Position Summary:
Privacy Specialist ensures compliance with the Personal Data Protection Act (PDPA) and related regulations. This role involves managing privacy policies, providing expert guidance, monitoring regulatory updates, and supporting privacy initiatives across Central Group. Additionally, the specialist will conduct employee training and promote a culture of data protection.
Key Responsibilities:
- Provide expert consultation to ensure compliance with PDPA and related regulations.
- Identify and assess risks related to personal data handling and propose effective mitigation strategies.
- Maintain and update Records of Processing Activities (ROPA) to ensure accuracy and compliance.
- Review, draft, and refine Central Group’s privacy policies to align with evolving regulations.
- Evaluate the necessity of Privacy Impact Assessments (PIA) and Data Protection Impact Assessments (DPIA).
- Conduct PIA/DPIA to identify and mitigate potential data protection risks.
- Oversee the handling of personal data breaches, including investigation, reporting, and corrective actions.
- Monitor and stay updated on changes to PDPA and related regulations to ensure Central Group’s compliance.
- Design and deliver training programs to educate employees on PDPA requirements and best practices.
- Foster a culture of data privacy awareness across the organization.
- Respond to data subject requests (e.g., access, correction, or deletion) in compliance with PDPA.
- Prepare and present compliance reports to management and relevant authorities.
Qualifications:
- Bachelor’s or master’s degree in Law, Information Technology, Security or a related field.
- In-depth knowledge of PDPA and other data protection regulations.
- At least 3 years of experience in data protection, compliance, or related fields.
- Exceptional research abilities, verbal and written communication skills, and strong analytical and problem-solving capabilities.
- Excellent communication and interpersonal skills for training and stakeholder engagement.
- Certification in data protection or privacy (e.g., Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM)) is an advantage.
- Strong verbal and written communication skills in English.
Kriangsak, jakriangsak@central.co.th