Job Summary
- Employer: National Development Bank
- Job Type: Full-time
- Location: Gaborone, Botswana
- Category: Risk & Compliance
- Closing Date: 2026-09-25
Key Responsibilities
- Serve as the Bank’s designated Data Protection Officer and lead the Data Protection & Privacy Management Framework.
- Develop privacy policies, standards, procedures, consent practices and the Record of Processing Activities (ROPA).
- Coordinate Data Protection Impact Assessments for new products, systems, projects and initiatives.
- Monitor privacy compliance, conduct audits and lead investigations relating to incidents and breaches.
- Embed privacy-by-design principles into products, systems and business initiatives.
- Promote responsible data use, data ethics, ESG-aligned governance and privacy awareness across the Bank.
Requirements
- Bachelor’s degree in Law, Information Technology, Information Governance, Risk Management or a related discipline.
- Minimum 7 years’ experience in Data Protection, Information Governance, Compliance, Privacy Risk Management, Information Security and Regulatory Compliance.
- Experience in financial services, banking, fintech or another highly regulated environment.
- Expertise in breach management, regulatory engagement, compliance audits, privacy risk assessments and data governance frameworks.
- Experience supporting ESG reporting, data ethics or AI governance will be an added advantage.
- The following will be an added advantage: CIPP, CIPM, CDPSE, ISO 27001 Lead Implementer or relevant Information Security, Governance or Risk certifications.
How to Apply
About the Company
The National Development Bank (NDB) is a parastatal financial institution in Botswana, wholly owned by the Government of Botswana. Established by an Act of Parliament in 1963, NDB's core mandate is to promote economic development and diversification within the country. It provides a comprehensive range of financial products and services, including agricultural finance for crops and livestock, commercial loans, property finance, and dedicated schemes for Small and Medium Enterprises (SMEs) and young farmers. NDB plays a crucial role in supporting key economic sectors and fostering sustainable growth across Botswana, empowering individuals and businesses to contribute to the nation's prosperity.
Your Partner in Development
Website: https://www.ndb.bw/
Frequently Asked Questions
What qualifications or certifications are typically required for a Data Protection & Privacy Manager role in Botswana?
Usually a bachelor's degree in law, information technology, business administration, or a related field is expected, with many employers preferring a postgraduate qualification in data protection, privacy law, or cybersecurity. Certifications such as CIPP/E, CIPM, ISO 27001 Lead Implementer, or ISACA's CISM/CISA are highly regarded and often required for senior compliance positions.
What are the common day-to-day responsibilities of a Data Protection & Privacy Manager at a financial institution like the National Development Bank?
The role involves developing and implementing privacy policies, conducting risk assessments, and ensuring compliance with Botswana's Data Protection Act and international standards such as GDPR where applicable. Daily tasks include monitoring data processing activities, providing training to staff, handling data subject requests, and liaising with internal audit and IT security teams to mitigate privacy risks.
How does the local work culture in Botswana influence expectations for this role?
Botswana's professional environment values punctuality, respect for hierarchy, and collaborative problem‑solving, so a Data Protection & Privacy Manager is expected to communicate clearly with senior management and work closely with cross‑functional teams. Demonstrating integrity, confidentiality, and a proactive approach to regulatory changes is essential to gain trust and effectiveness in the position.
What realistic career progression or growth paths can someone expect after starting as a Data Protection & Privacy Manager?
With experience, professionals can advance to senior roles such as Head of Privacy, Chief Privacy Officer, or Director of Risk & Compliance, often overseeing broader governance frameworks. Additional opportunities include moving into specialized consultancy, data governance leadership, or regional roles that cover multiple African jurisdictions, especially as cross‑border data flows increase.
What typical benefits are offered for full‑time positions in this category in Botswana, and how should a candidate prepare their application?
Employers commonly provide medical aid contributions, pension or provident fund schemes, paid annual leave (usually 20‑25 days), sick leave, and sometimes study assistance or professional development allowances. When applying, tailor your CV to highlight relevant privacy law knowledge, certifications, and experience with risk assessments, and include a cover letter that shows understanding of Botswana's Data Protection Act and the specific needs of the financial sector.