Data Protection Officer

2 weeks ago


Singapore Thunes Full time

**About Thunes**

Thunes is the Smart Superhighway for money movement around the world. Thunes' proprietary Direct Global Network allows Members to make payments in real-time in over 130 countries and more than 80 currencies. Thunes' Network connects directly to over 7 billion mobile wallets and bank accounts worldwide, via more than 350 different payment methods, such as GCash, M-Pesa, Airtel, MTN, Orange, JazzCash, Easypaisa, AliPay, WeChat Pay and many more.

Members of Thunes' Direct Global Network include gig economy giants like Uber and Deliveroo, super-apps like Grab and WeChat, MTOs, fintechs, PSPs and banks. Thunes' Direct Global Network differentiates itself through its worldwide reach, in-house Smart Treasury Management Platform and Fortress Compliance Infrastructure, ensuring Members of the Network receive unrivalled speed, control, visibility, protection and cost efficiencies when making real-time payments globally.

**Context of the role**

You will play a critical role in building trust with our clients, partners and employees by ensuring their personal data is protected and that the company meets all legal and regulatory requirements in respect of data privacy and governance.

**Key Responsibilities**
- **Data Protection Compliance**
- Lead and manage the company's data protection strategy and frameworks, as well as developing, implementing, and maintaining adequate technical and operation measures to ensure compliance with all applicable privacy laws (including GDPR (both UK and EU), US Federal and State (including CCPA/CPRA), PDPA (Singapore) and /US Federal, PDPO (Hong Kong) and other regional regulations where the group operates).
- Develop, implement and embed policies and procedures related to data protection, data retention, and data security.
- Maintain the groups data transfer and intra-group data sharing agreements and processes, including EU-US and UK extension data privacy frameworks
- Assist in the negotiation of data processing agreements with the group's customers and maintenance of related templates.
- Ensure that personal data processing activities are conducted in a manner that ensures the confidentiality, integrity, and availability of data.
- **Risk Management and Audits**
- Conduct Data Protection Impact Assessments (DPIA) and Data Transfer Impact Assessments in respect of the group's operations and for new products, services, and processes.
- Regularly audit data protection practices and provide recommendations for risk mitigation.
- Work with the group's CISO in respect of embedding data protection and cyber security processes and controls.
- Work with internal stakeholders to ensure that third-party vendors adhere to data protection standards.
- Report to the Thunes Risk Committee on a regular basis to ensure management oversight and control.
- Assist with regulatory reporting and filings as necessary.
- **Training and Awareness**
- Develop and deliver training programs to staff on data protection compliance and best practices.
- Maintain and train the wider legal team in respect of data privacy matters and documentation.
- Promote a culture of data privacy and privacy by design within the organisation.
- **Data Breach Response**
- Establish protocols for data breach investigation, remediation, and reporting.
- **Liaison with Authorities**
- Be registered as and act as the primary point of contact with data protection authorities and regulatory bodies.
- **Records of Processing Activities (RoPA)**
- Maintain and regularly update records of all data processing activities (RoPA) within the group.

**Professional Skills and Qualifications**
- **Educational Background**
- Bachelor's degree in Law, Information Security, or related field.
- Professional certifications such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), or equivalent are highly desirable.
- **Experience**
- At least 7 years of experience in data protection and privacy law, preferably within a FinTech, financial services or payments company.
- Familiarity with implementing data privacy frameworks and regulations, including GDPR, CCPA, and others.
- Experience in conducting and negotiating DPAs, DTIAs, DPIAs, audits, and data breach management.
- **Knowledge and Skills**
- Deep understanding of data protection laws, regulatory frameworks, and industry best practices.
- Ability to balance regulatory requirements with commercial needs.
- Strong problem-solving skills with the ability to assess risks and provide practical solutions.
- Excellent communication skills, both written and verbal, with the ability to explain complex data privacy concepts to non-specialists.
- Strong organisational skills and attention to detail.



  • Singapore Thye Hua Kwan Moral Charities Full time $40,000 - $60,000 per year

    COMPANY DESCRIPTION THKMC was incorporated on 13 October 2011 as a charity to provide multiple social and welfare services to the community at large, and achieved an Institute of Public Character (IPC) status on 18 November 2011. THKMC is the charitable arm of Thye Hua Kwan Moral Society, which lives by the mission - To Serve Mankind - to help anyone who...


  • Singapore Glints Pte Ltd Full time

    We are looking for a Data Protection Officer (Q). Data Protection Officer (DPO) will ensure the company is compliant with the PDPA, CCPA, and GDPR while promoting the commercial uses of data which improve the lives of citizens. **Responsibilities**: - Identify and evaluate the company’s data processing activities in multiple jurisdictions around the...


  • Singapore HYPERSCAL SOLUTIONS PTE. LTD. Full time $60,000 - $180,000 per year

    COMPANY DESCRIPTIONTHK MC was incorporated on 13 October 2011 as a charity to provide multiple social and welfare services to the community at large, and achieved an Institute of Public Character (IPC) status on 18 November 2011. THK MC is the charitable arm of Thye Hua Kwan Moral Society, which lives by the mission - To Serve Mankind - to help anyone who...


  • Singapore PRIVACY NINJA PTE. LTD. Full time $80,000 - $120,000 per year

    Job Summary:Privacy Ninja is the trusted DPO-as-a-Service partner, serving over 500 organisations across all sectors. We are seeking a highly skilled and knowledgeable Data Protection Officer (DPO) to join our diverse DPO-as-a-Service team. The ideal candidate will be responsible for providing our clients expert advice and guidance on data protection...


  • Singapore Huang He Consultancy Pte Ltd Full time

    The responsibilities of a DPO include, but are not limited to: - Ensuring compliance with PDPA when developing and implementing policies and processes for handling personal data; - Fostering a data protection culture among employees and communicating personal data protection policies to stakeholders; - Managing personal data protection-related queries and...


  • Singapore HUANG HE CONSULTANCY PTE. LTD. Full time

    **Job description**: The responsibilities of a DPO include, but are not limited to: - Ensuring compliance with PDPA when developing and implementing policies and processes for handling personal data; - Fostering a data protection culture among employees and communicating personal data protection policies to stakeholders; - Managing personal data...


  • Singapore PRIVACY NINJA PTE. LTD. Full time

    Job Summary: Privacy Ninja is the trusted DPO-as-a-Service partner, serving over 500 organisations across all sectors. We are seeking a highly skilled and knowledgeable Data Protection Officer (DPO) to join our diverse DPO-as-a-Service team. The ideal candidate will be responsible for providing our clients expert advice and guidance on data protection...


  • Singapore Funding Societies | Modalku Group Full time

    Funding Societies | Modalku is the largest SME digital financing platform in Southeast Asia, expanding into a leading SME neobank. We are licensed and registered in Singapore, Indonesia, Thailand, Malaysia, and operating in Vietnam, and backed by Sequoia India, Softbank Vision Fund and SMBC bank amongst many others. Funding Societies | Modalku provides...


  • Singapore Funding Societies Full time

    **Description**: Funding Societies | Modalku is the largest SME digital financing platform in Southeast Asia, expanding into a leading SME neobank. We are licensed and registered in Singapore, Indonesia, Thailand, Malaysia, and operating in Vietnam, and backed by Sequoia India, Softbank Vision Fund and SMBC bank amongst many others. Funding Societies |...

  • Data Protection

    1 week ago


    Singapore Aprisium Pte Ltd Full time

    Data Protection & Information Security Officer Aprisium is a Singapore-based deep-tech startup delivering real-time, autonomous contamination monitoring solutions for water, wastewater, and industrial fluids. Our IoT-enabled analyzers and AI-driven analytics help industries detect pollutants at source, optimize processes, and improve both profitability and...