Epicareer Might not Working Properly
Learn More

Data Privacy Lead

Salary undisclosed

Apply on


Original
Simplified
Get To Know Our GX Bank Team

GX Bank Berhad - the Grab-led Digital Bank - is the FIRST digital bank in Malaysia, approved by BNM to commence operations. We aim to leverage technology and innovation to serve the financial needs of the unserved and underserved individuals, and micro and small medium enterprises.

We are driven by our shared purpose and passion to bring positive transformation to the banking industry, starting with solutions that address the financial struggles of Malaysians and businesses.

Get To Know Our Team

Our company is seeking a talented Data Privacy Lead to assist Data Privacy Officer for overseeing the Bank’s data privacy practices, ensuring compliance with relevant regulations and protecting the personal information of data subjects. The Data Privacy Lead plays a crucial role in safeguarding the Bank against data breaches while also maintaining the trust of the Bank’s customers. This position is part of the Data team that gets to work in depth with the governance of data protection and gets to work closely with Information Security, Compliance, Legal and various stakeholders.

Day-to-day Activities

  • Privacy Program Management:
  • Develop, implement, and manage the organization's privacy program, including policies, procedures, and practices.
  • Ensure the program aligns with applicable laws and regulations, such as PDPA and MCIPD
  • Conduct regular privacy assessments and audits to evaluate program effectiveness and compliance.
  • Regulatory Compliance:
  • Stay informed about changes in privacy laws and regulations, and assess their impact on the organization.
  • Provide guidance on compliance with privacy laws, regulations, and industry standards.
  • Risk Management:
  • Conduct data inventory and data protection impact assessments (DPIAs) for new projects and initiatives.
  • Identify privacy risks and recommend mitigation strategies.
  • Collaborate with IT, legal, and other departments to address and resolve privacy issues.
  • Training and Awareness:
  • Develop and deliver privacy training programs for employees at all levels of the organization.
  • Promote awareness of privacy practices and policies throughout the company.
  • Act as a subject matter expert and provide guidance on privacy-related queries.
  • Incident Response:
  • Manage privacy incidents and data breaches, including investigation, reporting, and remediation.
  • Coordinate with relevant stakeholders to handle incidents effectively and ensure timely resolution.
  • Documentation and Reporting:
  • Maintain comprehensive documentation of privacy policies, procedures, and compliance activities.
  • Prepare regular reports for senior management and stakeholders on privacy program performance and compliance status.
  • Vendor Management:
  • Assess privacy risks associated with third-party vendors and service providers.
  • Review and negotiate privacy-related terms in vendor contracts and agreements.
  • Technical Tools and Platforms
  • Understanding how to embed privacy features into products, process, and systems
  • Technical understanding of platforms used to assess and mitigate privacy risks.
  • Automating data privacy practices and processes to identify and document data privacy risks and compliance checks.
  • Techniques for securing databases including encryption, access control, auditing and regular updates/ patches.

The Must Have

  • Bachelor’s degree in Law, Information Security, or a related field.
  • Minimum of 4 years of experience in privacy, data protection, cyber security or related fields
  • In-depth knowledge of privacy laws and regulations and industry best practices.
  • Experience in stakeholder management, communication, project management and presentation.
  • Banking experience will be an added advantage.