Personal Data Protection Officer

Sopra Steria I2S-Singapore, Singapura

Position Purpose:
There were recent evolutions in the regional Personal Data Protection laws as well as the group standards in that matter. The current APAC practices have to be improved to reach the required level of maturity. This is an opportunity as well to review the data protection framework at large. The main objective is to implement processes and controls to ensure that privacy and data protection risks are well mitigated.

There are a total of 3 openings for this role - 2 Juniors and 1 Senior.

Responsibilities

  • Deliver a register of personal data protection activities describing what personal data is, for what purpose and by whom. This has to be aligned with the Group global practices.
  • Implement data privacy risks assessment in the existing processes to ensure that new activities and recurrent risk reviews fully embed data privacy whenever required
  • Roll-out the relevant control plan to ensure that privacy risks management processes are in place
  • Assessing, managing and monitoring compliance of APAC activities to applicable data protection and privacy laws
  • To issue/update existing group Data Protection policies, standards and procedures to conform to internal best practice and local Data Privacy laws / regulations. Develop missing ones.
  • Generate and regularly update Compliance Management KPIs;
  • Advise internal stakeholders on applicable obligations for each existing and new data processing operations, following a “privacy by design / default” approach, providing comprehensive and pragmatic recommendations, as well as draft and review data processing agreements with service providers and partners;
  • Inform, empower and raise awareness: carry out or contributes to data protection awareness actions, update and deploy guidelines, policies and procedures and animate the Privacy Community
  • Promotion of Group best practices and support operational teams on their requests.
  • Supporting and advising on data protection impact assessments
  • Delivering training on privacy, data protection and policy matters

Requirements:

  • Bachelor's degree in business law or information technology law or Equivalent
  • Junior role: at least 5 years of experience in Data Protection/Privacy
  • Senior role: at least 7 years of experience in Data Protection/Privacy
  • Experience working in Banking / Financial industry (a must for the Senior position)
  • Change management and Operational risk management
  • Sound knowledge in Personal Data Protection and Privacy Laws, in particular the GDPR, PDPA, PIPA, APP, APPI, and of other major privacy frameworks and legislations in APAC;
  • Strong communication skill and teamwork skill, able to effectively communicate with cross-functional teams and vendors, both written and oral communication is critical.
  • Strong ability to analyze, adapt, and support change

Benefits

  • Benefits: annual leave, annual bonus, work-from-abroad option
  • Insurance: Life, GP, Dental and Optical insurance
  • Multinational working environment with internal mobility opportunities
  • E-learning and certifications paths
  • Regular team buildings and volunteering activities