Data Privacy Manager

Posted 14 Days Ago
Be an Early Applicant
Makati City, Southern Manila District, National Capital Region, PHL
Hybrid
Senior level
Professional Services • Financial Services
The Role
Manage and improve the Philippines privacy compliance framework, including governance, regulatory compliance, privacy risk assessments, incident response, third-party reviews, audits, reporting, and employee training. The role supports privacy-by-design reviews, data processing records, breach notifications, vendor agreements, global privacy initiatives, and cross-border compliance programs while coordinating with Legal, Information Security, Risk, Compliance, HR, and business stakeholders.
Summary Generated by Built In

Key Responsibilities

Privacy Program Governance
•    Support the design, implementation, and continuous improvement of the GCS’ privacy compliance framework in the Philippines.
•    Assist in establishing governance mechanisms, standards, policies, procedures, and controls related to personal data processing that align to GTA requirements
•    Monitor ongoing compliance with relevant privacy laws, regulations, and organizational requirements.
•    Provide guidance to business teams on privacy compliance obligations and best practices.
•    Creation and update of Records of Processing Activities (ROPAs) for both GCS and global privacy operations.
•    Ensure that GTA incident reporting policy is implemented in GCS operations and assist in implementation of technologies supporting incident reporting and processing globally.
•    Coordinate and attend meetings, emailing internal contacts for information as directed. 
•    Supporting Privacy review of products and services, creating review templates and identifying areas for more effective review.

Regulatory Compliance
•    Serve as the local privacy compliance resource for Philippine data protection matters.
•    Support compliance with the Philippine Data Privacy Act of 2012 and applicable implementing regulations.
•    Coordinate privacy registrations, regulatory submissions, and documentation requirements with relevant authorities when required.
•    Monitor legislative, regulatory and case law developments and recommend updates to internal processes and controls.
•    Consolidate requirements of, enforce and audit against privacy frameworks like DCPP, GDPR, CCPA, NIST, ISO (27001, 27559, 29100, 27701, 27559, DORA, EU AI Act, EU-US DPF)

Privacy Risk Management
•    Conduct privacy risk assessments and support Privacy Impact Assessments (PIAs).
•    Supporting Privacy review of products and services, creating review templates and identifying areas for more effective review.
•    Identify privacy risks associated with business processes, projects, systems, and third-party engagements.
•    Recommend mitigation controls and monitor remediation activities.
•    Maintain privacy risk registers and compliance documentation.

Incident Management
•    Support the investigation, assessment, and management of privacy incidents and data breaches.
•    Coordinate with Legal, Information Security, Risk, Compliance, and business stakeholders during incident response activities.
•    Assist in determining notification requirements and regulatory reporting obligations.
•    Maintain records of privacy incidents and corrective actions.

Global Privacy Operations Support
•    Report to the Global Privacy Team and support  
o    strategic privacy initiatives.
o    cross-border privacy compliance activities and global privacy governance programs.
o    privacy assessments, audits, reporting, and compliance monitoring activities.
o     privacy maturity across the organization.

Third-Party and Vendor Privacy Management
•    Review vendor privacy practices and support privacy due diligence activities.
•    Assist in evaluating data processing agreements and privacy-related contractual requirements.
•    Monitor privacy compliance obligations of third-party service providers.

Training and Awareness
•    Develop and deliver privacy awareness programs and training sessions.
•    Promote a strong culture of data protection and responsible information handling.
•    Create targeted training for employees, leaders, and stakeholders on privacy-related matters.

Audit and Compliance Support
•    Support internal and external audits involving privacy compliance requirements.
•    Assist with evidence gathering, control testing, and remediation activities.
•    Prepare privacy KPI metrics, governance reports, and management updates.

Qualifications

Education
•    Bachelor’s degree in law, Information Technology, Information Security, Business Administration, Risk Management, Compliance, Human Resources, or a related field.
•    Postgraduate qualification in Data Privacy, Law, Compliance, Risk Management, or Information Security is an advantage.

Experience
•    Extensive experience in implementing data privacy processes in global organizations to include implementation of privacy by design, risk management and compliance support.
•    Bachelor's degree or equivalent (computer science, data science, IT) 
•    5+ years’ experience implementing privacy enhancing technologies in data lakes, software, IT infrastructure and applications.
•    Certifications (e.g., CISSP, CISM, or CISA preferred)
•    AI product development experience.
•    Project planning experience (PMP or similar certification).
•    Experience in professional services organizations.
•    Excellent verbal and written communication skills.
•    Travel percentage: 5% (may be occasional travel if required)
 

Preferred Certifications
One or more of the following certifications is highly preferred:
•    Certified Information Privacy Professional (CIPP/A, CIPP/E, or CIPP/US)
•    Certified Information Privacy Manager (CIPM)
•    Certified Information Privacy Technologist (CIPT)
•    ISO 27701 Lead Implementer or Lead Auditor
•    Certified Information Systems Security Professional (CISSP)
•    Data Privacy Competency certification from the National Privacy Commission (NPC)

Key Competencies
Technical Competencies
•    Privacy compliance and governance
•    Data Protection Impact Assessments (DPIAs)
•    Privacy incident management
•    Regulatory compliance
•    Third-party risk management
•    Privacy by Design principles
•    Data lifecycle management
•    Records management

Behavioral Competencies
•    Strong stakeholder management
•    Analytical and problem-solving capability
•    Excellent communication and presentation skills
•    High professional integrity and confidentiality
•    Ability to influence across functions and geographies
•    Strong project management and organizational skills

Success Measures
Within the first 12 months, the successful candidate will:
•    Support the establishment and maturation of the Philippines privacy compliance framework.
•    Improve visibility and governance of personal data processing activities.
•    Strengthen privacy risk assessment and monitoring capabilities.
•    Enhance privacy awareness across business teams.
•    Contribute to global privacy initiatives and cross-border compliance programs.
•    Establish effective partnerships with Risk, Legal, Compliance, Information Security, HR, and Operations teams.


Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
16 Employees
Year Founded: 1995

What We Do

Grant Thornton Gibraltar is a leading professional services firm established in 1995. It serves private individuals and public companies listed on international stock exchanges, with experienced teams supporting local and international clients. Its offerings include audit and assurance, business services, payroll, advisory, tax, accounting, and financial services. The firm also helps organizations grow and develop by addressing their accountancy and business needs.

Similar Jobs

Mondelēz International Logo Mondelēz International

Technical Analyst - Operations Delivery

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
2 Locations
90000 Employees

Mondelēz International Logo Mondelēz International

Team Lead

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
Manila, Metro Manila, National Capital Region, PHL
90000 Employees
Remote or Hybrid
2 Locations
289097 Employees
Hybrid
Taguig City, Metro Manila, National Capital Region, PHL
205000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account