Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Rukayat Idrees

aubrey

Summary

A skilled and experienced Data Privacy and Compliance Analyst with over six years of experience in ensuring compliance, security, and privacy of data and vendor management. Proficient in conducting due diligence, negotiating and drafting data processing agreements, monitoring and auditing vendor performance, and reporting on privacy and vendor risk. Adept at using various tools and frameworks, such as GDPR, CCPA, and HIPAA, to manage and protect personal data. A team player with excellent communication, analytical, and problem-solving skills.

Overview

1
1
Certification
11
11
years of professional experience

Work History

Data Privacy and Compliance Analyst

Citizens Bank
01.2020 - Current
  • Ensure compliance requirements with a variety of global privacy regulations including GDPR, CCPA, HIPAA, PCI-DSS, state Privacy Laws, SOC2 Privacy, ISO 27001, ISO 27018, and ISO 27701.
  • Facilitate Privacy by Design by working with key business stakeholders to complete Privacy Impact Assessments (PIAs) and performing the initial review of completed PIAs and Data Protection Impact Assessments (DPIAs) for new processing activities, IT changes, projects, and data ingests.
  • Supports the team in responding to privacy requests from clients, candidates, and employees relating to privacy law. Manage data subject access requests DSAR.
  • Conduct and facilitate reviews of IT privacy controls based on standard methodologies and an understanding of technical infrastructure, IT & privacy risk, and cyber security.
  • Perform privacy training and awareness for employees and stakeholders.
  • Assist in the review and maintenance of the repository of policies and procedures. Ensure policies and procedures are updated as and when required, while ensuring privacy impacts are considered.
  • Review and negotiate Data Processing Agreements and similar privacy addendum.
  • Assist with the monitoring of compliance to third party contractual commitments in relation to IT Risk, Compliance and Privacy requirement.
  • Research problems related to data privacy and recommended solutions as well as providing resource estimates and progress reports.
  • Assists in developing, implementing, maintaining, and evaluating the efficiency of data privacy controls as well as other security-related compliance controls to reduce and mitigate risk.
  • Identify, quantify, track and lead mitigation of privacy and compliance risks. Assist with data mapping, data privacy impact assessments, data subject request.
  • Support DPIAs and report on associated risks because of the assessments, carry out trend analysis and support the business in approach for risk mitigation. Review vendor contracts for risk analysis.
  • Participate in the privacy component of third-party risk management program, including sending out questionnaires, reviewing answers for privacy implications, and coordinating with Security, Legal Compliance and Procurement
  • Monitor the privacy email alias and serve as the initial point of contact for customer, prospect, and internal privacy inquiries.
  • Track progress on the IT Privacy Program and assist with reporting progress and drive priority tasks.
  • Stay current with existing and new domestic and international laws.
  • Assist in privacy and compliance due diligence transactions and in integration of acquired companies into privacy and compliance programs.

Data Privacy Analyst

Valley Hospital
01.2017 - 12.2019
  • Ensured compliance with HIPAA, HITECH, and state healthcare privacy laws, reducing privacy and compliance risks.
  • Monitored and safeguarded PHI/ePHI across EMR systems, cloud platforms, and third-party vendors through access reviews and audits.
  • Conducted Privacy Impact Assessments (PIAs) and risk assessments for new technologies, patient portals, and vendor integrations.
  • Investigated and managed data breaches and potential PHI exposures, performing root cause analysis and reporting within regulatory timelines.
  • Developed and delivered HIPAA privacy training for clinical and administrative staff, increasing awareness and reducing human error incidents.
  • Collaborated with compliance, legal, and IT security teams to enforce Business Associate Agreements (BAAs) and ensure vendor compliance.
  • Drafted and updated privacy policies, consent management processes, and Notice of Privacy Practices (NPP) in alignment with regulatory updates.
  • Partnered with security teams to audit logs, monitor data flows, and enforce retention schedules, ensuring adherence to healthcare privacy standards.

Vendor Management Analyst

Sims Metal Management
10.2015 - 12.2016
  • Responsible for processing incoming vendor (agencies, subcontractors, background check vendor)
  • Maintain vendors’ status and serve as a point of contact for inquiries, findings, and best practices.
  • Perform a risk assessment of agencies and subcontractors based on the company due diligence procedure.
  • Collect vendor’s onboarding information and work with various analytical tools to research agencies and subcontractors.
  • Fraud Compliance review of applicant applications and documents delivered to back-office agents for approval.
  • Analyze fraud monitors and render a decision to determine the out of an application.
  • Collaborate with cross-functional teams troubleshoot technical issues.
  • Manage TPRA Assessment Requests Queue and Assignment
  • Review and analyze TPRA Assessments Identify risks and findings.
  • Communicate TPRA assessment results with the business and stakeholders.

Education

B.Sc. - Business Management

Kean University
Newark, NJ

Associate of Science - Business Administration

Essex County Community College

Skills

  • Data Processing Agreement (DPA)
  • Privacy by Design
  • Incident Response and Data Breach Management
  • Privacy Impact Assessments (PIAs)
  • Privacy Law
  • Privacy Policy Development
  • DSAR Vendor Assessment and Management
  • Data Auditing and Reporting
  • Training and Awareness Programs
  • Data Governance
  • Data Breach Response
  • Privacy Audit
  • Regulatory Compliance (GDPR, CCPA, HIPAA, etc)
  • Data Mapping and Classification

Certification

  • Certified Information Privacy Professional/United States (CIPP/US)
  • OneTrust Certified Privacy Professional
  • OneTrust PIA & DPIA Automation Expert
  • OneTrust Data Mapping Automation

Timeline

Data Privacy and Compliance Analyst

Citizens Bank
01.2020 - Current

Data Privacy Analyst

Valley Hospital
01.2017 - 12.2019

Vendor Management Analyst

Sims Metal Management
10.2015 - 12.2016

Associate of Science - Business Administration

Essex County Community College

B.Sc. - Business Management

Kean University
Rukayat Idrees