Data Protection Officer — Hitachi Rail GTS Egypt LLC (ref HRE-LCC-PDPL-JD-001)
Why now: PDPL Law 151/2020 and Decree 816/2025 require a PDPC-accredited DPO. The grace period ends 1 November 2026, and the company has no DPO today. That makes this the largest open compliance gap in LCC Egypt, and the facial recognition positions on AQM, ART and CML1 depend on filling it.
The post: Full-time, permanent, based in Cairo. It reports to the LCC Country Head, with direct access to the Country Director and LCC Regional Head MEA. The DPO's statutory independence is protected, and no dual IT, HR or systems-owner role is allowed.
Core duties:
Act as PDPC point of contact and handle registration, licences and permits
Run the ROPA, DPIAs and data processing audit
Handle breaches (72-hour notification) and data subject requests
Manage cross-border transfer approvals, including high-risk systems
Draft data protection terms in contracts, subcontracts and bids
Deliver staff training and quarterly reporting
Requirements:
PDPC accreditation, or passing the exam within a set period (company-funded)
Degree in Law, IT, Computer Science, Information Systems or Engineering
7+ years in privacy, compliance or technology law, including 3+ years running a programme
Direct experience with Egyptian regulators
Fluent Arabic and professional English