Data Protection & Legal Compliance Officer
ICEA Lion
Quick Take
Support ICEA Lion's legal and data privacy compliance across multiple subsidiaries by managing processing records, vendor agreements, regulatory submissions, and data subject requests while drafting contracts and conducting legal research.
Qualified advocate with strong knowledge of Kenya's Data Protection Act, ability to draft and review legal contracts, and meticulous management of compliance trackers and registers.
Competitive salary at a leading East African financial conglomerate with direct exposure to data privacy law and multi-entity governance, ideal for building a specialized compliance career.
Job Description
ICEA Lion Group, one of East Africa's leading insurance and financial services conglomerates, is seeking a detail-oriented and proactive Data Protection & Legal Compliance Officer to join its Legal and Compliance team in Nairobi. This role sits at the intersection of data privacy law and corporate legal practice, offering a unique opportunity to contribute to the governance and regulatory compliance framework of a multi-subsidiary financial institution.
Reporting to the Data Protection Officer (DPO) and the Legal team, the successful candidate will support the Group's adherence to Kenya's Data Protection Act, sector-specific regulations, and contractual obligations across the business. If you are a qualified advocate with a passion for data privacy and corporate law, this role provides the ideal platform to build a distinguished legal compliance career.
- Maintain and continuously update the Records of Processing Activities (RoPA) register to reflect current data processing operations across all subsidiaries.
- Support the timely renewal of registration certificates from relevant regulatory bodies including the Office of the Data Protection Commissioner (ODPC).
- Assist the DPO in monitoring and ensuring subsidiary-level data protection deliverables are completed on schedule.
- Maintain and update the third-party vendor register, and ensure Data Processing Agreements (DPAs) are executed with all relevant data processors.
- Manage the Data Subject Rights (DSR) request tracker and ensure all requests are resolved within legally prescribed timelines.
- Monitor and track emerging Data Protection Regulations, Guidelines, and Determinations issued by the ODPC and other bodies.
- Review, draft, and revise a wide range of court pleadings, contracts, and legal correspondence.
- Provide strategic legal input on business matters and commercial transactions.
- Support the continuous improvement of standard form agreements and legal process documentation.
- Research and analyse statutes, regulations, and legal precedents applicable to the Group's operations.
- Conduct gap analyses on proposed and enacted legislation affecting the Group's business activities.
- Track legal compliance levels across entities and produce periodic compliance reports.
- Maintain the Litigation Tracker, prepare periodic litigation status reports, and coordinate communication with external counsel.
- Perform any other duties as may be assigned by Management from time to time.
- Interpret and apply Kenya's Data Protection Act and subsidiary regulations to practical business scenarios across a multi-entity financial group.
- Draft, review, and negotiate legal contracts including Data Processing Agreements, NDAs, and commercial agreements with minimal supervision.
- Conduct thorough legal research and translate findings into actionable compliance recommendations.
- Manage multiple compliance trackers and registers accurately and proactively flag risks before deadlines are missed.
- Communicate complex legal concepts clearly to non-legal business stakeholders both verbally and in writing.
- Perform regulatory gap analyses and contribute meaningfully to legal risk management processes.
- Demonstrate high personal integrity and handle confidential information with absolute discretion.
- Work efficiently in a fast-paced, regulated financial services environment under tight deadlines.
ICEA Lion offers a competitive remuneration package benchmarked against the Kenyan financial services industry. The estimated monthly gross salary for this role ranges from KES 80,000 to KES 140,000 depending on qualifications and experience. The Group also offers a comprehensive benefits package typical of a leading insurance employer.
- Medical insurance cover
- Performance-based bonus
- Professional development and training support
- Pension/provident fund contributions
Ideal Candidate: You are a recently admitted Advocate of the High Court of Kenya (or awaiting admission) with a Bachelor of Laws degree and a strong academic grounding in Kenyan contract law and data protection legislation. You have a keen eye for detail, strong drafting skills, and are eager to grow within a structured legal and compliance environment in the financial services sector. Additional certification or training in Data Protection (e.g., CIPP, CIPM, or ODPC-accredited training) is a significant advantage.
Do NOT apply if: You do not hold an LLB degree from a recognised institution, you are not yet admitted or in the process of admission to the Kenyan bar, or you have no working knowledge of Kenya's Data Protection Act and the legal compliance landscape. This role is not suited for candidates seeking purely transactional or litigation-focused positions with no interest in regulatory compliance.
Interested and qualified candidates should submit their application through the ICEA Lion Group official careers portal or via the job platform where this posting was found. Your application should include:
- An updated CV clearly detailing your legal qualifications, admission status, and relevant experience.
- A cover letter addressed to the Head of Legal & Compliance explaining your suitability for the role and your specific interest in data protection and legal compliance.
- Copies of your LLB certificate and any data protection training certificates (if available).
Only shortlisted candidates will be contacted. ICEA Lion is an equal opportunity employer.
Requirements Breakdown
Must Have
- Admitted advocate of the High Court of Kenya or equivalent legal qualification
- Practical knowledge of Kenya's Data Protection Act and ODPC regulations
- Ability to draft, review, and negotiate legal contracts (DPAs, NDAs, commercial agreements)
- Experience managing compliance trackers, registers, and legal documentation
- Strong legal research and analytical skills with attention to detail
Nice to Have
- Prior experience working with a Data Protection Officer or in a compliance team
- Exposure to financial services or multi-subsidiary regulatory environments
- Familiarity with litigation tracking and external counsel coordination
- Knowledge of sector-specific regulations beyond data protection
Don't meet every requirement? Tailor your CV to close the gap →
Salary Context
Competitive mid-level salary for a specialized legal compliance role in Nairobi's financial services sector.
KES 80,000–140,000/month is above entry-level for a legal professional but reflects the specialized nature of data protection and compliance work in Kenya's financial services. Salary progression depends on advocate experience, data protection expertise, and responsibility scope within the Group.
About ICEA Lion
ICEA Lion Group is one of East Africa's leading insurance and financial services conglomerates, operating across multiple subsidiaries with significant regional presence. The Group prioritizes robust governance and regulatory compliance, making it an ideal employer for professionals seeking exposure to complex, multi-entity legal and compliance frameworks. Working at ICEA Lion offers exposure to sophisticated financial services operations and the opportunity to contribute meaningfully to data privacy leadership in East Africa.
Likely Interview Questions
- 1
Walk us through your experience with Kenya's Data Protection Act. Can you give an example of how you've applied it to a real business scenario?
- 2
Describe your experience drafting and negotiating Data Processing Agreements. What are the key clauses you always prioritize?
- 3
How would you manage competing priorities if you had multiple Data Subject Rights requests and a regulatory submission deadline simultaneously?
- 4
Tell us about a time you identified a compliance gap or risk before it became a problem. How did you escalate it and what was the outcome?
- 5
ICEA Lion operates multiple subsidiaries. How would you ensure consistent data protection compliance across a complex Group structure?
Application Tips
Emphasize any direct experience with the Office of the Data Protection Commissioner (ODPC), registration renewals, or Records of Processing Activities management—these are core day-to-day responsibilities.
Highlight specific examples of contracts you have drafted or negotiated, particularly DPAs or vendor agreements, and mention any experience with multi-entity or financial services environments.
Demonstrate your proactive compliance mindset by describing a situation where you identified a regulatory gap, researched it, and provided actionable recommendations to leadership.
Career Path
Roles that lead here
Where this leads
Skills & Keywords
Honest Assessment
Green Flags
- Reporting to both the DPO and Legal team provides dual mentorship and career development in two critical compliance domains.
- Working for a major East African financial services conglomerate with multiple subsidiaries offers exposure to complex, sophisticated compliance challenges and high-caliber legal work.
- Clear and detailed responsibility list (RoPA management, ODPC coordination, litigation tracking, contract drafting) shows structured compliance governance and professional development opportunities.
- Salary range of KES 80,000–140,000/month is competitive for a specialized legal role in Nairobi and reflects the seniority and expertise required.
Watch Out
- The job description is truncated mid-sentence under 'Required Skills & Experience,' suggesting the full role scope and expectations may not be clearly communicated. Request the complete job spec before applying.
- The salary range (KES 80,000–140,000) is quite broad—clarify during interview discussions where your experience level falls within that band.
- Heavy emphasis on 'any other duties as assigned by Management' could signal scope creep; confirm realistic workload and reporting structure clarity before acceptance.
A Day in the Life
Your week at ICEA Lion typically includes reviewing and updating the Records of Processing Activities register for subsidiary data flows, corresponding with the ODPC on registration renewals, and drafting or negotiating Data Processing Agreements with third-party vendors. You'll spend time managing the Data Subject Rights tracker, ensuring responses meet legal timelines, and conducting legal research on new ODPC determinations or emerging legislation. Mid-week, you might assist the DPO in conducting gap analyses across subsidiaries, prepare a compliance status report for management, and collaborate with external counsel on active litigation matters—balancing meticulous documentation with strategic legal advice on commercial transactions.
Frequently Asked Questions
What qualifications do I need to be a Data Protection & Legal Compliance Officer at ICEA Lion?
You must be an admitted advocate of the High Court of Kenya with practical knowledge of Kenya's Data Protection Act and ability to draft and negotiate legal contracts. Prior compliance or data protection experience is highly valuable.
Is the Data Protection & Legal Compliance Officer role at ICEA Lion remote?
The posting specifies the location as Nairobi with no mention of remote work. Clarify flexible working arrangements during the application or interview process.
How much does a Data Protection & Legal Compliance Officer earn at ICEA Lion?
The posted salary range is KES 80,000–140,000 per month. Your placement within that range will depend on your advocacy experience, data protection expertise, and relevant compliance background.
What are the career growth opportunities for this role?
This role is a strong stepping stone to becoming a Data Protection Officer, Head of Legal and Compliance, or Group General Counsel. Working within a multi-subsidiary financial services environment accelerates your understanding of complex regulatory governance and positions you for senior compliance leadership roles.
Free Match Score
See how well you match this job
Upload your CV and get an instant AI score showing exactly how well your experience matches this Data Protection & Legal Compliance Officer role. Free, takes 30 seconds.
Get My Match Score — FreeNo credit card needed
Boost your chances
AI-tailored for: Data Protection & Legal Compliance Officer at ICEA Lion