Search by job, company or skills

Manager - Data Protection, Privacy & Data Governance

Manager - Data Protection, Privacy & Data Governance

gamuda land
5-7 Years
Not Disclosed
  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

Job Summary

The role supports the implementation and day-to-day coordination of data protection, privacy and

data governance requirements within Gamuda Land, in alignment with Group policies and direction.

As Sub-Data Protection Officer (IT) for Gamuda Land, the role works closely with the Group DPO

and serves as the key coordination point for data protection and privacy matters relating to IT, digital

platforms, systems and data.

The primary responsibility is to operationalise Group data protection and privacy requirements within

Gamuda Land, coordinate implementation across the relevant stakeholders, monitor compliance

and escalate matters requiring Group-level direction to the Group DPO.

Data Protection and Privacy will be the primary focus, while Data Governance and Master Data

Management (MDM) will be progressively developed as a secondary capability within Gamuda

Land.

Key Responsibilities

  1. Data Protection & Privacy – Primary

● Work closely with the Group DPO to understand and implement Group data protection and

privacy requirements within Gamuda Land.

● Act as the key Sub-DPO (IT) contact for privacy and data protection matters relating to IT

systems, digital platforms and data.

● Support the implementation of Group data protection and privacy policies within Gamuda

Land.

● Apply Privacy by Design principles when introducing new systems, digital initiatives or major

system changes.

● Coordinate privacy reviews and Data Protection Impact Assessments (DPIAs) for projects

and systems involving personal data, where required.

● Identify privacy risks or gaps and work with the relevant business, IT, Information Security

and control functions to address them.

● Support privacy and data protection reviews of third-party vendors and technology service

providers.

● Maintain relevant Records of Processing Activities (RoPA) and other required privacy

records for GL IT systems and digital platforms.

● Maintain or coordinate data-flow mapping to understand how personal data is collected,

used, shared, stored, retained and disposed of.

● Maintain privacy assessments, action items and supporting documents for audit and

compliance purposes.

● Support internal and external audits relating to data protection and privacy.

● Track agreed actions and follow up with the responsible owners until they are completed.

● Escalate significant privacy risks, incidents or matters requiring further guidance to the

Group DPO.

2. Data Incident Coordination

● Act as the GL Sub-DPO (IT) coordination point when a potential data privacy incident is

identified.

● Work with IT and Information Security on technical investigation, containment and

remediation.

● Work with the relevant business owner to understand the affected data, process and

business impact.

● Gather and document the necessary facts for privacy assessment.

● Coordinate the privacy and governance assessment with the Group DPO.

● Escalate potential data breaches to the Group DPO based on the agreed incident reporting

process.

● Track agreed corrective and preventive actions to closure.

3. Privacy Awareness & Communication

● Support the rollout of Group privacy awareness programmes within Gamuda Land.

● Conduct practical awareness and training sessions for relevant GL employees and teams.

● Communicate Group privacy policies, requirements and good practices in simple business

language.

● Support targeted awareness for teams handling personal or sensitive data.

● Work with the Group DPO on communication materials and awareness initiatives where

required.

4. Data Governance – Secondary

● Support the implementation of Group data governance standards within Gamuda Land.

● Establish clear data ownership and stewardship within GL together with the relevant

business functions.

● Coordinate the identification and management of important or Critical Data Elements

(CDEs).

● Support data classification, retention, access and lifecycle requirements.

● Maintain relevant GL data inventories, data definitions and business glossaries where

required.

● Work with Data Owners and Data Stewards to identify and address data quality issues.

● Monitor agreed data governance actions and report significant gaps.

5. Master Data Management (MDM) – Secondary

● Support the progressive establishment of MDM practices within Gamuda Land.

● Work with business and IT teams to identify important master data across key platforms.

● Coordinate common definitions, ownership, standards and business rules for master data.

● Identify data inconsistencies across systems and work with the relevant Data Owners and

system teams on remediation.

● Support initiatives aimed at improving the consistency, accuracy and reliability of key

business data.

● Ensure MDM initiatives are aligned with Group data governance direction where applicable.

6. Digital & IT Governance Support

● Embed Privacy by Design into the SDLC, project lifecycle and major technology changes.

● Work with IT and Information Security to ensure appropriate safeguards including

least-privilege access, encryption, retention and secure deletion are implemented.

● Coordinate periodic reviews of access to systems containing personal or sensitive data.

● Maintain visibility of relevant IT assets and systems processing personal data, working with

the respective IT asset/system owners.

● Track privacy, data protection and related audit findings and coordinate remediation with the

responsible owners through to closure.

● Support third-party technology and vendor assessments from a privacy and data protection

perspective.

7. Group DPO & Stakeholder Coordination

● Maintain regular working communication with the Group DPO.

● Participate in Group DPO / Sub-DPO meetings and governance activities.

● Provide GL updates, information and supporting evidence requested under the agreed

operating model.

● Escalate matters requiring Group-level interpretation, policy direction or regulatory guidance

to the Group DPO.

● Coordinate with Legal, Risk, Compliance, Information Security, IT and business functions

where required.

● Provide management with clear updates on significant privacy risks, outstanding actions and

areas requiring attention.

Key Skills & Competencies

● Data Protection & Privacy

● Practical understanding of personal data / PII requirements

● Privacy risk and impact assessment

● Data incident coordination

● Data Governance

● Data ownership and stewardship

● Data classification and lifecycle management

● Data quality management

● Basic to intermediate Master Data Management (MDM)

● Understanding of enterprise systems and digital platforms

● Risk and compliance awareness

● Strong stakeholder coordination

● Good documentation and follow-up discipline

● Training and awareness facilitation

● Ability to communicate governance requirements in simple business language

● Ability to work across Business, IT, Legal, Risk, Compliance and Information Security

Qualifications & Experience

● Bachelor's degree in Information Systems, Data Management, Computer Science, Business,

Risk Management, Law or a related discipline.

● Around 5–7 years of relevant experience in data protection, privacy, data governance, risk,

compliance, enterprise data management or related areas.

● Practical experience implementing privacy, governance or compliance requirements within a business or technology environment.

● Experience working with IT systems, digital platforms and business stakeholders.

● Experience coordinating assessments, audits, incidents or remediation activities.

● Experience in Data Governance or MDM will be an advantage.

● Strong communication and stakeholder management skills.

Preferred Certifications

● CIPP / CIPM or equivalent privacy certification

● DAMA CDMP or equivalent data management certification

● COBIT, ISO 27001 or other relevant governance certification

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Stakeholder coordination

Privacy risk and impact assessment

Data quality management

Data classification and lifecycle management

Risk and compliance awareness

Training and awareness facilitation

Data ownership and stewardship

Documentation and follow-up discipline

Data incident coordination

Data Protection Privacy

Understanding of enterprise systems and digital platforms

About Company