana, such as leave, medical aid, or pension?
Most reputable employers in Botswana offer a standard benefits package including annual leave, sick leave, and often a provident fund or pension scheme. Medical aid contributions are also common, though the extent of coverage can vary between employers. Some organizations might also provide professional development allowances or bonuses based on performance.
How should a job seeker in Botswana best apply for a DPO role, and what do employers typically look for?
Employers in Botswana look for candidates with a demonstrable understanding of the local Data Protection Act and practical experience in implementing compliance frameworks. Highlight your analytical skills, attention to detail, and ability to communicate complex legal requirements clearly in your CV and cover letter. Tailor your application to showcase your relevant experience in privacy, legal, or IT security roles, emphasizing any certifications.