Jora Malaysia will close on 9th September 2026. Thank you for being with us, we are cheering you on as you continue your career journey.
This is a Data Protection Officer (DPO) role responsible for ensuring compliance with Malaysia's Personal Data Protection Act 709 and other applicable data protection laws. The DPO will adopt a risk-based approach in assessing risks from processing operations, considering the nature, scope, context and purposes of the processing, and will coordinate and cooperate with relevant internal and external stakeholders as necessary.
Key responsibilities
- Lead and collaborate in the formulation of policies related to collection and processing of personally identifiable information, based on the Malaysia Personal Data Protection Act
- Implement and monitor the data privacy policies and associated processes across applicable functions and business units
- Advise business functions and delivery units regarding different laws, regulations and related instruments, as well as industry standards and certifications for ensuring adequate compliance with personal data protection requirements
- Create awareness and conduct training regarding the requirements under Act 709 applicable to personal data processing activities
- Collect information to identify the processing operations, activities, measures, policies or systems of the data controller or data processor and maintain a record thereof
- Advise and oversee the implementation of security measures to protect personal data from unauthorized access, disclosure, alteration or destruction, in line with both legal requirements and internal security policies
- Advise the business and delivery functions on the potential risks and impacts that may arise from business practices
- Assess the development and enhancements of internal processes and systems through Privacy Impact assessments and recommend privacy related controls
- Lead the data breach handling process for effective addressal of related privacy gaps reported in the current process and systems
- Manage the process related to personal data access requests from individuals
About you
- Minimum Degree or above in Law or related studies
- Minimum 5 years' experience in Data Privacy matters both as a Data controller and Data Processor
- Knowledge of the Malaysia Act 709, requirement under the law data protection practices in the country (including any other applicable data protection laws, where relevant)
- Understanding of the data controller or data processor's business operations and the personal data processing operations that are carried out
- Understanding of information technology and data security
- Excellent Communication skills to communicate to the regulators on behalf of company
- Personal qualities such as integrity, understanding of corporate governance and high professional ethics
- Ability to promote data protection culture within the organization
- Privacy and Security Certifications such as CIPP (US/EU/IT/Asia) or any other equivalent certifications are desired but not mandatory