Data Protection Officer / Head of Legal & Compliance
About the Role
We are seeking a high-impact, dynamic leader to head the Legal, Compliance, and Data Protection. This role goes beyond traditional legal risk management, requiring an individual who can drive enterprise-wide compliance culture, influence business strategy, and scale governance frameworks across a growing, complex organization.
The successful candidate will serve as a strategic partner to senior leadership, ensuring not only regulatory adherence but also embedding a proactive, business-aligned, and future-ready compliance mindset across all levels of the organization.
This position requires a strong command of Philippine laws and global compliance standards, combined with the ability to lead transformation, enhance organizational maturity, and support evolving business needs at scale.
Key Responsibilities
1. Legal & Regulatory Leadership
- Ensure full compliance with Philippine laws and applicable global regulatory frameworks, including data privacy, corporate governance, labor, and financial regulations
- Provide forward-looking legal guidance aligned with business growth, transformation, and expansion initiatives
- Oversee contract management, legal advisory, and dispute resolution while mitigating organizational risk exposure
- Manage corporate governance activities in coordination with global legal stakeholders
- Represent the organization in legal proceedings and regulatory discussions, as required
2. Enterprise Compliance & Risk Transformation
- Design and implement scalable, future-ready compliance frameworks that support organizational growth and complexity
- Lead enterprise-wide risk identification and mitigation strategies, balancing regulatory requirements with business agility
- Go beyond compliance enforcement by driving a culture of accountability, ethics, and data responsibility
- Oversee key programs including data privacy, anti-bribery, ethics, and whistleblower mechanisms
- Establish and enhance metrics, dashboards, and reporting structures to provide actionable insights to leadership
3. Culture Building & Organizational Impact
- Champion a compliance-first mindset by embedding legal and ethical standards into day-to-day business operations
- Drive awareness, training, and leadership engagement programs to elevate compliance maturity across the organization
- Influence senior stakeholders to integrate risk and compliance considerations into strategic decision-making
- Act as a change agent, enabling the organization to evolve from reactive compliance to proactive governance and cultural integration
- Serve as the designated Data Protection Officer (DPO), ensuring adherence to the Data Privacy Act and related regulations
- Act as the primary liaison with the National Privacy Commission and other regulatory bodies
- Develop and enforce robust data governance, privacy, and security frameworks
- Lead incident response, data breach management, and regulatory reporting as required
5. Stakeholder & Global Collaboration
- Partner with HR, Finance, Operations, and global teams to ensure alignment of legal and compliance strategies
- Serve as a trusted advisor to executive leadership on business-critical legal and compliance matters
- Manage relationships with external counsel, regulators, and government agencies
- Support global compliance initiatives and ensure local execution aligns with enterprise standards
6. Leadership & Capability Building
- Build, lead, and develop a high-performing legal and compliance organization
- Strengthen internal capabilities to support long-term program maturity and scalability
- Manage legal budgets, vendor partnerships, and external legal resources effectively
Qualifications
- Preferably a Juris Doctor or Bachelor of Laws, but not a must.
- Minimum 10+ years of progressive experience in legal, compliance, regulatory, and data privacy functions within multinational or complex organizations.
- Demonstrated experience driving enterprise-wide compliance, governance, risk management, and culture-building initiatives.
- Strong knowledge of Philippine legal frameworks, including the Data Privacy Act and related regulations.
- Proven ability to influence senior stakeholders and operate at a strategic leadership level.
- Experience scaling compliance programs across growing or evolving organizations is highly preferred.
- Must have healthcare industry experience, preferably within a Healthcare BPO, Shared Services, Global Capability Center (GCC), Captive, or healthcare services environment, with direct exposure to healthcare regulatory, compliance, legal, and data privacy requirements.
Preferred Background
- Healthcare industry background is required; Healthcare BPO or Healthcare Shared Services experience is strongly preferred.
- Experience supporting healthcare compliance, privacy, governance, and regulatory frameworks within a highly regulated environment.
- Experience working in global or matrix organizations.
- Familiarity with US healthcare regulatory environments, healthcare data privacy requirements, and multinational governance frameworks is an advantage.
Why Join Us
This is an opportunity to play a strategic leadership role, shaping not only compliance and legal frameworks but also the organizational culture and future direction of the business.