Rush Street Interactive
Data Protection Manager
Posted
3 weeks ago
Experience
5+ Years
Deadline
Closed
Job Summary
The Data Protection Manager leads the operational execution of RSI's global privacy and data governance framework. Core responsibilities include managing a small team of privacy analysts, overseeing Records of Processing Activities (RoPA), conducting Data Protection Impact Assessments (DPIAs), leading data breach incident response procedures, updating Data Processing Agreements (DPAs), and managing international Data Subject Requests (DSRs).
Technical Stack & Governance Ecosystem
In your daily workflows, you will interface with and manage compliance across an integrated technical and regulatory stack, including:
- Privacy Management Tooling: Automated data mapping, DSR fulfillment centers, and DPIA logging platforms (e.g., OneTrust, WireWheel, or matching enterprise privacy software).
- Regulatory Compliance Frameworks: General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and emerging global data frameworks.
- Gaming Operational Mandates: Anti-Money Laundering (AML) logging systems, Know Your Customer (KYC) identity networks, and specialized state/national gaming board data retention rules.
- Corporate infrastructure: Secure document directories, automated vendor risk auditing queues, and cross-functional incident notification channels.
Experience & Competencies
Candidates must demonstrate a strong background in data protection frameworks, team leadership experience, and a practical understanding of technical systems:
Core Compliance & Governance Mastery
- Professional Tenure: Minimum of 5+ years of direct professional experience operating within data privacy, information security compliance, corporate governance, or a closely matching risk management field.
- Regulatory Fluency: Advanced operational working knowledge of GDPR and CCPA, with a demonstrated track record of applying at least one additional international privacy framework.
- Privacy Program Deployment: Proven history implementing enterprise privacy architectures, executing comprehensive Data Protection Impact Assessments (DPIAs), and organizing structured Records of Processing Activities (RoPA).
- DSR Lifecycle Management: Direct experience setting up, automating, and auditing multi-jurisdictional Data Subject Request (DSR) and deletion pipelines.
Specialized Industry Awareness
- Online Gaming Regulations: A functional understanding of how data protection overlaps with online gaming data mandates, transactional auditing rules, and player tracking limits.
- Financial Data Controls: Familiarity with the operational friction points between data minimization rules and structural Anti-Money Laundering (AML) / Know Your Customer (KYC) identity collection mandates.
Leadership & Analytical Skills
- Team Leadership: Proven capability to lead, mentor, and set clear operational priorities for a small team of compliance or privacy professionals, fostering professional growth and proactive risk management.
- Technical Translation: Exceptional communication and stakeholder management skills, with a proven ability to translate legal text and regulatory changes into actionable technical controls and business processes.
- Incident Readiness: Experience managing end-to-end incident response pipelines for personal data breaches, including documentation compilation, threat level assessments, and regulatory notification workflows.
- Professional Certifications: Active industry certifications—such as Certified Information Privacy Professional/Europe (CIPP/E), Certified Information Privacy Manager (CIPM), or Certified Information Privacy Technologist (CIPT)—are highly preferred.
Key Responsibilities
1. Privacy Team Leadership & Strategic Oversight (30%)
- Manage the Privacy Unit: Lead, mentor, and organize a small, focused team of privacy professionals—setting clear execution milestones, reviewing analytical outputs, and aligning team workflows with global compliance goals.
- Foster Accountability: Cultivate an internal culture of transparency, continuous learning, and proactive risk management across all business lines.
- Bridge Internal Stakeholders: Serve as the central point of contact for internal teams (Product, Security, Legal) and external entities (regulatory boards, external auditors) on sensitive data processing inquiries.
2. Operational Framework Management & Auditing (25%)
- Maintain Compliance Registers: Author, update, and manage core data protection registers, including global risk logs, localized DPIAs, and comprehensive Records of Processing Activities (RoPA).
- Govern Vendor Contracts: Develop and update standard Data Processing Agreement (DPA) templates, overseeing their implementation across external supply chains and third-party SaaS vendors.
- Conduct Third-Party Audits: Coordinate regular privacy audits and vendor risk assessments to verify that external business associates maintain sufficient security and compliance controls.
3. Privacy-by-Design Advocacy & Product Integration (25%)
- Embed Engineering Controls: Partner directly with product management and engineering squads to implement privacy-by-design and privacy-by-default principles across our software development lifecycle.
- Assess Regulatory Changes: Monitor international data protection developments continuously, translating upcoming regulatory updates into practical, proactive adjustments to internal source code and database rules.
- Run Training Programs: Design and deliver comprehensive privacy awareness programs and compliance training models across all organizational departments to lower the risk of human error.
4. Incident Response & Data Rights Execution (20%)
- Lead Breach Management: Manage our emergency incident response framework for potential personal data breaches, ensuring thorough forensic documentation, risk calculations, and timely regulatory alerts.
- Govern DSR Pipelines: Oversee the data subject request workflow, guaranteeing that customer access, correction, and deletion queries are securely validated and processed within legal timeframes.
- Audit System Purges: Verify that database architecture deletion scripts fully erase appropriate customer records across live and backup environments without breaking data preservation mandates.
Expected Outputs & Deliverables
- Up-to-date, legally defensible RoPA entries and documented DPIA records for all high-risk data operations.
- Standardized, operational DPA templates customized for varying supplier layers and cloud integrations.
- Auditable DSR processing logs demonstrating flawless adherence to statutory response windows.
- Comprehensive data breach incident response files, complete with post-mortem analyses, containment audits, and regulatory communications.
Skills Required:
- Computer / Software / It / Data
- Legal / Law
Quick Actions
Share Vacancy