Data Protection Analyst

    Highlights

    In addition to third-party risk management, the Analyst will provide privacy subject matter support to Company business units by supporting DSAR processing, privacy documentation, privacy and data protection research, Data Protection Impact Assessments ("DPIAs"), enterprise data mapping, privacy engineering initiatives, and privacy program management activities. Job Description: Seminole Hard Rock Support Services is seeking a highly motivated, detail-oriented Data Protection Analyst with a focus on third-party risk management, Data Subject Access Request ("DSAR") operations, privacy engineering support, and privacy program management.

    Numbers & Facts

    LocationDavie, FL

    Description

    Skip to main content

    You may choose to display a cookie banner on the external site. You must specify the message in the cookie banner and may add a link to a relevant policy. If you are unfamiliar with these requirements, please seek the advice of legal counsel.

    What are cookies?

    Cookies are simple text files that are stored on your computer or mobile device by a website's server. Each cookie is unique to your web browser. Some information that we collect about you is collected passively through the use of "cookies." Cookies are small files of information, which save and retrieve information about your visit to the Website - for example, how you entered and navigated our Website, and what information was of interest to you. We use this information to remember you when you return and to customize our Website to your preferences. It will contain some anonymous information such as a unique identifier, website's domain name, and some digits and numbers. We may use two types of cookies: (i) Session cookies; and (ii) Persistent Cookies. Session Cookies and Persistent Cookies are categorized as: (a) Strictly Necessary Cookies; (b) Performance and Functional Cookies; (c) Targeting Cookies and (d) Social Media Cookies.

    What types of cookies do we use?

    Necessary cookies

    Necessary cookies allow us to offer you the best possible experience when accessing and navigating through our website and using its features. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information. For example, these cookies let us recognize that you have created an account and have logged into that account. Strictly Necessary Cookies do not store any Personal Information.

    Performance & Functional cookies

    These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance. If you do not allow Performance Cookies we will not know when you have visited our site, and we will not be able to monitor its performance. (Examples: monitor website performance and collect anonymous data on how visitors use a website).

    Targeting cookies

    These cookies enable us and third-party services to collect aggregated data for statistical purposes on how our visitors use the website. These cookies do not contain personal information such as names and email addresses and are used to help us improve your user experience of the website. These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising. Examples include: Criteo, Google.

    Social Media Cookies

    These cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools. Examples include: Facebook, Instagram, Twitter).

    How to delete cookies?

    If you want to restrict or block the cookies that are set by our website, you can do so through your browser setting. Alternatively, you can visit www.internetcookies.com, which contains comprehensive information on how to do this on a wide variety of browsers and devices. You will find general information about cookies and details on how to delete cookies from your device.

    Do not track signals

    Currently, our systems do not recognize browser "do-not-track" requests. You may, however, disable certain tracking as discussed in the Cookies section (e.g., by disabling cookies). Please note that Hard Rock does not collect, and is not aware of third parties that collect, from users of the Website personal information about users' online activities across third party websites.

    Clear GIFS, Pixel Tags and other technologies

    Clear GIFs are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are stored on your computer's hard drive, clear GIFs are embedded invisibly on web pages. We may use clear GIFs (a.k.a. web beacons, web bugs or pixel tags), in connection with our Website to, among other things, track the activities of Website visitors, help us manage content, and compile statistics about Website usage. You may view and change your preferences at any time by using the 'Privacy Settings' link found in the footer of our website. We and our third party service providers also use clear GIFs in HTML e-mails to our customers, to help us track e-mail response rates, identify when our e-mails are viewed, and track whether our e-mails are forwarded.

    Third party analytics and tracking

    We use automated devices and applications, such as Google Analytics, to evaluate usage of our Site. We also may use other analytic means to evaluate our services. We use these tools to help us improve our services, performance and user experiences. These entities may use cookies, tracking pixels and other tracking technologies to perform their services. We do not share your personal information with these third parties.

    Contacting us

    If you have any questions about this policy or our use of cookies, please contact us at dataprotection@shrss.com.

    Read Full Privacy Message

    Decline

    Accept Cookies

    Sign In

    Search for JobsStay Connected

    Data Protection Analyst page is loaded

    Data Protection Analyst

    Apply

    remote typeHybrid

    locationsSupport Services Headquarters Building

    time typeFull time

    posted onPosted Yesterday

    job requisition idR14500

    Our team members are the key to our company's success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

    Job Description:

    Seminole Hard Rock Support Services is seeking a highly motivated, detail-oriented Data Protection Analyst with a focus on third-party risk management, Data Subject Access Request ("DSAR") operations, privacy engineering support, and privacy program management. This role will join the Company's exciting and fast-paced Global Data Protection Office ("GDPO") team in Davie, Florida. The Analyst will work closely with Company business units, third-party vendors, and service providers to assess privacy, data protection, and information security operational and contractual risks. The Analyst will communicate requirements and recommend practical controls to support risk reduction and Company compliance.

    In addition to third-party risk management, the Analyst will provide privacy subject matter support to Company business units by supporting DSAR processing, privacy documentation, privacy and data protection research, Data Protection Impact Assessments ("DPIAs"), enterprise data mapping, privacy engineering initiatives, and privacy program management activities. The Analyst will help translate privacy requirements into practical business, vendor, and technical controls and monitor implementation to support compliance, accountability, and risk reduction.

    Our team is growing and if you are equally passionate about privacy, data management, and career growth, an opportunity at Seminole Hard Rock may be a great match!

    Job Responsibilities:

    • Lead end-to-end processing of DSARs, ensuring timely fulfillment and compliance with applicable data protection regulations and internal Company policies and procedures.
    • Work closely with Company marketing, technology, security, data governance, and business teams to support privacy-by-design and the implementation of privacy-enhancing technologies, including data minimization, pseudonymization, anonymization, consent management, and preference management solutions.
    • Support privacy engineering initiatives by translating privacy requirements into operational and technical controls, including data minimization, purpose limitation, consent management, data mapping, retention, access controls, monitoring, and privacy-by-design requirements.
    • Conduct third-party privacy risk assessments, review vendor documentation, document findings, and track remediation in coordination with business owner, Security and Legal.
    • Assist with enterprise data mapping to help maintain clear visibility into personal information processed by the Company, including data flows, systems, processing purposes, vendors, and applicable controls.
    • Conduct DPIAs and related privacy risk assessments in accordance with GDPR requirements and other global regulatory requirements applicable to the Company.
    • Research global and local privacy and data protection laws, standards, and regulatory developments and translate requirements into actionable business, vendor, and technical steps.
    • Review and assist in developing privacy-related policies, standards, procedures, templates, and guidance materials.
    • Monitor changes in third-party and privacy regulatory requirements and coordinate with GDPO stakeholders to support impact analysis and remediation planning.
    • Support privacy program management activities by maintaining trackers, documenting decisions, monitoring control implementation, preparing status updates, and escalating issues requiring GDPO leadership attention.

    Minimum Required Qualifications:

    • Minimum of three (3) years of experience in data protection, privacy, compliance, risk management, or related role.
    • Strong understanding of privacy, data protection, and information security requirements within the United States and globally.
    • Ability to identify opportunities to streamline or automate repetitive tasks with a high degree of accuracy and consistency.
    • Excellent organizational skills with a strong focus on accuracy, attention to detail, and documentation quality.
    • Bachelor's degree or equivalent combination of education and experience, preferably in MIS, CIS, Computer Science, Cybersecurity, Law, or related field.
    • Experience processing DSARs and coordinating with stakeholders to complete privacy requests accurately and in a timely manner.
    • Ability to operate effectively both independently and as part of a team.
    • Strong written and verbal communication skills, including the ability to explain privacy requirements clearly to business and technical stakeholders.
    • Ability to manage multiple priorities, shift focus as needed and maintain accuracy under competing deadlines.
    • High level of personal integrity, discretion, and confidentiality.
    • Positive, collaborative attitude with a practical approach to getting things done.

    Additional Preferred Qualifications:

    • CIPP/US, CIPP/E, CIPM, CIPT, or other relevant privacy, data protection, security, or risk certification.
    • Experience with the design, implementation, and maintenance of privacy compliance policies, procedures, controls, and programs.
    • Experience working with technical, security, data governance, marketing, or product teams to operationalize privacy requirements through systems, workflows, and controls.
    • Proficiency in Microsoft Office Suite, including PowerPoint, Excel, Word, and OneDrive.
    • Experience with GRC tools, data posture management solutions, consent or preference management tools, and international legal research toolsets.
    • Ability to cross-train and collaborate with the GDPO and compliance teams on day-to-day privacy operations.
    • Experience performing privacy risk assessments and ongoing privacy compliance monitoring activities.
    • Ability to translate regulatory requirements into practical, actionable controls while supporting business strategy.

    Why work here?

    Thank you for choosing us as your employer of choice! If you are ready for an exciting opportunity working in a creative environment where you can bring your authentic self to work, we want to connect with you!

    Get In Touch

    If you''re unable to find a position that matches your interest, please tell us a little about yourself, and we''ll recommend jobs that match your interests.

    Get Started

    About Us

    Be Iconic represents the roots of our culture.

    The Seminole Tribe of Florida remains the only unconquered tribe in the United States of America. The Tribe established Seminole Gaming in 1979, when it opened the first high-stakes bingo hall in the United States. Building on its rich heritage of courageous and groundbreaking achievements, the Seminole Tribe of Florida acquired Hard Rock International in March 2007-the first transaction of its kind by a Native American tribe.

    Today, Hard Rock International remains one of the most globally recognized companies in the world, with Hard Rock Hotel, Casino, Cafe and Rock Shop venues in over 74 countries. With the continued growth of Seminole Gaming and Hard Rock International, Seminole Hard Rock Support Services was created to support all of our brands and lines of business.

    With the largest global footprint in the hospitality industry for over 50 years, our number-one job is to bring fun and excitement to our team members and our guests!

    Read More

    Follow Us

    *

    Privacy Policy

    2026 Workday, Inc. All rights reserved.

    Similar Jobs

    See more jobs