Job Purpose :
We are seeking a highly skilled and experienced Data Protection Officer (DPO) to join our team. The DPO will be responsible for overseeing and ensuring the compliance of CGSS with applicable data protection regulations, including GDPR and the Malaysian Personal Data Protection Act. This role involves regular support and consultation for sourcing initiatives during the transition phase concerning GDPR requirements, and acting as the main point of contact at CGSS for the Commerzbank Data Protection Officer on data protection matters.
Key Activities :
- Oversee compliance with EU General Data Protection Regulation (GDPR), the Malaysian Personal Data Protection Act, and other applicable data protection regulations or global policies.
- Provide expert support and consultation for sourcing initiatives during the transition phase to ensure GDPR requirements are met.
- Act as the main contact at CGSS for the Commerzbank Data Protection Officer (DPO) on all data protection matters, ensuring seamless communication and alignment.
- Develop, implement, and maintain data protection policies, procedures, and best practices within CGSS.
- Conduct regular audits and assessments to monitor compliance and identify potential risks related to data protection.
- Lead and coordinate data protection impact assessments (DPIAs) where necessary.
- Handle inquiries and concerns related to data privacy and protection from internal stakeholders and external customers.
- Facilitate data protection training and awareness programs for CGSS employees.
- Respond to and manage data breaches, including the coordination of investigations and reporting to relevant authorities.
- Stay updated on developments within data protection laws and regulations, advising on necessary adaptations to CGSS policies and practices.
- Ensure data protection compliance for data subject rights requests (e.g. including user access, rectification).
Formal Education :
University degree in Law, Data Protection, Information Security, or a related fieldProfessional certification in data protection is a plus.Specialist Knowledge :
Minimum of
5 years of experience
in data protection and privacy management including experience the Malaysian Personal Data Protection Act and ideally as well with GDPR.
Detailed Requirements for each career level (each Functional Level separately)
Strong understanding of data protection laws, regulations, standards, and best practices.Excellent communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels.Proven track record in managing data protection compliance and handling data subject rights requests.Ability to work independently, prioritize tasks, and manage time effectively.Strong analytical and problem-solving skills.High ethical standards and a commitment to maintaining confidentiality and integrity.