Manager, Data Privacy and Governance is responsible for developing and overseeing the organisation’s data privacy and governance framework. The role serves as the organisation's subject matter expert on data protection matters, ensuring compliance with applicable laws, managing risks, and establishing effective governance frameworks, policies, and controls. The incumbent will partner closely with business, technology, legal, security, and risk stakeholders to embed privacy-by-design principles, monitor regulatory developments, and drive a culture of responsible data management and governance across the organisation.
Key Responsibilities
Data Privacy
- Serve as the designated subject matter expert on data privacy across the organisation and provide guidance on data protection matters.
- Ensure compliance with applicable privacy and data protection laws, including regular reporting to the organisation’s parent company.
- Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for both existing and new products, systems, technologies, and business initiatives.
- Assess recommend appropriate controls to mitigate regulatory, operational, and reputational risks.
- Manage data subject requests, privacy incidents, breach reporting obligations, and compliance documentation.
- Oversee third-party privacy risk management, including privacy due diligence and vendor assessments.
- Partner with Legal, Technology, and Business teams to embed privacy-by-design principles into business processes and technology solutions.
Regulatory Affairs
- Monitor, analyse, and interpret applicable legislation, regulatory developments, guidance, and industry best practices in the industry.
- Assess the impact of new or amended regulatory requirements and lead implementation efforts to ensure ongoing compliance.
- Act as the primary point of contact for regulatory enquiries, audits, inspections, investigations, and authority requests.
- Support regulatory reporting, submissions, and engagement activities as required.
- Maintain awareness of regulatory trends and enforcement actions to proactively identify emerging compliance risks.
Governance & Policy
- Lead the development, implementation, and continuous improvement of the organisation’s governance framework.
- Develop, maintain, and periodically review policies, standards, procedures, and governance controls.
- Establish and monitor governance processes, accountability mechanisms, and compliance oversight activities.
- Prepare organisation risk, compliance, and governance reporting for senior management, risk committees, and other governance forums.
- Develop privacy-related metrics, KPIs, and KRIs to measure programme effectiveness and compliance maturity.
- Drive continuous improvement initiatives to strengthen governance, compliance processes, and operational effectiveness.
Requirements
- Bachelor's degree in Law, Business, Information Systems, Cybersecurity, Risk Management, or a related discipline.
- 5–8 years of experience in data privacy, regulatory compliance, governance, risk management, or a related field.
- Strong knowledge of privacy and data protection regulations, including Singapore's PDPA and regional privacy frameworks.
- Experience developing and implementing privacy programmes, governance frameworks, policies, and controls.
- Experience conducting privacy risk assessments, PIAs, and DPIAs.
- Strong stakeholder management, communication, and policy drafting skills.
- Ability to interpret regulatory requirements and translate them into practical business solutions.
- Professional privacy certifications (e.g. CIPP, CIPM, CIPT) are preferred.
- Experience in technology, cybersecurity or other regulated industries will be advantageous.