Summary:
The Compliance Manager oversees the company's data protection and corporate compliance programs, ensuring adherence to the Personal Data Protection Act (PDPA), internal policies, and relevant regulations. This role manages data privacy, cross-border data transfers, anti-bribery, fraud prevention, and business ethics initiatives, while driving training and awareness across all departments to uphold high standards of compliance and governance.
Responsibilities:
Personal Data Protection Act (PDPA) Compliance:
- Ensure compliance with PDPA and other relevant data protection laws across all business functions.
- Develop, implement, and maintain PDPA policies and procedures to ensure the safeguarding of personal data across manufacturing, retail, and supply chain operations.
- Conduct regular data protection impact assessments (DPIAs), maintain and monitor the company's Records of Processing Activities (RoPA) / Data Inventory Mapping as well as ensure the proper documentation of all data processing activities.
- Develop and execute incident response plans for data breaches, ensuring timely reporting and compliance with PDPA regulations.
- Oversee PDPA cross-border data transfer compliance, ensuring that appropriate safeguards are in place for the lawful transfer of personal data across borders.
Company Data Compliance:
- Oversee the company's broader data compliance program, ensuring that data used for business operations (including customer, employee, and operational data) adheres to internal policies and industry regulations.
- Develop, implement, and maintain internal data management policies, including data classification, retention, access control, and disposal.
- Conduct audits to ensure company data is protected and handled in accordance with internal and external standards, including compliance with applicable laws.
- Advise on data-related compliance issues that arise within the business, including manufacturing, retail sales, and IT functions.
Compliance Management:
- Lead the company's compliance program across all areas, including anti-bribery, fraud prevention, and business ethics, ensuring adherence to local and international regulations.
- Develop, implement, and enforce compliance policies for business ethics, fraud prevention, conflicts of interest, and anti-bribery.
- Monitor and ensure that the company's operations adhere to all regulatory requirements across its various business functions.
- Work closely with risk team to identify and mitigate compliance risks across the organization.
Training and Awareness:
- Develop and deliver PDPA and company data compliance training programs to raise awareness across all departments, ensuring employees understand their responsibilities related to data protection and internal data management.
- Conduct regular training sessions on anti-bribery, fraud prevention, and other compliance topics to maintain high standards of business ethics across the company.
Other Compliance-Related Matters:
- Assist in addressing any legal and regulatory inquiries or investigations related to compliance matters across the organization.
- Undertake any other compliance-related tasks as assigned by superior or as required by the company.
- Ensure effective compliance reporting and presentations by providing regular, accurate compliance updates to senior management, regulators, and auditors, as required.
Requirements:
- Bachelor's degree in Law, Business Administration, Compliance, or a related field.
- Prior experience as Data Protection Officer (DPO) will be added advantage.
- Must have experience in managing SOPs, policies, and governance frameworks.
- At least 5 years of experience in developing and managing compliance programs, including PDPA, company data management and compliance policies, ideally in the automotive, manufacturing or retail sectors.
- In-depth knowledge of data protection laws, including PDPA and cross-border data transfer regulations.
- Strong communication, leadership, and training skills, with the ability to engage and educate employees at all levels on compliance issues.
- Able to work independently and collaborate effectively within a team.
- Proactive and capable of multitasking, with the ability to propose new initiatives and solutions.
- Fluent in English, Bahasa Malaysia and Mandarin (Preferable)