Position Summary
Rajah & Tann Asia is seeking an experienced and commercially minded Data Governance Officer to lead and oversee the firm's regional data governance, data protection and data management initiatives across its network of offices in ASEAN and China.
The successful candidate will develop and maintain a robust governance framework to ensure that the firm's collection, storage, use, sharing, retention and transfer of data are secure, compliant, ethical and aligned with business objectives.
The role will work closely with Legal, Compliance, Technology, Cybersecurity, Risk Management, Information Security, Knowledge Management and business stakeholders to support the firm's digital transformation and regional data-sharing initiatives. The role will also provide governance oversight over the use of artificial intelligence, cloud solutions and other emerging technologies.
Key Responsibilities
1. Data Protection and Regulatory Compliance
- Develop and maintain the firm's regional data protection compliance framework covering client, employee and business data.
- Monitor relevant data protection, privacy, confidentiality and cybersecurity requirements across the jurisdictions in which Rajah & Tann Asia operates.
- Conduct data protection risk assessments and compliance reviews, and support the implementation of privacy-by-design principles.
- Develop and maintain policies and procedures relating to data protection, client confidentiality, information classification, data handling, retention and acceptable use.
- Lead and coordinate responses to data incidents and breaches, including investigations, regulatory notifications, remediation and post-incident reviews.
- Develop and deliver regional data protection and information-governance training and awareness programmes.
2. Enterprise Data Governance
- Develop and implement a firm-wide Data Governance Framework, including appropriate governance structures, reporting mechanisms and accountability for key data assets.
- Establish standards for data quality, integrity, classification, consistency and lifecycle management.
- Maintain appropriate data inventories and records of processing activities.
- Oversee the classification and handling of client, matter-related, employee, financial, confidential and regulated data.
- Promote data stewardship and coordinate remediation of identified data-quality or governance issues.
- Provide regular reporting to senior management on material data risks, compliance developments and governance initiatives.
3. Data Use, AI and Technology Governance
- Provide governance oversight over the appropriate use of firm data in artificial intelligence tools, analytics platforms, knowledge-management systems and data-sharing initiatives.
- Advise on data governance requirements for new technologies, cloud solutions, third-party platforms and digital-transformation projects.
- Work with Technology, Information Security, Legal and Risk stakeholders to ensure that appropriate contractual, organisational and technical controls are in place.
- Support assessments relating to new systems, vendors and technology-enabled business initiatives.
4. Information Lifecycle Management
- Oversee data and records retention and disposal programmes.
- Ensure that records are retained in accordance with applicable legal, regulatory, professional and client requirements.
- Establish appropriate processes for the secure and defensible disposal of data and records when they are no longer required.
5. Cross-Border Data Governance
- Develop and maintain a regional framework for the transfer of personal, client and firm information between offices and external parties.
- Assess data-transfer risks arising from regional shared services, cloud deployments, outsourcing arrangements, AI platforms and client-directed transfers.
- Develop appropriate transfer mechanisms, safeguards and supporting documentation.
- Coordinate with local offices and relevant stakeholders on cross-jurisdictional data matters and regulatory enquiries.
- Monitor relevant developments in China's data protection, cybersecurity, data localisation and cross-border transfer requirements.
Requirements
- Degree in Law, Information Governance, Information Management, Computer Science, Cybersecurity, Business, Data Analytics or a related discipline.
- At least 7 to 10 years of relevant experience in data governance, privacy, information management, compliance or cybersecurity.
- Demonstrated experience developing and implementing data governance or regulatory compliance programmes.
- Experience working across multiple jurisdictions, preferably within ASEAN and China.
- Experience in a professional-services, legal, financial-services or other highly regulated environment would be advantageous.
- Familiarity with Microsoft 365, document-management systems, cloud environments, AI-enabled tools and data-governance technologies.
Professional Certifications
Relevant professional certifications would be advantageous, including:
- Certified Information Privacy Professional (CIPP)
- Certified Information Privacy Manager (CIPM)
- Certified Information Privacy Technologist (CIPT)
- Certified Data Management Professional (CDMP)
- ISO 27001 Implementer or Auditor
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
Core Competencies
- Strong knowledge of data governance, data protection and information-lifecycle principles.
- Ability to translate regulatory and technical requirements into practical and proportionate business controls.
- Strong policy-development, analytical and problem-solving capabilities.
- Excellent stakeholder-management and influencing skills.
- Ability to work effectively with senior management, regional offices and multidisciplinary teams.
- Strong written and verbal communication skills.
- Sound judgement, integrity and the ability to handle sensitive and confidential information.