Manager - Data Protection, Privacy & Data Governance
gamuda land- Posted 4 days ago
- Be among the first 10 applicants
Job Description
Job Summary
The role supports the implementation and day-to-day coordination of data protection, privacy and
data governance requirements within Gamuda Land, in alignment with Group policies and direction.
As Sub-Data Protection Officer (IT) for Gamuda Land, the role works closely with the Group DPO
and serves as the key coordination point for data protection and privacy matters relating to IT, digital
platforms, systems and data.
The primary responsibility is to operationalise Group data protection and privacy requirements within
Gamuda Land, coordinate implementation across the relevant stakeholders, monitor compliance
and escalate matters requiring Group-level direction to the Group DPO.
Data Protection and Privacy will be the primary focus, while Data Governance and Master Data
Management (MDM) will be progressively developed as a secondary capability within Gamuda
Land.
Key Responsibilities
- Data Protection & Privacy – Primary
● Work closely with the Group DPO to understand and implement Group data protection and
privacy requirements within Gamuda Land.
● Act as the key Sub-DPO (IT) contact for privacy and data protection matters relating to IT
systems, digital platforms and data.
● Support the implementation of Group data protection and privacy policies within Gamuda
Land.
● Apply Privacy by Design principles when introducing new systems, digital initiatives or major
system changes.
● Coordinate privacy reviews and Data Protection Impact Assessments (DPIAs) for projects
and systems involving personal data, where required.
● Identify privacy risks or gaps and work with the relevant business, IT, Information Security
and control functions to address them.
● Support privacy and data protection reviews of third-party vendors and technology service
providers.
● Maintain relevant Records of Processing Activities (RoPA) and other required privacy
records for GL IT systems and digital platforms.
● Maintain or coordinate data-flow mapping to understand how personal data is collected,
used, shared, stored, retained and disposed of.
● Maintain privacy assessments, action items and supporting documents for audit and
compliance purposes.
● Support internal and external audits relating to data protection and privacy.
● Track agreed actions and follow up with the responsible owners until they are completed.
● Escalate significant privacy risks, incidents or matters requiring further guidance to the
Group DPO.
2. Data Incident Coordination
● Act as the GL Sub-DPO (IT) coordination point when a potential data privacy incident is
identified.
● Work with IT and Information Security on technical investigation, containment and
remediation.
● Work with the relevant business owner to understand the affected data, process and
business impact.
● Gather and document the necessary facts for privacy assessment.
● Coordinate the privacy and governance assessment with the Group DPO.
● Escalate potential data breaches to the Group DPO based on the agreed incident reporting
process.
● Track agreed corrective and preventive actions to closure.
3. Privacy Awareness & Communication
● Support the rollout of Group privacy awareness programmes within Gamuda Land.
● Conduct practical awareness and training sessions for relevant GL employees and teams.
● Communicate Group privacy policies, requirements and good practices in simple business
language.
● Support targeted awareness for teams handling personal or sensitive data.
● Work with the Group DPO on communication materials and awareness initiatives where
required.
4. Data Governance – Secondary
● Support the implementation of Group data governance standards within Gamuda Land.
● Establish clear data ownership and stewardship within GL together with the relevant
business functions.
● Coordinate the identification and management of important or Critical Data Elements
(CDEs).
● Support data classification, retention, access and lifecycle requirements.
● Maintain relevant GL data inventories, data definitions and business glossaries where
required.
● Work with Data Owners and Data Stewards to identify and address data quality issues.
● Monitor agreed data governance actions and report significant gaps.
5. Master Data Management (MDM) – Secondary
● Support the progressive establishment of MDM practices within Gamuda Land.
● Work with business and IT teams to identify important master data across key platforms.
● Coordinate common definitions, ownership, standards and business rules for master data.
● Identify data inconsistencies across systems and work with the relevant Data Owners and
system teams on remediation.
● Support initiatives aimed at improving the consistency, accuracy and reliability of key
business data.
● Ensure MDM initiatives are aligned with Group data governance direction where applicable.
6. Digital & IT Governance Support
● Embed Privacy by Design into the SDLC, project lifecycle and major technology changes.
● Work with IT and Information Security to ensure appropriate safeguards including
least-privilege access, encryption, retention and secure deletion are implemented.
● Coordinate periodic reviews of access to systems containing personal or sensitive data.
● Maintain visibility of relevant IT assets and systems processing personal data, working with
the respective IT asset/system owners.
● Track privacy, data protection and related audit findings and coordinate remediation with the
responsible owners through to closure.
● Support third-party technology and vendor assessments from a privacy and data protection
perspective.
7. Group DPO & Stakeholder Coordination
● Maintain regular working communication with the Group DPO.
● Participate in Group DPO / Sub-DPO meetings and governance activities.
● Provide GL updates, information and supporting evidence requested under the agreed
operating model.
● Escalate matters requiring Group-level interpretation, policy direction or regulatory guidance
to the Group DPO.
● Coordinate with Legal, Risk, Compliance, Information Security, IT and business functions
where required.
● Provide management with clear updates on significant privacy risks, outstanding actions and
areas requiring attention.
Key Skills & Competencies
● Data Protection & Privacy
● Practical understanding of personal data / PII requirements
● Privacy risk and impact assessment
● Data incident coordination
● Data Governance
● Data ownership and stewardship
● Data classification and lifecycle management
● Data quality management
● Basic to intermediate Master Data Management (MDM)
● Understanding of enterprise systems and digital platforms
● Risk and compliance awareness
● Strong stakeholder coordination
● Good documentation and follow-up discipline
● Training and awareness facilitation
● Ability to communicate governance requirements in simple business language
● Ability to work across Business, IT, Legal, Risk, Compliance and Information Security
Qualifications & Experience
● Bachelor's degree in Information Systems, Data Management, Computer Science, Business,
Risk Management, Law or a related discipline.
● Around 5–7 years of relevant experience in data protection, privacy, data governance, risk,
compliance, enterprise data management or related areas.
● Practical experience implementing privacy, governance or compliance requirements within a business or technology environment.
● Experience working with IT systems, digital platforms and business stakeholders.
● Experience coordinating assessments, audits, incidents or remediation activities.
● Experience in Data Governance or MDM will be an advantage.
● Strong communication and stakeholder management skills.
Preferred Certifications
● CIPP / CIPM or equivalent privacy certification
● DAMA CDMP or equivalent data management certification
● COBIT, ISO 27001 or other relevant governance certification
More Info
Key Skills
Stakeholder coordination
Privacy risk and impact assessment
Data quality management
Data classification and lifecycle management
Risk and compliance awareness
Training and awareness facilitation
Data ownership and stewardship
Documentation and follow-up discipline
Data incident coordination
Data Protection Privacy
Understanding of enterprise systems and digital platforms
