Manager - Data Protection, Privacy & Data Governance
GAMUDA LAND · Damansara, Selangor, Malaysia
Apply & track with Apply EdgeJob SummaryThe role supports the implementation and day-to-day coordination of data protection, privacy anddata governance requirements within Gamuda Land, in alignment with Group policies and direction.As Sub-Data Protection Officer (IT) for Gamuda Land, the role works closely with the Group DPOand serves as the key coordination point for data protection and privacy matters relating to IT, digitalplatforms, systems and data.The primary responsibility is to operationalise Group data protection and privacy requirements withinGamuda Land, coordinate implementation across the relevant stakeholders, monitor complianceand escalate matters requiring Group-level direction to the Group DPO.Data Protection and Privacy will be the primary focus, while Data Governance and Master DataManagement (MDM) will be progressively developed as a secondary capability within GamudaLand.Key ResponsibilitiesData Protection & Privacy – Primary● Work closely with the Group DPO to understand and implement Group data protection andprivacy requirements within Gamuda Land.● Act as the key Sub-DPO (IT) contact for privacy and data protection matters relating to ITsystems, digital platforms and data.● Support the implementation of Group data protection and privacy policies within GamudaLand.● Apply Privacy by Design principles when introducing new systems, digital initiatives or majorsystem changes.● Coordinate privacy reviews and Data Protection Impact Assessments (DPIAs) for projectsand systems involving personal data, where required.● Identify privacy risks or gaps and work with the relevant business, IT, Information Securityand control functions to address them.● Support privacy and data protection reviews of third-party vendors and technology serviceproviders.● Maintain relevant Records of Processing Activities (RoPA) and other required privacyrecords for GL IT systems and digital platforms.● Maintain or coordinate data-flow mapping to understand how personal data is collected,used, shared, stored, retained and disposed of.● Maintain privacy assessments, action items and supporting documents for audit andcompliance purposes.● Support internal and external audits relating to data protection and privacy.● Track agreed actions and follow up with the responsible owners until they are completed.● Escalate significant privacy risks, incidents or matters requiring further guidance to theGroup DPO.2. Data Incident Coordination● Act as the GL Sub-DPO (IT) coordination point when a potential data privacy incident isidentified.● Work with IT and Information Security on technical investigation, containment andremediation.● Work with the relevant business owner to understand the affected data, process andbusiness impact.● Gather and document the necessary facts for privacy assessment.● Coordinate the privacy and governance assessment with the Group DPO.● Escalate potential data breaches to the Group DPO based on the agreed incident reportingprocess.● Track agreed corrective and preventive actions to closure.3. Privacy Awareness & Communication● Support the rollout of Group privacy awareness programmes within Gamuda Land.● Conduct practical awareness and training sessions for relevant GL employees and teams.● Communicate Group privacy policies, requirements and good practices in simple businesslanguage.● Support targeted awareness for teams handling personal or sensitive data.● Work with the Group DPO on communication materials and awareness initiatives whererequired.4. Data Governance – Secondary● Support the implementation of Group data governance standards within Gamuda Land.● Establish clear data ownership and stewardship within GL together with the relevantbusiness functions.● Coordinate the identification and management of important or Critical Data Elements(CDEs).● Support data classification, retention, access and lifecycle requirements.● Maintain relevant GL data inventories, data definitions and business glossaries whererequired.● Work with Data Owners and Data Stewards to identify and address data quality issues.● Monitor agreed data governance actions and report significant gaps.5. Master Data Management (MDM) – Secondary● Support the progressive establishment of MDM practices within Gamuda Land.● Work with business and IT teams to identify important master data across key platforms.● Coordinate common definitions, ownership, standards and business rules for master data.● Identify data inconsistencies across systems and work with the relevant Data Owners andsystem teams on remediation.● Support initiatives aimed at improving the consistency, accuracy and reliability of keybusiness data.● Ensure MDM initiatives are aligned with Group data governance direction where applicable.6. Digital & IT Governance Support● Embed Privacy by Design into the SDLC, project lifecycle and major technology changes.● Work with IT and Information Security to ensure appropriate safeguards includingleast-privilege access, encryption, retention and secure deletion are implemented.● Coordinate periodic reviews of access to systems containing personal or sensitive data.● Maintain visibility of relevant IT assets and systems processing personal data, working withthe respective IT asset/system owners.● Track privacy, data protection and related audit findings and coordinate remediation with theresponsible owners through to closure.● Support third-party technology and vendor assessments from a privacy and data protectionperspective.7. Group DPO & Stakeholder Coordination● Maintain regular working communication with the Group DPO.● Participate in Group DPO / Sub-DPO meetings and governance activities.● Provide GL updates, information and supporting evidence requested under the agreedoperating model.● Escalate matters requiring Group-level interpretation, policy direction or regulatory guidanceto the Group DPO.● Coordinate with Legal, Risk, Compliance, Information Security, IT and business functionswhere required.● Provide management with clear updates on significant privacy risks, outstanding actions andareas requiring attention.Key Skills & Competencies● Data Protection & Privacy● Practical understanding of personal data / PII requirements● Privacy risk and impact assessment● Data incident coordination● Data Governance● Data ownership and stewardship● Data classification and lifecycle management● Data quality management● Basic to intermediate Master Data Management (MDM)● Understanding of enterprise systems and digital platforms● Risk and compliance awareness● Strong stakeholder coordination● Good documentation and follow-up discipline● Training and awareness facilitation● Ability to communicate governance requirements in simple business language● Ability to work across Business, IT, Legal, Risk, Compliance and Information SecurityQualifications & Experience● Bachelor's degree in Information Systems, Data Management, Computer Science, Business,Risk Management, Law or a related discipline.● Around 5–7 years of relevant experience in data protection, privacy, data governance, risk,compliance, enterprise data management or related areas.● Practical experience implementing privacy, governance or compliance requirements within a business or technology environment.● Experience working with IT systems, digital platforms and business stakeholders.● Experience coordinating assessments, audits, incidents or remediation activities.● Experience in Data Governance or MDM will be an advantage.● Strong communication and stakeholder management skills.Preferred Certifications● CIPP / CIPM or equivalent privacy certification● DAMA CDMP or equivalent data management certification● COBIT, ISO 27001 or other relevant governance certification