The role supports the implementation and day-to-day coordination of data protection, privacy and
data governance requirements within Gamuda Land, in alignment with Group policies and direction.
As Sub-Data Protection Officer (IT) for Gamuda Land, the role works closely with the Group DPO
and serves as the key coordination point for data protection and privacy matters relating to IT, digital
platforms, systems and data.
The primary responsibility is to operationalise Group data protection and privacy requirements within
Gamuda Land, coordinate implementation across the relevant stakeholders, monitor compliance
and elevate matters requiring Group-level direction to the Group DPO.
Data Protection and Privacy will be the primary focus, while Data Governance and Master Data
Management (MDM) will be progressively developed as a secondary capability within Gamuda
Land.
Key Responsibilities
- Data Protection & Privacy – Primary
- Work closely with the Group DPO to understand and implement Group data protection and privacy requirements within Gamuda Land.
- Act as the key Sub-DPO (IT) contact for privacy and data protection matters relating to IT systems, digital platforms and data.
- Support the implementation of Group data protection and privacy policies within Gamuda Land.
- Apply Privacy by Design principles when introducing new systems, digital initiatives or major system changes.
- Coordinate privacy reviews and Data Protection Impact Assessments (DPIAs) for projects and systems involving personal data, where required.
- Identify privacy risks or gaps and work with the relevant business, IT, Information Security and control functions to address them.
- Support privacy and data protection reviews of third-party vendors and technology service providers.
- Maintain relevant Records of Processing Activities (RoPA) and other required privacy records for GL IT systems and digital platforms.
- Maintain or coordinate data-flow mapping to understand how personal data is collected, used, shared, stored, retained and disposed of.
- Maintain privacy assessments, action items and supporting documents for audit and compliance purposes.
- Support internal and external audits relating to data protection and privacy.
- Track agreed actions and follow up with the responsible owners until they are completed.
- Escalate significant privacy risks, incidents or matters requiring further guidance to the Group DPO.
- Act as the GL Sub-DPO (IT) coordination point when a potential data privacy incident is identified.
- Work with IT and Information Security on technical investigation, containment and remediation.
- Work with the relevant business owner to understand the affected data, process and business impact.
- Gather and document the necessary facts for privacy assessment.
- Coordinate the privacy and governance assessment with the Group DPO.
- Escalate potential data breaches to the Group DPO based on the agreed incident reporting process.
- Track agreed corrective and preventive actions to closure.
3. Privacy Awareness & Communication
- Support the rollout of Group privacy awareness programmes within Gamuda Land.
- Conduct practical awareness and training sessions for relevant GL employees and teams.
- Communicate Group privacy policies, requirements and good practices in simple business language.
- Support targeted awareness for teams handling personal or sensitive data.
- Work with the Group DPO on communication materials and awareness initiatives where required.
4. Data Governance – Secondary
- Support the implementation of Group data governance standards within Gamuda Land.
- Establish clear data ownership and stewardship within GL together with the relevant business functions.
- Coordinate the identification and management of important or Critical Data Elements
- Support data classification, retention, access and lifecycle requirements.
- Maintain relevant GL data inventories, data definitions and business glossaries where required.
- Work with Data Owners and Data Stewards to identify and address data quality issues.
- Monitor agreed data governance actions and report significant gaps.
5. Master Data Management (MDM) – Secondary
- Support the progressive establishment of MDM practices within Gamuda Land.
- Work with business and IT teams to identify important master data across key platforms.
- Coordinate common definitions, ownership, standards and business rules for master data.
- Identify data inconsistencies across systems and work with the relevant Data Owners and
- Support initiatives aimed at improving the consistency, accuracy and reliability of key
- Ensure MDM initiatives are aligned with Group data governance direction where applicable.
6. Digital & IT Governance Support
- Embed Privacy by Design into the SDLC, project lifecycle and major technology changes.
- Work with IT and Information Security to ensure appropriate safeguards including least-privilege access, encryption, retention and secure deletion are implemented.
- Coordinate periodic reviews of access to systems containing personal or sensitive data.
- Maintain visibility of relevant IT assets and systems processing personal data, working with the respective IT asset/system owners.
- Track privacy, data protection and related audit findings and coordinate remediation with the responsible owners through to closure.
- Support third-party technology and vendor assessments from a privacy and data protection perspective.
7. Group DPO & Stakeholder Coordination
- Maintain regular working communication with the Group DPO.
- Participate in Group DPO / Sub-DPO meetings and governance activities.
- Provide GL updates, information and supporting evidence requested under the agreed operating model.
- Escalate matters requiring Group-level interpretation, policy direction or regulatory guidance to the Group DPO.
- Coordinate with Legal, Risk, Compliance, Information Security, IT and business functions where required.
- Provide management with clear updates on significant privacy risks, outstanding actions and areas requiring attention.