Manager, Data Privacy
Harley-Davidson Motor Company · Milwaukee, WI · Today
Consulting$130k–$208k/yrFull-time
About the role
The Manager of Harley-Davidson, Inc’s Data Privacy reports to the Data Privacy Officer and leads Harley-Davidson’s global data privacy office. These functions help monitor and oversee privacy compliance in key business areas and reduce privacy, end-user, and reputational risk to our Brands related to how we handle Privacy Restricted information we hold on our employees, customers, and dealers. The team is responsible for building and enhancing workforce knowledge to ensure proper security and privacy measures exist and processes are followed when handling Privacy Restricted information throughout the data lifecycle.
Responsibilities
- Partner with the Data Privacy Officer to build the HDI Data Privacy strategy and framework, based on industry-recognized standards, to align operational work, business assessment activities, compliance gaps, and privacy risk mitigation efforts.
- Translate US domestic and International Legal guidance and regulatory requirements into policies, standards, and control expectations, ensuring clear articulation of compliance requirements for first-line teams.
- Provide oversight and maintain existing governance frameworks and standards for core privacy program areas, including:
- Data subject rights (DSAR) processes and Service Level Agreements (SLA)
- Data protection impact assessment (PIA) governance and documentation standards
- Consent and preference management expectations
- Data retention and deletion requirements
- Work with functional business leaders to conduct PIAs on key business processes involving privacy-regulated data we collect and hold on employees, customers, and dealers; assess privacy risk and prioritize gaps; provide senior business leaders with privacy risk reports and recommendations for remediation; develop a global Privacy Breach Notification Process that meets all privacy regulatory requirements/restrictions.
- Build and maintain strong business partnerships across key areas at a senior leadership level, bridging their understanding of data privacy concepts and requirements with an understanding of regional and global business practices.
- Manage and facilitate a secured process for all HR/Legal/Ethics Privacy-related Investigations.
- Manage and maintain our customer-facing Privacy Notice, Consent Language, and Cookie Usage Policy.
- Ensure all employee, customer, and regulatory inquiries and complaints are addressed in a compliant and timely manner.
- Drive a dynamic and multi-faceted global Data Privacy Awareness Training program for employees and contractors to heighten awareness and reduce security/privacy risk due to human error; drive campaigns to test business behavior and track end-user knowledge to drive ongoing program content and effectiveness.
Education Requirements
- High School Diploma or Equivalent Required
- Bachelor's Degree in business management, information systems, or a related discipline
- CIPP/US certification
- Master's Degree in related field is Preferred
- CIPP/EU or CIPM certification is Preferred
Experience Requirements
- Typically requires a minimum of 8 years of related experience.
- 8+ years of relevant professional experience directly related to data privacy, audit and compliance, or information security.
- Demonstrated experience working in an enterprise-level Data Privacy Office with global accountabilities.
- Direct experience leading Privacy Impact Assessments with business leaders and managers.
- Possess comprehensive knowledge and understanding of the primary data privacy principles and key industry-leading regulations such as:
- California Consumer Privacy Act (CCPA)
- European General Data Protection Regulation (GDPR)
- Proven ability to address privacy issues, incidents and inquiries from data subjects and to respond to them with a high degree of certainty and comprehension.
- Ability to define and establish comprehensive procedures that integrate with key business processes to ensure privacy standards and best practices are part of privacy compliance by design.
- Excellent communication and presentation skills with demonstrated skill in presenting complex detail around regulations clearly and to a variety of audience members.
- Proven ability to develop frameworks, strategies and roadmaps and to provide direction across all areas of accountability as well as to work closely with the Corporate Information Security Office (CISO) organization where dependencies exist.
- Strong leadership, organization, communication, and process management skills; ability to lead and manage high performing teams, and an ability to develop a continuous improvement mentality in all operational activities.
Preferred Experience
- Experience in building and leading a team with a proven ability in developing capabilities, attracting and retaining a core team of collaborative professionals and creating an organization viewed as a highly attractive place to work.
- Experience in delivering privacy awareness presentations or training modules/content for a global audience.
Benefits
- Annual bonus programs
- Health insurance benefits
- 401k program
- Onsite fitness centers and employee stores
- Employee discounts on products and accessories