Data Protection Officer - Yubi MENA
Yubi MENA · Dubai, Dubai, United Arab Emirates
Apply & track with Apply EdgeData Protection Officer — Yubi MENALocation: Dubai, UAE (Regional coverage)Reports to: Group CISO, Yubi Group, with direct access to Yubi MENA senior management and relevant Board/Board committee forums on data protection matters. The DPO shall operate independently in the performance of statutory DPO responsibilities and shall have appropriate access to information, resources and management necessary to fulfil those responsibilities.Role Context The Data Protection Officer (DPO) is accountable for Yubi MENA's data protection and privacy programme across its debt marketplace, lending, and financial services platforms. The role holder will serve as Yubi MENA's regional Data Protection Officer, including fulfilling statutory DPO obligations where required under applicable UAE, DIFC, ADGM, KSA and other MENA data protection regimes., and other applicable data protection regimes across the jurisdictions in which Yubi MENA operates (including ADGM and Saudi Arabia's PDPL, where relevant). Given the sensitivity of the financial, credit, and KYC data Yubi processes on behalf of borrowers, lenders, and institutional clients, this role is central to maintaining regulatory trust, platform integrity, and customer confidence. Determines and advises on Yubi's role as Controller, Processor, Joint Controller or Sub-processor for material processing activities, and ensures appropriate contractual, governance and accountability arrangements are established. The Data Protection Officer (DPO) is a senior compliance role accountable for Yubi MENA's data protection and privacy programme across its debt marketplace, lending, and financial services platforms. The role holder will serve as Yubi MENA's Regional Data Protection Officer, including fulfilling statutory DPO obligations where required under applicable UAE, DIFC, ADGM, KSA and other MENA data protection regimes. Given the sensitivity of the financial, credit, and KYC data Yubi processes on behalf of borrowers, lenders, and institutional clients, this role is central to maintaining regulatory trust, platform integrity, and customer confidence. The DPO determines and advises on Yubi's role as Controller, Processor, Joint Controller or Sub-processor for material processing activities, and ensures appropriate contractual, governance and accountability arrangements are established. The DPO provides expert privacy advice to the MENA leadership team, Legal & Compliance, Technology, and business units, and acts as the primary liaison with regional data protection authorities.Key AccountabilitiesStrategic ContributionDevelops and drives Yubi MENA's data protection strategy, aligned to regional regulatory requirements (UAE PDPL, DIFC Law, ADGM, KSA PDPL) and Yubi's growth plans across the debt and credit marketplace.Builds a privacy framework that scales with Yubi's expansion into new products (lending, supply chain finance, co-lending) and new GCC markets.Promotes a culture of privacy-by-design across product, engineering, credit, and operations teams.Establishes and operates privacy-by-design and privacy-by-default review gates within the product development lifecycle for new products, material feature changes, new processing purposes, data integrations and high-risk use cases. Advises leadership on privacy risk exposure tied to sensitive financial and credit data.Maintains a regional privacy risk register and establishes measurable privacy KRIs/KPIs covering regulatory compliance, DPIA coverage, data-subject rights performance, incidents, retention exceptions, third-party privacy risk, cross-border transfer exposure and remediation status. Leadership & Regulatory EngagementServes as the primary point of contact for the UAE's Data Office, DIFC Commissioner of Data Protection, and other applicable regulators, as well as for data subjects (borrowers, lenders, guarantors). Serves as the primary point of contact for applicable data protection authorities, including the UAE Data Office, DIFC Commissioner of Data Protection and relevant ADGM/KSA authorities, as applicable, and acts as an escalation point for data protection matters involving borrowers, lenders, guarantors and other data subjects. Leads breach and incident response, coordinating with Technology, Risk, and Legal, and reporting to leadership within statutory notification windows. Provides privacy regulatory oversight during personal-data incidents, coordinating with Technology, Security, Risk and Legal on assessment, notification thresholds, regulatory notifications, data-subject communications and remediation within applicable statutory timelines. Acts as an escalation point for privacy complaints and complex data subject requests.Coordinates with counterparts in Yubi's India/global privacy function to ensure consistent group-wide standards while respecting local regulatory nuance.Privacy ProgrammeDefines and oversees data retention, archival, deletion and anonymisation requirements, ensuring alignment between legal and regulatory retention obligations, contractual requirements and Yubi data lifecycle controls across production systems, backups, analytics platforms and third parties. Develops, implements, and maintains data protection policies, procedures and standards specific to Yubi MENA's lending and credit operations, including controller/processor governance, privacy-by-design, data lifecycle management and accountability requirements. Maintains Records of Processing Activities (RoPA), data flow maps, data inventories and processing-role assessments covering borrower/lender KYC, credit bureau data, financial and transaction data, analytics and other material personal-data processing activities. Conducts and oversees Data Protection Impact Assessments (DPIAs) for new products, material product changes, credit-scoring and AI/ML models, profiling, high-risk processing and third-party integrations. Reviews and advises on data protection clauses in vendor, lender, platform partner and data-sharing agreements — including controller-to-controller, controller-to-processor and sub-processing arrangements and cross-border data-transfer mechanisms involving credit bureaus, banks or offshore service providers. Owns the regional data-subject rights framework, including intake, identity verification, legal assessment, fulfilment, exemptions, audit trails and escalation for access, correction, erasure, objection and other applicable rights, in line with the requirements and timelines of the relevant jurisdiction. Maintains a regulatory applicability matrix covering jurisdictions, entities, products, processing activities and applicable privacy obligations; monitors regulatory developments across the GCC and advises on required adaptations to policy, contracts, controls or platform design. Maintains a regional data-transfer and data-residency register identifying where personal data is collected, stored, accessed, transferred and processed, including transfers between MENA entities and Yubi Group entities outside the region. Third-Party & Vendor RiskLeads privacy due diligence on fintech partners, cloud/data-hosting providers, KYC/AML vendors, credit bureaus and other material processors or data-sharing partners, including assessment of their privacy governance, security controls, sub-processors and regulatory obligations. Assesses cross-border data transfer, access and data-residency requirements and ensures appropriate safeguards, contractual measures, risk assessments, approvals and local equivalents are in place for applicable jurisdictions.AI & Credit Model OversightProvides advisory oversight on the privacy implications of AI/ML-driven credit scoring, underwriting, profiling and risk models used on the Yubi platform, including model training, inference and use of external AI service providers. Advises on transparency, explainability, data minimisation, purpose limitation, bias mitigation, human oversight and applicable rights relating to automated lending decisions and profiling. Briefs MENA leadership and relevant risk/audit committees periodically on privacy risk metrics, material findings, regulatory developments, incidents and remediation status. Monitors emerging AI governance and privacy expectations in the UAE and GCC and advises on organisational readiness, including governance requirements for high-risk AI use cases involving personal data. Training & AwarenessBriefs MENA leadership and relevant risk/audit committees on privacy developments, incidents, and regulatory changes.Designs and delivers privacy training for employees, with tailored modules for credit, sales, and technology teams handling sensitive personal and financial data.External Advisers & BudgetManages relationships with external counsel and privacy consultants engaged for regional matters and coordinates privacy regulatory examinations, audits and formal information requests. Owns privacy programme planning and resource requirements and provides input into the annual privacy budget, including external counsel and specialist advisory support. Professional DevelopmentMaintains current knowledge of UAE, DIFC, ADGM, KSA and other applicable MENA data protection law, and relevant international frameworks (including GDPR) where they inform best practice or contractual requirements. Holds or pursues relevant certification (e.g., IAPP CIPP/E, CIPM, CIPT).Qualifications & SkillsEducationDegree in law, information technology, business, or a related discipline.Professional certification in data protection (IAPP CIPP/E, CIPM, CIPT, or equivalent) strongly preferred.Experience8+ years' experience in data protection/privacy roles, including significant experience owning or operating a privacy programme within a fintech, banking, lending, payments or other highly regulated financial services environment; experience serving as a DPO or equivalent senior privacy leader is strongly preferred. Working knowledge of UAE PDPL, DIFC Data Protection Law and ideally ADGM and KSA PDPL, with practical experience assessing applicability and implementing requirements across multiple jurisdictions. Experience handling personal-data breach response, regulatory notification, privacy investigations, regulatory examinations and regulator engagement. Experience advising on data protection aspects of KYC/AML processes, credit data, financial information, data-sharing arrangements, retention/deletion requirements and vendor/partner agreements in a lending, banking or credit context. Exposure to AI/ML governance considerations, particularly around profiling, automated credit decisioning and processing of personal data by AI systems, is strongly preferred. Skills & CompetenciesStrong grasp of financial services data flows (credit data, KYC, financial and transaction data) and associated regulatory sensitivities, including data lifecycle, retention, deletion and cross-border processing. Ability to translate privacy law into practical, commercially workable guidance and embed privacy-by-design and privacy-by-default controls into product, engineering and credit processes. Must be able to perform DPO responsibilities independently and must not be placed in a position where operational responsibilities create a conflict of interest with statutory DPO duties. Sound judgment in handling sensitive and confidential matters.Strong stakeholder management skills across Legal, Compliance, Technology, Security, Product, Credit and regional leadership, with the ability to operate independently and challenge decisions where privacy risk requires escalation. Excellent written and verbal communication in English (Arabic a plus), with the ability to communicate complex privacy requirements clearly to senior management, regulators and operational teams.Solid understanding of information security principles and data architecture.Self-directed, comfortable operating across GCC jurisdictions and time zones, with the independence, judgement and organisational maturity required to perform statutory DPO responsibilities.