Main Purpose of the Position: Reporting to the Risk and Compliance Manager, the Data Protection Officer (DPO) is responsible for ensuring that the Society complies with the Data Protection Act and all applicable data protection and privacy regulations. The DPO will develop and oversee data protection policies, promote a culture of privacy, monitor compliance, and serve as the primary liaison with regulatory authorities on data protection matters.
Job Summary
- Type: full-time
- Location: Gaborone
- Category: Data Protection
- Closing Date: 2026-07-31
Key Responsibilities
- Regulatory Compliance: Ensure the Society complies with the Data Protection Act and other applicable privacy legislation; monitor developments in data protection laws and recommend appropriate policy and procedural changes; serve as the primary point of contact with regulatory and supervisory authorities on data protection matters.
- Data Privacy Management: Develop, implement and maintain the Society’s data protection policies, procedures and privacy framework; conduct regular compliance audits and reviews of data processing activities; coordinate and oversee Data Protection Impact Assessments (DPIAs) where required.
- Risk Management: Identify, assess and mitigate data privacy risks across the Society; develop incident response procedures for data breaches and oversee investigations and reporting; monitor implementation of appropriate data security and privacy controls.
- Training and Awareness: Design and deliver staff awareness programmes on data protection and privacy obligations; promote a culture of data privacy and compliance throughout the Society.
- Data Subject Rights: Manage requests relating to access, correction, deletion, restriction and other rights of data subjects; ensure all requests and complaints are handled within statutory timelines and legal requirements.
- Documentation and Record Management: Maintain accurate records of processing activities; ensure data processing agreements with third parties comply with applicable legal requirements; prepare compliance reports for Management and regulators.
- Data Governance: Collaborate with Management and Information Technology teams to strengthen data governance and information security.
Requirements
- A Bachelor’s Degree in Law, Information Technology, Business Administration, Information Security or a related field.
- A minimum of three (3) years’ experience in data protection, privacy, information governance, compliance or information security.
- Demonstrated knowledge of the Data Protection Act and internationally recognised data protection principles and best practices.
- Experience in developing and implementing data protection policies and compliance programmes.
- Strong analytical, investigative and problem-solving skills.
- Excellent communication, report writing and stakeholder engagement skills.
- High standards of integrity, confidentiality and professionalism.
- Experience within the financial services sector, particularly a Savings and Credit Cooperative Society (SACCOS), banking, insurance or other regulated financial institution, will be an added advantage.
- A professional certification such as CIPP, CIPM, CDPSE, ISO 27001 Lead Implementer/Auditor or equivalent will be an added advantage.
Salary
An attractive and competitive remuneration package, commensurate with qualifications and experience, will be offered to the successful candidate.
How to Apply
Vacancy Circular No: CIRCULAR NO. 2 OF 2026
About the Company
Thuto SACCOS Limited is a cooperative financial institution deeply rooted in Botswana, structured to serve its members. Operating as a member-owned entity, it delivers crucial financial services to support the economic well-being of its constituents. Eligibility for membership is specifically extended to employees working for the Government of Botswana and various Parastatals across the nation. This targeted approach ensures that Thuto SACCOS effectively caters to the distinct financial needs of Botswana's public sector workforce.
A cooperative financial institution for Botswana's public sector employees.
Website: https://www.thutosaccos.co.bw/
Frequently Asked Questions
What are the typical qualifications and certifications required for a Data Protection Officer (DPO) role in Botswana?
A Bachelor's degree in Law, IT, or a related field is often preferred, with relevant certifications like CIPP/E, CIPM, or CDPSE being highly advantageous. Employers in Botswana will also look for demonstrable experience with local data protection regulations, such as the Data Protection Act of 2018.
What are the common day-to-day responsibilities of a Data Protection Officer (DPO) in a SACCOS environment in Botswana?
You would typically advise on data protection compliance, conduct Data Protection Impact Assessments (DPIAs), and act as a point of contact for data subjects and regulatory authorities. This involves monitoring internal compliance, managing data breach responses, and ensuring all data processing activities align with Botswana's data protection laws.
What can I expect regarding local work culture and expectations for a DPO role in Botswana?
Botswana's work culture often values professionalism, respect, and collaborative problem-solving, with an emphasis on adherence to established procedures. As a DPO, you'll need strong communication skills to educate staff and stakeholders, fostering a culture of data protection awareness and compliance across the organization.
What are the realistic career progression paths for a Data Protection Officer (DPO) in Botswana?
A DPO can advance to senior compliance, risk management, or information security leadership roles within larger organizations or across different sectors. Specializing further in areas like cybersecurity, privacy law, or enterprise risk management also offers significant growth opportunities within the Batswana market.
What are the typical benefits packages offered for DPO roles in Botswana, particularly concerning leave, medical aid, and pension?
Employers in Botswana generally offer competitive benefits packages that include annual leave, sick leave, and maternity/paternity leave in line with the Employment Act. Most reputable organizations also provide medical aid schemes and contribute to pension funds to ensure employee well-being and future financial security.