Search Jobs

Search by job, company or skills

Head of Data Protection Officer

Head of Data Protection Officer

BANK XYZ Financial Services
8-12 Years
  • Posted 15 hours ago
  • Be among the first 10 applicants

Job Description

Job Summary

The Data Protection Officer is the Bank's statutorily appointed DPO under the Personal Data Protection Act B.E. 2562 (PDPA) and leads the Data Protection Office and Data & AI Governance. The role is accountable for advising the Bank on personal data protection obligations, monitoring PDPA compliance across all data processing activities, and acting as the contact point for data subjects and the Personal Data Protection Committee (PDPC).

Key Responsibilities

  • Act as the Bank's appointed Data Protection Officer under PDPA;
  • Advise the Board, management, and staff on PDPA obligations and monitor the Bank's compliance
  • Own and maintain the Personal Data Protection Framework, policies, standards, notices, and procedures, aligned with PDPA
  • Maintain the Record of Processing Activities (RoPA), data inventory, and data flow mapping.
  • Govern lawful basis determination and consent management, including consent capture, granularity, withdrawal, and refresh mechanisms in digital channels.
  • Establish and run Data Protection Impact Assessment (DPIA) and privacy-by-design review processes for new products, features, channels, data sharing arrangements in the product lifecycle
  • Oversee data subject rights fulfilment, including SLAs, workflow, verification controls, and quality assurance
  • Lead personal data breach management from a PDPA perspective
  • Govern data processor and data sharing arrangements.
  • Act as contact point for data subjects, the PDPC, and regulators
  • Report on data protection and data/AI governance status, risks, incidents, and remediation to RMC, ROC, and the Board
  • Drive privacy and data ethics culture
  • Monitor developments in PDPA enforcement and PDPC guidance

Qualifications

Experience

  • Minimum 8–12 years of experience in data protection/privacy, legal, compliance, information security, or risk management, with at least 3–5 years focused on personal data protection
  • Demonstrated experience as a DPO, deputy DPO, or privacy lead in a regulated organization; experience in banking, payments, insurance, or fintech strongly preferred
  • Proven experience implementing PDPA (or GDPR) compliance programmes, including RoPA, DPIA, consent, data subject rights, and breach response
  • Experience handling personal data breaches and regulator engagement
  • Exposure to data governance and AI/model governance is an advantage

Technical Skills

  • Deep knowledge of PDPA and PDPC subordinate regulations, with practical ability to translate legal requirements into operational controls
  • Strong understanding of privacy engineering concepts: privacy-by-design, data minimization, anonymization/pseudonymization, encryption and tokenization, consent architecture, and access governance
  • Familiarity with data governance disciplines
  • Experience with privacy management, GRC, DLP, data discovery, or consent management tooling
  • Ability to run DPIAs and privacy risk assessments and to negotiate DPAs and data sharing terms
  • Data analysis and reporting skills for privacy KRI and compliance monitoring
  • Strong analytical, drafting, and advisory skills; sound judgement in ambiguous situations
  • Excellent communication, training, and stakeholder management skills, able to influence senior management; strong command of English and Thai

What We Offer

  • Competitive salary and performance-based bonus
  • Comprehensive health and life insurance coverage
  • Flexible working arrangements and hybrid work policy
  • Learning & development budget and access to industry certifications
  • Opportunity to work at the forefront of virtual banking and fintech innovation in Thailand
  • Collaborative and inclusive work culture within a high-growth organization

More Info

Job Type:
Industry:
Employment Type:

Key Skills

access governance

PDPA

pseudonymization

privacy-by-design

consent architecture

anonymization

consent management tooling

DPIAs

data minimization

privacy management

privacy engineering concepts

data sharing terms

DPAs

privacy risk assessments