Key Responsibilities
Regulatory Compliance
Ensure organization-wide compliance with the Malaysian Personal Data Protection Act (PDPA), the Sri Lanka Personal Data Protection Act (PDPA), and Indonesia's Law No. 27 of 2022 on Personal Data Protection
Track regulatory developments across all three jurisdictions and update internal policies, standards and procedures accordingly
Maintain and continuously improve the organization's Information Security Management System (ISMS) and Privacy Information Management System (PIMS) in line with ISO 27001 and ISO 27701
Privacy by Design & Impact Assessments
Conduct Privacy by Design (PbD) assessments across new and existing platforms, products and projects
Conduct Data Protection Impact Assessments (DPIAs), identify privacy risks, and recommend practical mitigation measures
Partner with product, engineering and business teams to embed privacy controls from the earliest stages of design
Governance & Project Management
Manage multiple concurrent privacy projects across markets, prioritizing effectively to meet deadlines
Develop, maintain and enforce data privacy policies, standards and procedures group-wide
Support internal and external audits related to ISO 27001, ISO 27701 and data protection compliance
Manage data subject requests, privacy incidents and breach response processes
Training & Awareness
Design and deliver data privacy awareness programs for all staff, including teams in Malaysia, Sri Lanka and Indonesia
Build a sustained culture of privacy awareness through training sessions, communications and periodic refreshers
Stakeholder & Team Management
Liaise effectively with offshore and local teams, Axiata Group, regulators and business units to ensure consistent privacy practices region-wide
Report on privacy compliance status, risks and incidents to senior management and the group
Person Specifications
Strong analytical and risk-assessment mindset
Excellent project management and organizational skills
Cross-cultural communication and regional sensitivity across Malaysia, Sri Lanka and Indonesia
Proven ability to manage multiple projects simultaneously across different markets and time zones
Ability to translate legal and regulatory requirements into practical, business-friendly processes
High attention to detail and integrity in handling confidential information
Excellent communication and stakeholder management skills, with the ability to deliver trainings to diverse audiences