Data Protection Officer

24 hours ago


Singapore Thunes Full time

**About Thunes**

Thunes is the Smart Superhighway for money movement around the world. Thunes' proprietary Direct Global Network allows Members to make payments in real-time in over 130 countries and more than 80 currencies. Thunes' Network connects directly to over 7 billion mobile wallets and bank accounts worldwide, via more than 350 different payment methods, such as GCash, M-Pesa, Airtel, MTN, Orange, JazzCash, Easypaisa, AliPay, WeChat Pay and many more.

Members of Thunes' Direct Global Network include gig economy giants like Uber and Deliveroo, super-apps like Grab and WeChat, MTOs, fintechs, PSPs and banks. Thunes' Direct Global Network differentiates itself through its worldwide reach, in-house Smart Treasury Management Platform and Fortress Compliance Infrastructure, ensuring Members of the Network receive unrivalled speed, control, visibility, protection and cost efficiencies when making real-time payments globally.

**Context of the role**

You will play a critical role in building trust with our clients, partners and employees by ensuring their personal data is protected and that the company meets all legal and regulatory requirements in respect of data privacy and governance.

**Key Responsibilities**
- **Data Protection Compliance**
- Lead and manage the company's data protection strategy and frameworks, as well as developing, implementing, and maintaining adequate technical and operation measures to ensure compliance with all applicable privacy laws (including GDPR (both UK and EU), US Federal and State (including CCPA/CPRA), PDPA (Singapore) and /US Federal, PDPO (Hong Kong) and other regional regulations where the group operates).
- Develop, implement and embed policies and procedures related to data protection, data retention, and data security.
- Maintain the groups data transfer and intra-group data sharing agreements and processes, including EU-US and UK extension data privacy frameworks
- Assist in the negotiation of data processing agreements with the group's customers and maintenance of related templates.
- Ensure that personal data processing activities are conducted in a manner that ensures the confidentiality, integrity, and availability of data.
- **Risk Management and Audits**
- Conduct Data Protection Impact Assessments (DPIA) and Data Transfer Impact Assessments in respect of the group's operations and for new products, services, and processes.
- Regularly audit data protection practices and provide recommendations for risk mitigation.
- Work with the group's CISO in respect of embedding data protection and cyber security processes and controls.
- Work with internal stakeholders to ensure that third-party vendors adhere to data protection standards.
- Report to the Thunes Risk Committee on a regular basis to ensure management oversight and control.
- Assist with regulatory reporting and filings as necessary.
- **Training and Awareness**
- Develop and deliver training programs to staff on data protection compliance and best practices.
- Maintain and train the wider legal team in respect of data privacy matters and documentation.
- Promote a culture of data privacy and privacy by design within the organisation.
- **Data Breach Response**
- Establish protocols for data breach investigation, remediation, and reporting.
- **Liaison with Authorities**
- Be registered as and act as the primary point of contact with data protection authorities and regulatory bodies.
- **Records of Processing Activities (RoPA)**
- Maintain and regularly update records of all data processing activities (RoPA) within the group.

**Professional Skills and Qualifications**
- **Educational Background**
- Bachelor's degree in Law, Information Security, or related field.
- Professional certifications such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), or equivalent are highly desirable.
- **Experience**
- At least 7 years of experience in data protection and privacy law, preferably within a FinTech, financial services or payments company.
- Familiarity with implementing data privacy frameworks and regulations, including GDPR, CCPA, and others.
- Experience in conducting and negotiating DPAs, DTIAs, DPIAs, audits, and data breach management.
- **Knowledge and Skills**
- Deep understanding of data protection laws, regulatory frameworks, and industry best practices.
- Ability to balance regulatory requirements with commercial needs.
- Strong problem-solving skills with the ability to assess risks and provide practical solutions.
- Excellent communication skills, both written and verbal, with the ability to explain complex data privacy concepts to non-specialists.
- Strong organisational skills and attention to detail.



  • Singapore BANK OF SINGAPORE LIMITED Full time

    This role reports to the Head of the Global Data Protection Office, within the Legal function. The Global Data Protection Office develops and maintains the Data Protection programme for the


  • Singapore Bank of Singapore, Asia's Global Private Bank Full time

    Overview Bank of Singapore opens doors to new opportunities. At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of openness, teamwork and fairness. Most importantly, we invest in our people through our programmes that develop them on both professional and personal levels. Besides...


  • Singapore Bank of Singapore, Asia's Global Private Bank Full time

    Join to apply for the Data Protection Office (Vice President) role at Bank of Singapore, Asia's Global Private Bank Get AI-powered advice on this job and more exclusive features. Bank of Singapore opens doors to new opportunities. At Bank of Singapore, we are constantly on the lookout for exceptional individuals to join our team. We promote a culture of...


  • Singapore PRIVACY NINJA PTE. LTD. Full time

    **Job Summary**: **Key Responsibilities**: **Client Advisory Services**: - Provide expert consultation to clients on all aspects of data protection and PDPA compliance. - Address client inquiries and provide solutions to complex data protection issues. - Stay updated with changes in data protection laws and regulations to offer timely and accurate...


  • Singapore Tangspac Full time

    F- Posted by - Fong Chua- Recruiter Great Opportunity for a Data Protection/Data Privacy/Data Loss Prevention specialist to join an international bank as a Data Protection Officer covering the APAC region Direct Responsibilities - Contribute to relevant personal data protection activities realization - Guarantee advice and assistance to strategical program...


  • Singapore HUANG HE CONSULTANCY PTE. LTD. Full time

    **Job description**: The responsibilities of a DPO include, but are not limited to: - Ensuring compliance with PDPA when developing and implementing policies and processes for handling personal data; - Fostering a data protection culture among employees and communicating personal data protection policies to stakeholders; - Managing personal data...


  • Singapore BYD (SINGAPORE) PTE. LTD. Full time

    **Roles & Responsibility: Monitor and assess the Company’s personal data protection policies and practices, to ensure compliance with the PDPA. This includes identifying risks associated with the collection, use, disclosure and storage of personal data understand their impact and propose measures to manage these risks. - Establish and maintain...


  • Singapore beBeeDataProtection Full time

    Lead Data Protection Efforts We are seeking an experienced Manager to drive continuous data protection improvements and promote a positive data culture. The successful candidate will have the opportunity to lead ad-hoc projects, conduct reviews to ensure privacy and data protection compliance, and investigate data incidents. In this role, you will be...

  • Board Secretary

    2 weeks ago


    Singapore TAURUS FIRM PTE. LTD. Full time

    **Board Secretary / Data Protection Officer** **Responsibilities**: - Organize and schedule board meetings; prepare and distribute agendas with the board chair and executive team. - Record and maintain detailed minutes, resolutions, and official documents. - Ensure compliance with legal and regulatory requirements, including filing necessary documents. -...


  • Singapore DRAKE INTERNATIONAL (SINGAPORE) LIMITED Full time

    **Responsibilites**: - Support the review and enhancement of data governance framework, policies, standards, guidelines and data inventory across the Group - Assist in performing risk and impact assessments - Provide advisory to Business Units on personal data protection at various stages of the personal data life cycle - Review and assist in conducting...