Job description
Company culture :
Axa Services Maroc operates within a strongly collaborative culture, where people, trust, and high-quality professional relationships are central. The company promotes close and supportive management, encouraging accountability, development, and teamwork. This human-centered environment is reinforced by robust organizational practices that ensure reliability and operational efficiency. It is balanced by a performance-oriented mindset and a measured openness to innovation, supporting collective success.
Job :
Role and main mission:
Reporting to the Head of the Compliance, Internal Control, and Security Department, your main mission is to ensure the organization's compliance with current regulations (particularly GDPR) regarding personal data protection, and to manage risks related to the confidentiality and security of data.
Main responsibilities
1. Regulatory and strategic watch
Continuously monitor regulatory changes (GDPR, local laws, CNDP recommendations, etc.)
Support management on legal and strategic issues related to data protection
2. Data compliance and governance
Define, deploy, and maintain the personal data protection policy
Manage and update the register of processing activities
Implement and manage:
Consent management systems
Procedures for exercising data subject rights
Data breach management processes
Conduct impact assessments (DPIA) and support business projects
Lead structural topics: data mapping, cookies, Privacy by Design
Supervise data purging campaigns (structured and unstructured)
Manage the dedicated personal data mailbox
Handle requests for exercising rights and complaints
Ensure processing compliance and monitor declarations to the CNDP
3. Awareness and training
Design and deliver training and awareness sessions for employees
Promote a data protection culture within the organization
4. Incident management and audits
Supervise the management of incidents related to personal data (breaches, leaks)
Keep the incident register up to date
Lead or coordinate GDPR compliance audits
Define and monitor corrective action plans
5. Relations with control authorities
Be the preferred point of contact with the CNDP
Ensure mandatory declarations (incidents, files, reports)
Manage exchanges and controls with authorities
6. Advice and support
Support business units and data controllers in their projects
Integrate GDPR requirements from the design stage (Privacy by Design / by Default)
Required profile :
You have a Master's degree (Bac + 5) in a legal field (business law, digital law, personal data law), computer science (information system security), or a business school with a specialization in compliance or risk management.
Professional experience:
Minimum 2 to 3 years of experience in similar roles (lawyer specializing in personal data, compliance auditor, or GDPR consultant)
- In-depth knowledge of GDPR
- Knowledge of "Privacy by Design" and "Privacy by Default" methodologies
- Management of data processing mapping tools
- Information system security (ISS) principles
- Project management
الوصف الوظيفي
ثقافة الشركة :
تعمل Axa Services Maroc ضمن ثقافة تعاونية قوية، حيث تشكل العاطفة والتواصل والثقة والعلاقات المهنية العالية الجودة محور الاهتمام. تعزز الشركة الإدارة القريبة والداعمة، مما يشجع على المسؤولية والتطوير والعمل الجماعي. هذه البيئة المتركزة حول الإنسان تتعزز من خلال ممارسات تنظيمية قوية تضمن الموثوقية والكفاءة التشغيلية. وهي متوازنة مع عقلية موجهة نحو الأداء وانفتاح مدروس على الابتكار، مما يدعم النجاح الجماعي.
الوظيفة :
الدور والمهمة الرئيسية:
تحت سلطة رئيس قسم الامتثال والرقابة الداخلية والأمن، تتمثل مهمتك الرئيسية في ضمان امتثال المؤسسة للوائح المعمول بها (خاصة اللائحة العامة لحماية البيانات GDPR) المتعلقة بحماية البيانات الشخصية، وإدارة المخاطر المتعلقة بسرية البيانات وأمنها.
المسؤوليات الرئيسية
1. اليقظة التنظيمية والاستراتيجية
المتابعة المستمرة للتغييرات التنظيمية (GDPR، القوانين المحلية، توصيات اللجنة الوطنية CNDP، إلخ)
دعم الإدارة في القضايا القانونية والاستراتيجية المتعلقة بحماية البيانات
2. امتثال البيانات والحوكمة
تحديد ونشر وصيانة سياسة حماية البيانات الشخصية
إدارة وتحديث سجل أنشطة المعالجة
تنفيذ وإدارة:
أنظمة إدارة الموافقة
إجراءات ممارسة حقوق أصحاب البيانات
عمليات إدارة خرق البيانات
إجراء تقييمات الأثر (DPIA) ودعم مشاريع الأعمال
قيادة الموضوعات الهيكلية: رسم خرائط البيانات، ملفات تعريف الارتباط (cookies)، الخصوصية بالتصميم (Privacy by Design)
الإشراف على حملات تطهير البيانات (المهيكلة وغير المهيكلة)
إدارة صندوق البريد المخصص للبيانات الشخصية
معالجة طلبات ممارسة الحقوق والشكاوى
ضمان امتثال المعالجة ومتابعة التصريحات للجنة CNDP
3. التوعية والتدريب
تصميم وتقديم دورات تدريبية وجلسات توعية للموظفين
تعزيز ثقافة حماية البيانات داخل المؤسسة
4. إدارة الحوادث وعمليات التدقيق
الإشراف على إدارة الحوادث المتعلقة بالبيانات الشخصية (الانتهاكات، التسريبات)
الحفاظ على تحديث سجل الحوادث
قيادة أو تنسيق عمليات تدقيق الامتثال للائحة العامة لحماية البيانات GDPR
تحديد ومتابعة خطط العمل التصحيحية
5. العلاقات مع سلطات المراقبة
أن تكون نقطة الاتصال المفضلة مع اللجنة الوطنية CNDP
ضمان التصريحات الإلزامية (الحوادث، الملفات، التقارير)
إدارة التبادلات وعمليات المراقبة مع السلطات
6. الاستشارة والدعم
دعم وحدات الأعمال ومسؤولي معالجة البيانات في مشاريعهم
دمج متطلبات اللائحة العامة لحماية البيانات GDPR منذ مرحلة التصميم (Privacy by Design / by Default)
الملف الشخصي المطلوب :
أنت حاصل على درجة الماجستير (Bac + 5) في مجال قانوني (قانون الأعمال، القانون الرقمي، قانون البيانات الشخصية)، أو علوم الكمبيوتر (أمن نظم المعلومات)، أو من مدرسة تجارية مع التخصص في الامتثال أو إدارة المخاطر.
الخبرة المهنية:
خبرة لا تقل عن 2 إلى 3 سنوات في أدوار مماثلة (محامٍ متخصص في البيانات الشخصية، مدقق امتثال، أو مستشار GDPR)
- معرفة عميقة باللائحة العامة لحماية البيانات (GDPR)
- معرفة بمنهجيات "Privacy by Design" و"Privacy by Default"
- إدارة أدوات رسم خرائط معالجة البيانات
- مبادئ أمن نظم المعلومات (ISS)
- إدارة المشاريع