Role Summary
We are seeking an experienced Data Protection Officer (DPO) to lead our privacy and data protection program across the UK and Europe, while providing advisory support to the Asia-Pacific region (primarily Singapore).
The successful candidate will serve as the primary advisor on data privacy matters, ensuring compliance with GDPR, the EU AI Act, and other applicable privacy and AI regulations.
The role will work closely with Legal, Information Security, Risk, Compliance, HR, Technology, and Business teams to embed privacy-by-design into business processes and technology initiatives.
Key Responsibilities
- Act as the designated Data Protection Officer for UK and European operations.
- Serve as the primary point of contact for data protection matters.
- Liaise with regulators and supervisory authorities as required.
- Advise senior leadership on privacy risks and compliance obligations.
- Maintain and enhance the enterprise privacy framework.
- Develop and update privacy policies, standards, and procedures.
- Ensure privacy-by-design principles are embedded into projects.
- Oversee Records of Processing Activities (RoPA).
- Ensure compliance with: UK GDPR, EU GDPR, EU AI Act, Other applicable privacy and AI regulations.
- Monitor emerging regulatory developments and assess business impact.
- Lead Privacy Impact Assessments (DPIAs/PIAs).
- Assess privacy risks associated with new technologies and business initiatives.
- Review cross-border data transfer mechanisms.
- Support third-party privacy risk assessments.
- Advise on personal data breach investigations.
- Support regulatory notification requirements.
- Coordinate privacy-related incident response.
- Partner with Legal, Security, Compliance, Internal Audit, and Technology teams.
- Deliver privacy awareness and training programs.
- Support internal and external audits.
- Provide advisory support to regional privacy initiatives, primarily in Singapore.
- Collaborate with regional business and compliance teams to ensure alignment with enterprise privacy policies.
Required Skills
- Extensive experience in Data Privacy and Data Protection.
- Deep knowledge of UK GDPR and EU GDPR.
- Working knowledge of the EU AI Act.
- Experience serving as a Data Protection Officer or Deputy DPO.
- Strong understanding of privacy governance.
- Experience conducting DPIAs.
- Experience with cross-border data transfers.
- Ability to engage with executive stakeholders.
Preferred
- Insurance or Financial Services experience.
- Knowledge of privacy regulations in Singapore/APAC.
- Familiarity with privacy tooling such as: OneTrust (Primary tool in use), Microsoft Purview, Veronis, Proofpoint.