Jobs Companies AIA Data Protection Officer, Principal

Sobre este puesto de Data Protection Officer, Principal en AIA

AIA · Presencial · Kuala Lumpur, MY-AIA Malaysia

At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone.

As pioneering innovators for over 100 years, we’re now transforming our organisation to be faster, simpler and more connected. Because we want to be even better equipped to develop digital solutions and experiences that help more people live Healthier, Longer, Better Lives.

To get there, we need people with tech/digital/analytics expertise and passion to help develop positive, sustainable change through digitally enhanced experiences that will impact the lives of millions of people and create a healthier future for everyone.

If you believe in developing a better tomorrow, read on. 

About the Role

The Data Protection Officer (DPO) leads and oversees the Company’s data protection and privacy program to ensure compliance with the Personal Data Protection Act (Act 709) and other relevant data protection laws. This role supports the organization and its entities in managing personal data processing risks, ensuring regulatory compliance, and promoting a culture of privacy. The DPO also acts as the main liaison for regulatory authorities and a key point of contact for data subjects.

Roles and Responsibilities:  
 

1. Data Privacy & Compliance Oversight 

  • Draft, review and maintain on an ongoing basis, local policies and guidelines to ensure compliance with both the AIA Group requirements and local regulatory requirements. 

  • Implement a risk-based data protection program across the Company and embed privacy-by-design in Company’s processing operations. 

  • Work with relevant departments/functions to build up and/or implement controls and provide quality and solutions-focused advice on data protection and privacy risk and control issues relevant to the business units for informed decision-making. 

  • Maintain and oversee a centralized record of personal data processing activities. 

  • Maintain a privacy risk register aligned to Enterprise Risk Management taxonomy. 

  • Review and approve Data Privacy Impact Assessments (DPIAs). 

  • Conduct periodic monitoring and review on the Company as part of control testing, including internal audits, gap assessments, and policy reviews. 

  • Coordinate cross-functional teams (e.g., IT, Legal, HR, Operations) to embed privacy requirements into business processes and systems. 

  • Where appropriate or upon request, provide guidance or share expertise with the DPOs of other entities. 

 

2. Data Subject Rights Management 

  • Act as the main point of contact for customers, policyholders, employees, agents, and other individuals regarding their personal data and privacy rights. 

  • Coordinate and manage escalated responses to data access requests, correction requests, withdrawal of consent, and privacy-related complaints. 

  • Ensure the handling of data subject rights is aligned with legal and regulatory standards. 

 

3. Personal Data Incident / Breach Management 

  • Establish and maintain data breach response plans, and conduct investigation, documentation, and reporting of breaches within prescribed timelines. 

 

4. Third-Party & Outsourcing Governance 

  • Review data privacy/protection due diligence for third-party vendors. 

  • Work with Legal and business units to support the facilitation of Data Processing Agreements by incorporating relevant clauses from Act 709, specifying MCIPD disclosure limitations, defining incident-reporting triggers, and establishing the right to audit. 

 

5. Regulatory Engagement & Reporting 

  • Act as the primary liaison with the Commissioner and other relevant regulatory bodies. 

  • Prepare and submit required documentation, reports, and notifications in relation to personal data processing and data breaches. 

  • Keep the organization informed of regulatory developments, enforcement trends, and compliance obligations. 

 

6. Training, Awareness and Culture 

  • Work with business unit heads to embed training on data protection and privacy risk subject for employees, sales intermediaries and or third-party service providers. Monitor implementation of an effective training curriculum. 

  • Conduct data protection and privacy training and communicating obligations to embed a culture of risks and controls within AIA Bhd. 

Minimum Job Requirements: 

  • Bachelor’s degree in law, Business Administration, Information Security, or a related field. 

  • Preferred certifications:  

  • Certified Information Privacy Professional (CIPP/A) 

  • Certified Information Privacy Manager (CIPM) 

  • Certified Data Protection Officer (CDPO) 

  • ISACA, IAPP, or similar accreditation 

 

Experience 

  • Minimum 7 - 10 years of experience in compliance, legal, or information security roles. 

  • At least 5 years in a data protection role, preferably in the insurance or financial services sector. 

  • Familiarity with managing group-level or multi-entity privacy governance. 

 

Skills & Attributes 

  • Deep understanding of Act 709 and global data protection standards (e.g., GDPR). 

  • Strong grasp of insurance operations, data flows, and third-party engagements. 

  • Knowledge of information technology and cybersecurity principles. 

  • High level of integrity, independence, and professional ethics. 

  • Strong communication, stakeholder management, and problem-solving skills. 

  • Ability to build awareness and promote a privacy culture throughout the organization. 

Build a career with us as we help our customers and the community live Healthier, Longer, Better Lives.

You must provide all requested information, including Personal Data, to be considered for this career opportunity. Failure to provide such information may influence the processing and outcome of your application. You are responsible for ensuring that the information you submit is accurate and up-to-date.

¿Listo para postularte en AIA?
Postúlate en AIA

Sobre AIA

At AIA we’ve started an exciting movement to create a healthier, more sustainable future for everyone. It's about finding new ways to not only better people's lives, but to better the communities and environments we live in. As the largest listed company on the Hong Kong Stock Exchange, we’ve been proudly making a difference for people and communities across Asia for over a century. And we build on this every day with our ambition to engage one billion people to live Healthier, Longer, Better Lives by 2030. If you work at AIA, you play an important part in this movement. Which is why we give you every opportunity to learn, grow and shape your career - your way. Inspiring and supporting you t

Ver todos los empleos en AIA →

Empleos similares

Harvey
Privacy and AI Counsel, EMEA
Harvey
⚡ Postúlate pronto Dublin Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 8h
Harvey
Privacy and AI Counsel, EMEA
Harvey
⚡ Postúlate pronto London Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 8h
Affirm
Compliance Manager (Data Protection Officer, Regulatory Compliance & Privacy)
Affirm
⚡ Postúlate pronto Remote UK · restringido por ubicación £101,000–£149,000
● Nuevo 👁 Visto ✓ Postulado hace 8h
Fiserv
Senior Legal Counsel – Privacy & AI
Fiserv
⚡ Postúlate pronto New York, New York Presencial $146,000–$244,800
● Nuevo 👁 Visto ✓ Postulado hace 12h
Roblox
Privacy & Security Counsel
Roblox
⚡ Postúlate pronto San Mateo, CA, United States Híbrido $168,100–$211,760
● Nuevo 👁 Visto ✓ Postulado hace 12h
Lvs1
Chief Information Security Officer and Privacy Officer
Lvs1
⚡ Postúlate pronto Calgary Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 16h
Coursera
Senior Privacy Counsel
Coursera
⚡ Postúlate pronto United States Presencial
● Nuevo 👁 Visto ✓ Postulado hace 20h
NG
Group Function - Privacy Legal Counsel
NetEase Games
⚡ Postúlate pronto Hong Kong; Singapore-Guoco Mid... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 23h
Verkada
Senior Privacy Counsel
Verkada
⚡ Postúlate pronto Austin, TX United States Presencial $1–$1
● Nuevo 👁 Visto ✓ Postulado hace 1d

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en AIA

Ver todos los empleos en AIA →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis