Head of Data Protection Officer
BANK XYZ Financial Services- Posted 15 hours ago
- Be among the first 10 applicants
Job Description
Job Summary
The Data Protection Officer is the Bank's statutorily appointed DPO under the Personal Data Protection Act B.E. 2562 (PDPA) and leads the Data Protection Office and Data & AI Governance. The role is accountable for advising the Bank on personal data protection obligations, monitoring PDPA compliance across all data processing activities, and acting as the contact point for data subjects and the Personal Data Protection Committee (PDPC).
Key Responsibilities
- Act as the Bank's appointed Data Protection Officer under PDPA;
- Advise the Board, management, and staff on PDPA obligations and monitor the Bank's compliance
- Own and maintain the Personal Data Protection Framework, policies, standards, notices, and procedures, aligned with PDPA
- Maintain the Record of Processing Activities (RoPA), data inventory, and data flow mapping.
- Govern lawful basis determination and consent management, including consent capture, granularity, withdrawal, and refresh mechanisms in digital channels.
- Establish and run Data Protection Impact Assessment (DPIA) and privacy-by-design review processes for new products, features, channels, data sharing arrangements in the product lifecycle
- Oversee data subject rights fulfilment, including SLAs, workflow, verification controls, and quality assurance
- Lead personal data breach management from a PDPA perspective
- Govern data processor and data sharing arrangements.
- Act as contact point for data subjects, the PDPC, and regulators
- Report on data protection and data/AI governance status, risks, incidents, and remediation to RMC, ROC, and the Board
- Drive privacy and data ethics culture
- Monitor developments in PDPA enforcement and PDPC guidance
Qualifications
Experience
- Minimum 8–12 years of experience in data protection/privacy, legal, compliance, information security, or risk management, with at least 3–5 years focused on personal data protection
- Demonstrated experience as a DPO, deputy DPO, or privacy lead in a regulated organization; experience in banking, payments, insurance, or fintech strongly preferred
- Proven experience implementing PDPA (or GDPR) compliance programmes, including RoPA, DPIA, consent, data subject rights, and breach response
- Experience handling personal data breaches and regulator engagement
- Exposure to data governance and AI/model governance is an advantage
Technical Skills
- Deep knowledge of PDPA and PDPC subordinate regulations, with practical ability to translate legal requirements into operational controls
- Strong understanding of privacy engineering concepts: privacy-by-design, data minimization, anonymization/pseudonymization, encryption and tokenization, consent architecture, and access governance
- Familiarity with data governance disciplines
- Experience with privacy management, GRC, DLP, data discovery, or consent management tooling
- Ability to run DPIAs and privacy risk assessments and to negotiate DPAs and data sharing terms
- Data analysis and reporting skills for privacy KRI and compliance monitoring
- Strong analytical, drafting, and advisory skills; sound judgement in ambiguous situations
- Excellent communication, training, and stakeholder management skills, able to influence senior management; strong command of English and Thai
What We Offer
- Competitive salary and performance-based bonus
- Comprehensive health and life insurance coverage
- Flexible working arrangements and hybrid work policy
- Learning & development budget and access to industry certifications
- Opportunity to work at the forefront of virtual banking and fintech innovation in Thailand
- Collaborative and inclusive work culture within a high-growth organization
More Info
Key Skills
access governance
PDPA
pseudonymization
privacy-by-design
consent architecture
anonymization
consent management tooling
DPIAs
data minimization
privacy management
privacy engineering concepts
data sharing terms
DPAs
privacy risk assessments
