Data Protection Manager
Role Overview:
The Data Protection Manager is responsible for developing, implementing, and overseeing the company’s global data protection and privacy framework across all jurisdictions where the Group operates. This includes ensuring compliance with applicable data protection laws (including but not limited to GDPR, UK GDPR, local data privacy laws in Romania and the Philippines), managing data governance processes, handling data subject requests, and supporting business teams in maintaining compliance in all data processing activities — including partner data, employee data, and streaming-related personal data.
The role also extends to managing data and IP issues related to live casino streaming, including performer and participant rights, image and voice rights, and contractual compliance with third-party studios and technology partners.
Key Responsibilities:
- Develop, implement, and maintain the Group’s global data protection framework and policies in compliance with applicable laws (GDPR, UK GDPR, Data Privacy Act of the Philippines, etc.).
- Conduct privacy impact assessments (DPIAs) for new systems, products, or services
- Maintain records of processing activities (ROPAs) across all group entities.
- Oversee data transfer mechanisms between jurisdictions (e.g., SCCs, IDTAs, adequacy decisions).
- Monitor developments in data protection law and advise management on implications for the business.
- Manage and respond to data subject access requests (DSARs), complaints, and potential data breaches.
- Liaise with data protection authorities when necessary and manage regulatory notifications.
- Establish internal controls and processes to ensure ongoing compliance with data protection obligations.
- Conduct regular internal data protection audits and risk assessments across business units.
- Collaborate with the Technology and InfoSec departments to ensure appropriate technical and organizational measures (TOMs) are implemented.
- Maintain the Group’s data retention schedules and ensure secure data disposal practices.
- Provide oversight on vendor data protection due diligence and data processing agreements (DPAs).
- Act as the primary point of contact for data protection matters across departments (Legal, HR, Compliance, Marketing, Product, Technology, Operations).
- Support the product and technology teams in privacy-by-design implementation for new features or platform changes.
- Advise on compliance aspects of marketing, CRM, and analytics tools (e.g., tracking technologies, cookies, profiling).
- Oversee compliance for streaming and broadcast rights, ensuring all performer, dealer, and participant image, voice, and likeness rights are properly secured and documented.
- Maintain consent and release management systems for on-camera talent and other individuals appearing in live or recorded content.
- Work with production, HR, Legal and partner studios to ensure contracts cover data and IP aspects of live streaming and recorded material.
- Manage third-party rights clearance and ensure that use of visual and audio materials complies with IP, data protection, and contract terms.
- Advise on data protection implications of video storage, camera systems, and monitoring in live casino studios.
- Coordinate the data breach response process, including investigation, documentation, and notification.
- Maintain incident registers and report findings to the Legal and Compliance Director.
- Work with IT Security on mitigation strategies and root cause analysis.
- Maintain up-to-date documentation of all privacy policies, procedures, and risk assessments.
- Prepare periodic reports to the Legal & Compliance Director on data protection KPIs and incidents.
- Support internal and external audits related to privacy and compliance.
Qualifications & Skills:
- Bachelor’s degree in Law, Compliance, Information Security, or related field; legal qualification preferred.
- Minimum 5 years’ experience in data protection, ideally within the gaming, tech, or streaming/media sectors.
- In-depth knowledge of GDPR, UK GDPR, and other relevant privacy laws (Philippines, Romania, etc.).
- Experience handling cross-border data transfers and vendor risk management.
- Familiarity with IP rights, image/voice rights, and broadcast or streaming regulations.
- Strong stakeholder management and communication skills.
- Certification (e.g., CIPP/E, CIPM, or equivalent) preferred.
What’s in it for you?
- Experience a dynamic and team-orientated work environment.
- Opportunities for personal growth and learning.
- An open, inclusive and supportive team where you will be valued, and your suggestions will be welcome.
- 24 days paid holiday per year. This is in addition to local public holidays..
- Life Assurance (2x annual salary).
- Private Medical Insurance.
- Access to an in-house gym.
- €400 annual wellness allowance.
- Team Building Opportunities.
- Monthly lunch allowance.
- Parking (limited).
- Local discounts and more.
Our team is committed to keeping remuneration and benefits under constant review to make sure what we offer stays relevant.
- Department
- Malta Legal
- Locations
- Birkirkara
Already working at Eeze?
Let’s recruit together and find your next colleague.