Manager - Data Protection, Privacy & Data Governance

GAMUDA LAND

Petaling Jaya

On-site

MYR 120,000 - 180,000

Full time

44 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Gamuda Land seeks a Sub-Data Protection Officer (IT) to implement and coordinate data protection, privacy and data governance across IT systems and platforms. You will work with the Group DPO to translate Group policies into workable controls for Gamuda Land, maintain RoPA, conduct privacy reviews and DPIAs, and escalate issues requiring Group guidance.

You will also lead privacy awareness activities, support governance and master data management initiatives, and partner with IT, legal and risk

Qualifications

  • Experience implementing privacy, governance or compliance requirements within a business or technology environment.
  • Practical understanding of personal data/PII requirements.
  • Knowledge of privacy laws and regulatory expectations.

Responsibilities

  • Work with Group DPO to implement Group data protection and privacy requirements within Gamuda Land.
  • Act as Sub-DPO (IT) contact for privacy and data protection relating to IT systems and data.
  • Coordinate privacy reviews and DPIAs for projects involving personal data.
  • Maintain RoPA and other privacy records for GL IT systems and platforms.
  • Coordinate data-flow mapping and privacy assessments; escalate significant privacy risks.

Skills

Privacy by design
DPIA coordination
RoPA maintenance
Data protection
Stakeholder management
Privacy awareness
IT systems

Education

Bachelor's degree in IS/CS/Data Management/Law

Job description

The role supports the implementation and day-to-day coordination of data protection, privacy and

data governance requirements within Gamuda Land, in alignment with Group policies and direction.

As Sub-Data Protection Officer (IT) for Gamuda Land, the role works closely with the Group DPO

and serves as the key coordination point for data protection and privacy matters relating to IT, digital

platforms, systems and data.

The primary responsibility is to operationalise Group data protection and privacy requirements within

Gamuda Land, coordinate implementation across the relevant stakeholders, monitor compliance

and elevate matters requiring Group-level direction to the Group DPO.

Data Protection and Privacy will be the primary focus, while Data Governance and Master Data

Management (MDM) will be progressively developed as a secondary capability within Gamuda

Land.

Key Responsibilities
  • Data Protection & Privacy – Primary
  • Work closely with the Group DPO to understand and implement Group data protection and privacy requirements within Gamuda Land.
  • Act as the key Sub-DPO (IT) contact for privacy and data protection matters relating to IT systems, digital platforms and data.
  • Support the implementation of Group data protection and privacy policies within Gamuda Land.
  • Apply Privacy by Design principles when introducing new systems, digital initiatives or major system changes.
  • Coordinate privacy reviews and Data Protection Impact Assessments (DPIAs) for projects and systems involving personal data, where required.
  • Identify privacy risks or gaps and work with the relevant business, IT, Information Security and control functions to address them.
  • Support privacy and data protection reviews of third-party vendors and technology service providers.
  • Maintain relevant Records of Processing Activities (RoPA) and other required privacy records for GL IT systems and digital platforms.
  • Maintain or coordinate data-flow mapping to understand how personal data is collected, used, shared, stored, retained and disposed of.
  • Maintain privacy assessments, action items and supporting documents for audit and compliance purposes.
  • Support internal and external audits relating to data protection and privacy.
  • Track agreed actions and follow up with the responsible owners until they are completed.
  • Escalate significant privacy risks, incidents or matters requiring further guidance to the Group DPO.
  • Act as the GL Sub-DPO (IT) coordination point when a potential data privacy incident is identified.
  • Work with IT and Information Security on technical investigation, containment and remediation.
  • Work with the relevant business owner to understand the affected data, process and business impact.
  • Gather and document the necessary facts for privacy assessment.
  • Coordinate the privacy and governance assessment with the Group DPO.
  • Escalate potential data breaches to the Group DPO based on the agreed incident reporting process.
  • Track agreed corrective and preventive actions to closure.
3. Privacy Awareness & Communication
  • Support the rollout of Group privacy awareness programmes within Gamuda Land.
  • Conduct practical awareness and training sessions for relevant GL employees and teams.
  • Communicate Group privacy policies, requirements and good practices in simple business language.
  • Support targeted awareness for teams handling personal or sensitive data.
  • Work with the Group DPO on communication materials and awareness initiatives where required.
4. Data Governance – Secondary
  • Support the implementation of Group data governance standards within Gamuda Land.
  • Establish clear data ownership and stewardship within GL together with the relevant business functions.
  • Coordinate the identification and management of important or Critical Data Elements
  • Support data classification, retention, access and lifecycle requirements.
  • Maintain relevant GL data inventories, data definitions and business glossaries where required.
  • Work with Data Owners and Data Stewards to identify and address data quality issues.
  • Monitor agreed data governance actions and report significant gaps.
5. Master Data Management (MDM) – Secondary
  • Support the progressive establishment of MDM practices within Gamuda Land.
  • Work with business and IT teams to identify important master data across key platforms.
  • Coordinate common definitions, ownership, standards and business rules for master data.
  • Identify data inconsistencies across systems and work with the relevant Data Owners and
  • Support initiatives aimed at improving the consistency, accuracy and reliability of key
  • Ensure MDM initiatives are aligned with Group data governance direction where applicable.
6. Digital & IT Governance Support
  • Embed Privacy by Design into the SDLC, project lifecycle and major technology changes.
  • Work with IT and Information Security to ensure appropriate safeguards including least-privilege access, encryption, retention and secure deletion are implemented.
  • Coordinate periodic reviews of access to systems containing personal or sensitive data.
  • Maintain visibility of relevant IT assets and systems processing personal data, working with the respective IT asset/system owners.
  • Track privacy, data protection and related audit findings and coordinate remediation with the responsible owners through to closure.
  • Support third-party technology and vendor assessments from a privacy and data protection perspective.
7. Group DPO & Stakeholder Coordination
  • Maintain regular working communication with the Group DPO.
  • Participate in Group DPO / Sub-DPO meetings and governance activities.
  • Provide GL updates, information and supporting evidence requested under the agreed operating model.
  • Escalate matters requiring Group-level interpretation, policy direction or regulatory guidance to the Group DPO.
  • Coordinate with Legal, Risk, Compliance, Information Security, IT and business functions where required.
  • Provide management with clear updates on significant privacy risks, outstanding actions and areas requiring attention.
  • Practical understanding of personal data / PII requirements
  • Privacy risk and impact assessment
  • Data ownership and stewardship
  • Data classification and lifecycle management
  • Basic to intermediate Master Data Management (MDM)
  • Understanding of enterprise systems and digital platforms
  • Risk and compliance awareness
  • Good documentation and follow-up discipline
  • Training and awareness facilitation
    Qualifications & Experience
    • Bachelor's degree in Information Systems, Data Management, Computer Science, Business, Risk Management, Law or a related discipline.
    • Around 5–7 years of relevant experience in data protection, privacy, data governance, risk, compliance, enterprise data management or related areas.
    • Practical experience implementing privacy, governance or compliance requirements within a business or technology environment.
    • Experience working with IT systems, digital platforms and business stakeholders.
    • Experience coordinating assessments, audits, incidents or remediation activities.
    • Experience in Data Governance or MDM will be an advantage.
    • Strong communication and stakeholder management skills.
    Preferred Certifications
    • CIPP / CIPM or equivalent privacy certification
    • DAMA CDMP or equivalent data management certification
    • COBIT, ISO 27001 or other relevant governance certification
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Data Protection & Privacy Lead — IT & Governance
Data Protection & Privacy Lead — IT & Governance

GAMUDA LAND • Petaling Jaya

On-site
MYR 120,000 - 180,000
Senior Executive - Data & Digital Governance
Senior Executive - Data & Digital Governance

Gamuda Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
Senior Executive - Data & Digital Governance
Senior Executive - Data & Digital Governance

GAMUDA • Petaling Jaya

On-site
MYR 120,000 - 180,000
Data Privacy Officer
Data Privacy Officer

Businesslist • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Medical benefits
Senior Data & Privacy Governance Lead
Senior Data & Privacy Governance Lead

GAMUDA • Petaling Jaya

On-site
MYR 120,000 - 180,000
Data Protection Officer, Principal
Data Protection Officer, Principal

AIA Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 280,000
Data Protection Manager
Data Protection Manager

Hong Leong Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Specialist, Data Protection Risk & Compliance
Specialist, Data Protection Risk & Compliance

Averis • Kuala Lumpur

On-site
MYR 60,000 - 90,000
Data & Privacy Governance Lead
Data & Privacy Governance Lead

Gamuda Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
ASSISTANT MANAGER- DATA PRIVACY & GOVERNANCE
ASSISTANT MANAGER- DATA PRIVACY & GOVERNANCE

JAYA GROCER • Malaysia

On-site
MYR 80,000 - 120,000