Data Privacy Legal Officer
Lahore, Punjab, Pakistan
Full Time
Corporate Governance & Legal
Mid Level
About Us:
ACE Money Transfer is a UK-based multinational company headquartered in Manchester, United Kingdom. We provide secure online remittance services to customers in 29 countries across the UK, Europe, Canada, and Australia, enabling cross-border money transfers to 100+ countries worldwide.
About the role:
The Data Privacy Legal Officer provides operational legal and compliance support to the Data Privacy Expert and Manager, CGLA, covering the full scope of data protection obligations across the ACE Money Transfer Group. The role is responsible for first-line DSAR management, data protection contract drafting and review, DPIA and DTIA documentation support, breach first-response logging, RoPA maintenance, privacy notice upkeep, and regulatory filing support across the Group’s nine operating jurisdictions. The role sits within the Corporate Governance and Legal Affairs (CGLA) department and reports to the Manager CGLA.
Key Responsibilities
ACE Money Transfer is a UK-based multinational company headquartered in Manchester, United Kingdom. We provide secure online remittance services to customers in 29 countries across the UK, Europe, Canada, and Australia, enabling cross-border money transfers to 100+ countries worldwide.
About the role:
The Data Privacy Legal Officer provides operational legal and compliance support to the Data Privacy Expert and Manager, CGLA, covering the full scope of data protection obligations across the ACE Money Transfer Group. The role is responsible for first-line DSAR management, data protection contract drafting and review, DPIA and DTIA documentation support, breach first-response logging, RoPA maintenance, privacy notice upkeep, and regulatory filing support across the Group’s nine operating jurisdictions. The role sits within the Corporate Governance and Legal Affairs (CGLA) department and reports to the Manager CGLA.
Key Responsibilities
Contract drafting
- Draft, review, and support negotiation of Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), NDAs, Partnership Agreements, Commercial Agreements, and RAS (Remittance-as-a-Service) Agreements, ensuring data protection provisions are accurately embedded and aligned with UK GDPR, EU GDPR, and applicable international privacy frameworks.
- Support vendor, partner, and third-party contracting across the ACE Group, conducting first-line privacy due diligence on new and existing processors and sub-processors, completing data protection questionnaires, and flagging risks to the Data Privacy Expert for review and sign-off.
- Apply approved templates, standard clauses, and negotiation playbooks maintained by the Data Privacy Expert; escalate novel legal risks, complex cross-border transfer scenarios, or contractual disputes to the Data Privacy Expert or Manager, CGLA for guidance.
- Review and implement data protection provisions in contracts in line with UK GDPR, EU GDPR, and applicable international privacy laws, covering:
- Controller, joint controller, and processor role assessment and appropriate contractual framing
- Processor obligations, sub-processor authorisation, and confidentiality requirements
- Security, breach notification, cooperation, and audit rights clauses
- Cross-border data transfer safeguards including SCCs, adequacy decisions, and Article 49 derogations
- Data retention, deletion, purpose limitation, and data minimisation clauses
- Ensure consistency between DPAs, commercial agreements, SCCs, and ACE’s internal privacy framework, flagging any misalignments or gaps to the Data Privacy Expert.
- Maintain and manage data protection contracts within the CLM platform, including contract intake, tracking, approval workflows, renewal alerting, and archiving of executed copies; maintain the DP contract template library in collaboration with the Data Privacy Expert.
- Support internal audits, regulatory inspections, governance reviews, and supervisory authority requests by compiling and providing accurate contract records, DPA documentation, and data protection compliance evidence.
- Serve as first-line handler for all data subject rights requests (DSARs) — including access, rectification, erasure, restriction, objection, and portability — logging all requests, managing statutory timelines, coordinating information retrieval across relevant teams, and escalating complex or contentious requests to the Data Privacy Expert.
- Maintain the Group DSAR register, tracking volumes, outcomes, and timelines; prepare DSAR metrics for the Data Privacy Expert’s governance reporting to the Manager, CGLA and ExCo.
- Provide first-line support in data breach response: log reported incidents in the Group breach register, complete initial impact assessments, and escalate to the Data Privacy Expert for regulatory notification decisions; maintain records of all incidents and responses.
- Assist the Data Privacy Expert in maintaining and updating the Group’s Records of Processing Activities (RoPAs) across all entities, ensuring records reflect current processing activities, data flows, legal bases, and retention periods.
- Draft and maintain data inventory documentation, data flow maps, and processing activity descriptions across ACE Group entities and jurisdictions, as directed by the Data Privacy Expert.
- Maintain and renew registrations and notifications with data protection supervisory authorities across applicable jurisdictions, monitoring renewal dates and ensuring timely submission.
- Support preparation of documentation required for regulatory inspections, supervisory authority enquiries, internal audits, and governance reviews, ensuring materials are accurate and produced within required timelines.
- Support the Data Privacy Expert in developing and delivering internal data protection training materials and awareness communications across the Group, including tailoring content for specific departments and jurisdictions.
- Maintain the Group’s DP policy register, tracking policy status, review cycles, ownership, and approval records; coordinate policy update and re-approval processes as directed.
- Provide general administrative and coordination support to the Data Privacy Expert and Manager, CGLA on departmental data protection matters, including preparation of presentations, reports, and compliance dashboards.
ACE Money Transfer Profile: https://acemoneytransfer.com/company-profile
Apply for this position
Required*