Senior Privacy and Data Protection Advisor

Locations
Bangkok, Thailand / Bangsar South City, Malaysia
Countries
Thailand / Malaysia
Contract type
Permanent
Work pattern
Full Time
Market
Various
Discipline
Legal
Job ref
8157
Recruiter contact
Betty Atthawimol

Location/s: Bangkok, Thailand / Kuala Lumpur Malaysia
Recruiter contact: Betty Atthawimol
 

The Group Head of Privacy and Data Protection and his team operate as a global advisory, compliance, and assurance function. The role of Privacy and Data Protection Adviser - Asia-Pacific is focussed on supporting these activities across East Asia, Southeast Asia, Australia, and New Zealand. Although Australia (the location of approximately 1,000 of our employees) and Hong Kong (hosting around 600 of our employees) are Mott MacDonald’s largest hubs within the region, the Group also operates in the 
following jurisdictions: China, Indonesia, Japan, Malaysia, New Zealand, Singapore, South Korea, Taiwan and Thailand (with approximately 1,000 employees distributed across those countries).

Job description:

  • Informing and advising colleagues across the Asia-Pacific of their obligations under our global  privacy and data protection compliance framework and applicable privacy and data protection laws (including the Australian Privacy Act, Singapore Personal Data Protection Act, Hong Kong Personal Data (Privacy) Ordinance, Thailand Personal Data Protection Act, New Zealand Privacy Act, Indonesian Personal Data Protection Law, UK GDPR, and EU GDPR).
  • Working with colleagues in our legal, procurement, and commercial functions to ensure that appropriate contractual safeguards (covering the collection, use, disclosure, storage, and destruction of personal information) are in place between Mott MacDonald and its clients, suppliers, and other commercial partners.
  • Working with internal stakeholders (including IT and cyber/information security teams) to co-ordinate the timely identification, reporting, logging, investigation, notification (to relevant regulatory authorities and affected individuals), and resolution of personal data breaches.
  • Supporting the completion and maintenance of our ‘record of processing activities’ to ensure compliance with record-keeping, transparency, and accountability requirements under relevant policies and legislation.
  • Advising colleagues when/how to complete Personal Information Risk Assessments (PIRAs), AI Risk 
  • Assessments (AIRAs), International Transfer Risk Assessments (ITRAs), Personal Information 
  • Compliance Assessments (PICAs), Asset Discovery Questionnaires (ADQs) in the context of new/evolving projects, initiatives and technologies.
  • Evaluating completed assessments (PIRAs, AIRAs, TIRAs, PICAs, and ADQs), providing feedback, recommending appropriate risk treatments/mitigations, and then monitoring their implementation.
  • Providing advice and guidance to colleagues on the identification, logging, evaluation, and timely  resolution of individual rights requests (for example, requests from job applicants or former employees who want to obtain copies of their personal information).
  • Working with colleagues in our legal function (and with external legal advisers) to ensure appropriate  arrangements are in place covering international intra-group transfers of personal information.
  • Contributing to the development and maintenance of our privacy and data protection compliance framework (including policies, requirements, guidance, work instructions, consent statements, and privacy information notices).
  • Co-ordinating the activities of our internal privacy and data protection champions across the AsiaPacific, arranging quarterly briefings and helping to maintain appropriate coverage (at least one ‘Privacy Practitioner’ in each jurisdiction).
  • Delivering training and contributing to the development of eLearning and Intranet content which helps colleagues understand their responsibilities under privacy and data protection legislation.
  • Providing advice and guidance to colleagues on the identification, definition, recording, evaluation, mitigation, and treatment of risks related to the processing of personal information.
  • Investigating and responding to privacy and data protection concerns/complaints raised by individuals (including employees, job applicants, client contacts, and members of the public) whose personal information is processed by Mott MacDonald.
  • Providing advice and guidance to HR colleagues on the handling of disciplinary matters involving employee misuse of (or unauthorised access to) personal information.
  • As required, liaising with privacy and data protection regulators across the Asia-Pacific and building constructive working relationships with those organisations.


Candidate specification
Essential:

  • Experience of providing pragmatic expert advice on the interpretation and application of privacy and data protection laws (and associated regulatory frameworks) in one or more jurisdiction within the Asia-Pacific region.
  • Able to identify and respond to a range of privacy and data protection compliance challenges (including changes to the law, new regulatory guidance, and emerging technologies) and work with colleagues to identify pragmatic cost-effective solutions.
  • Experience of co-ordinating the resolution of individual rights requests and/or complaints by individuals about the processing of their personal information.
  • Experience of contributing to the response to personal data breaches and assessing their potential impact on the affected individuals (as well as the organisations involved).
  • A confident and articulate self-starter able to manage and prioritise a large and varied workload, work independently, take decisions on your own initiative within defined parameters, and meet challenging deadlines (whilst managing the expectations of others).
  • Able to assimilate and interpret information quickly; and can explain complex processes or requirements to colleagues without using confusing technical or legal jargon.
  • Able to communicate and negotiate effectively with colleagues at all levels of an organisation and influencing decision-making by linking compliance requirements to business objectives/outcomes.
  • Able to communicate effectively (and respectfully) with colleagues, data subjects, commercial partners and other external stakeholders irrespective of national boundaries and cultures.
  • Able to handle confidential information with discretion; with a strong commitment to maintaining their personal/professional integrity and upholding the highest ethical and professional standards.
  • Excellent IT and administrative skills (including extensive experience of using SharePoint and other Microsoft applications).
  • Possesses the confidence and self-awareness required to identify gaps in their own knowledge and the intellectual curiosity required to continually develop their professional expertise.

 

Equality, diversity and inclusion

We put equality, diversity and inclusion at the heart of our business, seeking to promote fair employment procedures and practices to ensure equal opportunities for all. We encourage individual expression in our workplace and are committed to creating an inclusive environment where everyone feels they have the opportunity to contribute.

 

Agile working

At Mott MacDonald, we believe it makes business sense for you and your manager to choose how you can work most effectively to meet your client, team and personal commitments. We embrace agility, flexibility and trust.