Data Protection and Privacy Officer
UNHCRAbout the role
Hardship Level
H (no hardship)Family Type
FamilyFamily Type
FamilyResidential location (if applicable)
Grade
PR3Staff Member / Affiliate Type
ProfessionalReason
Regular > Regular AssignmentTarget Start Date
2025-10-01Deadline for Applications
August 8, 2025Standard Job Description
Data Protection and Privacy Officer
Organizational Setting and Work Relationships
UNHCR General Policy on Personal Data Protection and Privacy (GDPP) establishes a unified data protection and privacy framework for the Organization, and is applicable to processing of personal data of all categories of data subjects, including forcibly displaced and stateless persons, UNHCR workforce, partners, individual donors and others.
The Data Protection and Privacy Officer job is situated within UNHCR’s Data Protection Office reporting to the Chief Data Protection and Privacy Officer. The incumbent provides expert guidance, oversight, and support to UNHCR’s regional bureaux, country operations, and headquarters divisions on data protection standards and practices, including matters related to the collection, storage, access, and use of personal data.
The Data Protection and Privacy Officer provides timely and effective data protection advice to headquarters divisions and services, regional bureaux, country operations and key external partners, including people forced to flee and stateless persons. To achieve this, the incumbent will need to build and maintain effective partnerships with other sections and divisions within headquarters including the Legal Affairs Service (LAS) and the Chief Information Security Officer, as well as with UNHCR's regional bureaux and country operations. S/he may directly supervise staff in the professional and general service categories.
All UNHCR staff members are accountable to perform their duties as reflected in their job description. They do so within their delegated authorities, in line with the regulatory framework of UNHCR which includes the UN Charter, UN Staff Regulations and Rules, UNHCR Policies and Administrative Instructions as well as relevant accountability frameworks. In addition, staff members are required to discharge their responsibilities in a manner consistent with the core, functional, cross-functional and managerial competencies and UNHCR’s core values of professionalism, integrity and respect for diversity.
Duties
Guide and recommend actions to UNHCR's Personal Data Controllers and Data Protection Focal points in regional bureaux and country operations, and counterparts in states, partners and other relevant stakeholders, on a wide range of data protection issues, in accordance with UNHCR personal data protection and privacy framework.
Provide expert advice to country operations in monitoring the development of domestic data protection legal frameworks that may impact UNHCR operations and contribute to the development of situation- or country-specific guidance.
Advise and guide sections and divisions of headquarters on data protection requirements, in particular in the context of implementing enterprise systems (e.g. proGres, BIMS, etc.) and innovation projects with potential implications for the protection of data of people forced to flee and stateless persons.
Draft legal positions on data protection matters, in collaboration with Legal Affairs Service (LAS).
Develop advisories, formal opinions and interpretations on personal data protection and privacy to be adopted by Chief DPO.
Undertake expert review and clearance of data sharing arrangements.
Examine incidences of non-compliance with UNHCR’s personal data protection and privacy framework and relay these to the appropriate oversight mechanism(s).
Consolidate and promote best practices across UNHCR by sharing these examples in data protection groups, training fora.
Develop and provide training to UNHCR staff and partners on UNHCR's data protection frameworks, as well as its Operational Guidelines.
Maintain inventories of information provided by Data Controllers and Data Protection Focal Points, including Data Transfer Agreements, specific instances of data sharing with third parties, Data Protection Impact Assessments, data breach notifications, and complaints by data subjects.
Draft internal and external reports with concluding observations on the Organization’s compliance with its personal data protection and privacy framework.
Stay updated on data protection trends, laws, and industry standards.
Foster a positive and incl
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s