It’s never been a more exciting time to join Vistra.
At Vistra our purpose is progress. We believe that our clients have the power to change the world and to do great things for global progress, and we exist to remove the friction that comes from the complexity of global business – to help our clients achieve progress without friction.
But progress only happens when people come together and take action. And we’re absolutely committed to building a culture where our people can do just that.
We have an exciting opportunity for you to join our team as Data Privacy Manager. Reporting to the Data Privacy Officer this full-time and permanent position is based in Kuala Lumpur, Malaysia and offers regional coverage, allowing you to make a significant impact to the Group Privacy Office and its’ growth.
The Data Privacy Manager will be a member of the Group Privacy Office and support all areas of the business, with specific focus on Global Solutions operations. The role ensures adherence to Group Privacy policies while providing expert guidance to business teams across multiple jurisdictions.
Responsibilities
Privacy Queries
- Act as the go-to expert on privacy matters, providing guidance to various teams within the organization, especially the Global Solutions business.
- Interpret and apply data privacy laws and regulations to business operations, ensuring compliance and risk mitigation.
- Address internal and external queries related to data privacy, including advice on the lawful basis for data processing, data retention, and cross-border data transfers.
Data Privacy Impact Assessments (DPIAs):
- Conduct DPIAs for new projects, systems, or processes involving personal data to assess potential privacy risks.
- Collaborate with project managers, legal teams, and business units to implement risk mitigation strategies.
- Ensure DPIAs align with regulatory requirements such as the GDPR, PDPA, or other applicable privacy laws.
Register of Processing Activities (ROPA)
- Maintain and update the ROPA, ensuring it accurately reflects the organization’s data processing activities.
Incident Management
- Act as a key advisor in handling data breaches or security incidents, ensuring swift and compliant responses.
Subject Rights Requests (SRRs):
- Manage and respond to SRRs (such as access, rectification, erasure, or data portability requests) within legally mandated timeframes.
Regulatory Monitoring
- Track and implement changes in local privacy regulations.
Training
- Develop and deliver privacy training programs tailored for different business functions.
- Raise awareness about data protection responsibilities and best practices through workshops, e-learning modules, and awareness campaigns.
- Ensure employees understand and comply with privacy policies, especially those handling personal data.
Requirements
- Bachelor’s degree in any relevant background
- 3–4 years of experience in a data privacy role within a multinational organization.
- Strong understanding of privacy regulations in the Asia region (PDPA, DPDP, PIPL) and a good understanding of the global data protection landscape.
- Excellent interpersonal and advisory skills.
- Excellent organisational and communication skills.
- Fluent in English and proficient in a regional language eg. Mandarin would advantageous.
At our Malaysia office, we believe in putting our employees’ well-being first! We provide:
- Regional working exposure in different jurisdiction
- Training and development for career advancement & personal development
- Hybrid working arrangement
- Medical, life, dental coverage
- Study leave and professional membership coverage
If you are excited about working with us, we encourage you to apply or have a confidential chat with one of our Talent Acquisition team members. Our goal is to make this a great place to work where all our people can thrive. We hope you join us on this exciting journey!