Job Responsibilities
Regular
Assists the DPO and Deputy DPO with the following work:
- Executing an annual work plan to ensure compliance with the Personal Data Protection Act (“PDPA”) under the guidance of the Deputy General Counsel.
- Reviewing and executing company policies and procedures for effective personal data compliance management, covering all aspects of personal data care under the 9 PDPA Obligations.
- Communicating internal personal data protection policies, processes and issues to TMs through internal newsletters, awareness trainings etc.
- Administering the Company’s Data Protection compliance system.
- Administering the orientation and annual refresher training for all employees on personal data protection.
- Working with the User Departments to respond to queries and requests from third parties (vendors, third party casinos, government agencies and other Sands Group companies), members and guests on personal data protection policies and processes.
- Working with the User Departments to manage responses to customer requests to access their personal data and correction in an appropriate and timely manner in accordance with the PDPA Access & Correction Requests Handling Procedure.
- Working with the User Departments to run personal data risk assessments and recommending mitigating controls to User Departments to moderate identified personal data risks identified in processes.
- Maintaining the Company’s personal data inventory and ensuring that it is up-to-date.
Periodic
- Conducts topical trainings on PDPA issues.
- Works with the User Departments to reach out to TMs on PDPA-related activities, such as disseminating information on TM’s responsibilities, personal data protection policies, programme initiatives, etc.
Incident Specific
- Manages PDPA-related incidents and complaints in an appropriate and timely manner in accordance with the PDPA Incident Response Framework.
- Escalates personal data risk alerts, major PDPA complaints and programme implementation issues to DPO and Deputy DPO for deliberation and decision.
- Works with other stakeholders such as the Cyber and IT departments to implement remediations and mitigation controls.
Job Requirements
Education & Certification
- LLB with minimum of 3 years PQE or equivalent.; Certified Information Privacy Professional.
Experience
- Has worked as a legal counsel advising on personal data protection compliance and legal issues at a customer facing organisation in Singapore or outside Singapore or in the alternative, has worked as an external lawyer in a law firm advising on personal data protection compliance and legal issues.
- Has experience conducting data protection compliance trainings or managing data breach situations.
- Has experience in implementing data protection or other related general compliance programmes, conducting compliance monitoring reviews.