
Manager - Data Privacy Compliance
ประกาศจากแหล่งภายนอกคุณสมัครได้โดยตรง — เราจะพาคุณไปยังหน้าสมัครงานของบริษัท ไม่ต้องสมัครสมาชิก ไม่มีคนกลาง ไม่ต้องล็อกอิน ThaiJobz
เกี่ยวกับตำแหน่ง
This role is for a Data Privacy Compliance Manager responsible for strengthening the organization's data privacy framework in compliance with Thailand's PDPA, focusing on the life insurance and financial services sector. It involves supervising a team, advising on data privacy matters, managing AI compliance, and coordinating with various stakeholders.
รายละเอียดงาน
About the Company
The Manager - Data Privacy Compliance is responsible for supervising and strengthening the organization's data privacy and personal data protection framework in compliance with Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA), applicable regulatory requirements, and relevant group policies. The role supports the Deputy DPO and DPO in providing independent oversight, advisory support, and practical governance across the Company and relevant group entities, with particular focus on the life insurance and financial services environment.
Key Responsibilities:
- Supervise the day-to-day activities of the Data Privacy Team and ensure that privacy-related work is prioritized, completed accurately, and delivered within agreed timelines.
- Support the Deputy DPO and DPO in overseeing compliance with the PDPA, subordinate regulations, regulatory guidance, and internal data protection policies across the Company and relevant group entities.
- Develop, maintain, and enhance the organization's privacy governance framework, including policies, standards, procedures, operating guidelines, templates, and control mechanisms.
- Advise business units and support functions on the lawful collection, use, disclosure, transfer, retention, and disposal of personal data throughout the information lifecycle.
- Review and provide privacy advice on new products, services, distribution channels, digital initiatives, marketing activities, data analytics, artificial intelligence use cases, outsourcing arrangements, and material business changes.
- Coordinate with the AI Compliance Officer and relevant Legal, Compliance, Risk, Information Security, Technology, and business teams to assess and manage AI systems and use cases integrated into personal data processing activities, including privacy-by-design requirements, lawful basis, transparency, data minimization, automated decision-making, security safeguards, human oversight, third-party risk, and ongoing compliance monitoring.
- Lead or coordinate privacy impact assessments, data protection impact assessments, legitimate interest assessments, and other privacy risk assessments, as applicable.
- Oversee the maintenance of records of processing activities, data inventories, consent and preference management processes, privacy notices, data retention schedules, and data-sharing documentation.
- Coordinate the handling of data subject rights requests and ensure responses are complete, consistent, legally compliant, and delivered within statutory timelines.
- Support the assessment, escalation, investigation, documentation, and regulatory notification of personal data breaches in collaboration with Information Security, Legal, Compliance, Risk, Operations, and other relevant stakeholders.
- Review privacy clauses in contracts, data processing agreements, intra-group arrangements, vendor agreements, and cross-border data transfer mechanisms, in coordination with Legal and Procurement.
- Monitor third-party and service-provider privacy risks, including due diligence, contractual safeguards, control assessments, remediation tracking, and ongoing compliance monitoring.
- Design and deliver privacy awareness, role-based training, communications, and practical guidance for employees, management, agents, business partners, and other relevant stakeholders.
- Establish and monitor privacy compliance metrics, key risk indicators, control testing results, incident trends, remediation plans, and management reporting for the Deputy DPO, DPO, senior management, and relevant committees.
- Coordinate with regulators, external auditors, internal auditors, group privacy functions, and other assurance providers, as assigned by the Deputy DPO or DPO.
- Promote a strong privacy culture and embed privacy-by-design and privacy-by-default principles into business processes, systems, products, and organizational decision-making.
- Perform other data privacy, governance, compliance, or risk-management duties assigned by the Deputy DPO or DPO.
Qualifications:
- Bachelor's degree or higher in Law, Information Technology, Computer Science, Cybersecurity, Information Security, Risk Management, Compliance, Business Administration, Finance, Insurance, or another relevant discipline.
- At least 5 years’ experience in Compliance, Legal, Risk Management, Information Security Governance, Internal Control, or any related field; managerial or team-supervision experience is preferred.
- Preferred 3 - 5 years of relevant experience in Data Privacy / Data Protection.
- Experience in the financial services sector is preferred, with life insurance, insurance, banking, securities, or other regulated financial-sector experience considered a strong advantage.
- Practical knowledge of the PDPA and its application to business operations, customer data, employee data, marketing activities, digital channels, vendors, and regulated financial services.
- Hands-on experience implementing PDPA compliance frameworks and supporting the governance, risk assessment, or compliant deployment of artificial intelligence (AI) solutions in business operations, particularly where AI is integrated into personal data processing activities, is preferred.
- Experience working with senior management and cross-functional stakeholders, including Legal, Compliance, Risk, Information Security, Technology, Operations, Human Resources, Marketing, Procurement, and Internal Audit.
- Completion of recognized PDPA, data protection, privacy management, or DPO training programs offered by reputable educational institutions, professional bodies, or recognized training providers.
- Relevant professional certification is preferred, such as equivalent privacy, compliance, information security, or risk-management credential.
- Strong analytical, problem-solving, judgment, and risk-assessment capabilities, with the ability to translate legal and regulatory requirements into practical business controls.
- High level of integrity, discretion, independence, and professionalism when handling confidential information.
สวัสดิการที่ได้รับ
คุณสมบัติผู้สมัคร
- ประสบการณ์
- 6-10 ปี
- การศึกษา
- ปริญญาตรี
