About this role
At Kempinski, we don't just offer stays; we curate moments. As a hospitality organization, anchored in a legacy of elegance and a pioneering spirit, we have grown into a collection of iconic hotels and resorts around the world, each a landmark in its own right. From grand palaces steeped in history to contemporary masterpieces of design, Kempinski is where impeccable service meets authentic local experiences. We empower our people to be artisans of hospitality, fostering an environment where passion is nurtured, individuality is celebrated, and every detail is thoughtfully considered. Joining Kempinski means becoming part of a family that is dedicated to creating memories that last a lifetime for our guests, and a fulfilling and enriching career for our team. If you are driven by excellence, inspired by the art of hospitality, and seek to contribute to a legacy of luxury, we invite you to explore the exceptional opportunities that await you at Kempinski Hotels. Come, be a part of our story. As the Compliance Officer, you will serve as the primary steward of guest and employee privacy across our global portfolio of luxury hotels. You will be responsible for safeguarding the brand’s reputation by ensuring that our operational excellence is matched by unwavering ethical and legal integrity. Policy Development & Governance Draft and Maintain: Create, update, and implement robust data protection policies, standards, and procedures tailored to the hospitality industry. Global Alignment: Ensure local hotel practices align with the Corporate Privacy Framework while respecting regional legal nuances. Records of Processing: Maintain comprehensive Records of Processing Activities (ROPA) for all corporate and property-level functions. Compliance Monitoring & Auditing Compliance Oversight: Monitor compliance with the GDPR and other relevant privacy laws through regular gap analyses and internal audits. DPIAs: Lead and document Data Protection Impact Assessments (DPIAs) for new technologies, guest loyalty programs, and marketing initiatives. Third-Party Risk: Evaluate the data protection posture of vendors and partners, ensuring Data Processing Agreements (DPAs) are in place. Advisory & Training Expert Guidance: Serve as the primary point of contact for the business on privacy matters, providing pragmatic advice on "Privacy by Design." Awareness Programs: Design and deliver engaging data protection training modules for corporate staff and hotel management teams worldwide. Subject Access Requests: Oversee the timely and legal handling of Data Subject Access Requests (DSARs) and "Right to be Forgotten" queries. Incident Management Response Leadership: Lead the response team in the event of data breaches, ensuring timely notification to supervisory authorities and affected individuals. Remediation: Conduct post-mortem analyses of incidents to strengthen technical and organizational measures.