Data Protection Officer
jland group - jlg- Posted 3 hours ago
- Be among the first 10 applicants
Job Description
Company Description JLand Group (JLG) is the Real Estate & Infrastructure arm of Johor Corporation, with a portfolio spanning data centers, logistics, integrated industrial developments, and township projects. As a strategic real estate investor, JLG delivers end-to-end solutions that support a smarter and more sustainable future. The organization focuses on building digital-first and sustainable ecosystems that serve industry needs and long-term growth. JLG is committed to creating opportunities and generating lasting value for stakeholders. Team members join a forward-looking environment that emphasizes innovation, sustainability, and impact.
Role Description
Data Protection Governance & Compliance
Develop, implement and maintain the organisation's personal data protection and privacy governance framework in accordance with Act 709 and applicable regulatory requirements.
Monitor regulatory developments and assess their potential impact on the organisation's data processing activities.
Advise management and business functions on personal data protection obligations, risks and compliance requirements.
Establish and maintain appropriate policies, procedures, standards and guidelines relating to personal data protection.
Monitor the organisation's compliance with applicable data protection requirements and recommend corrective actions where necessary.
Maintain appropriate records and documentation relating to personal data protection activities.
Data Protection Risk Management
Identify, assess and monitor personal data protection and privacy risks arising from the organisation's business and data processing activities.
Provide risk-based advice on new and existing data processing activities.
Support the business in implementing appropriate technical and organisational measures to mitigate data protection risks.
Review data processing arrangements involving third parties, vendors, service providers and other relevant stakeholders.
Data Protection Impact Assessment (DPIA)
Lead or support the conduct of Data Protection Impact Assessments (DPIAs) for high-risk or complex personal data processing activities.
Assess privacy risks associated with new systems, technologies, projects, products, services and business processes.
Provide recommendations and mitigation measures to address identified privacy risks.
Monitor the implementation of agreed risk mitigation measures.
Data Breach & Security Incident Management
Act as a key advisor in the organisation's personal data breach and privacy incident management process.
Coordinate with relevant stakeholders, including IT, Cybersecurity, Legal, Risk, HR and business functions, in assessing and responding to personal data breaches.
Assist in determining regulatory notification and reporting requirements.
Coordinate the preparation and submission of required reports or notifications to the Personal Data Protection Commissioner within prescribed timelines.
Maintain appropriate records of personal data breaches, incidents, investigations and remedial actions.
Recommend measures to prevent recurrence and strengthen the organisation's data protection controls.
Data Subject Rights & Privacy Requests
Serve as a key point of contact for data subjects on matters relating to the processing of their personal data and their rights.
Oversee and advise on the handling of data subject requests, enquiries, complaints and privacy-related concerns.
Ensure that requests and complaints are assessed and addressed in accordance with applicable requirements and internal procedures.
Promote transparency and appropriate communication regarding the organisation's collection and use of personal data.
Privacy by Design & Business Advisory
Provide data protection and privacy advice during the development or implementation of new products, services, systems, technologies and business processes.
Promote Privacy by Design principles across relevant business initiatives.
Review privacy implications relating to data sharing, outsourcing, technology implementation, digital platforms and other data processing arrangements.
Provide practical recommendations that balance regulatory compliance, business requirements and data protection risks.
Third-Party & Data Sharing Management
Review and advise on personal data processing arrangements with third parties, including vendors, service providers, contractors and business partners.
Support the assessment of data protection requirements in contracts, data processing arrangements and information-sharing activities.
Advise on personal data transfers and data-sharing arrangements, including cross-border transfers where applicable.
Compliance Monitoring & Assurance
Conduct or coordinate periodic privacy compliance reviews, assessments and audits across relevant business functions.
Identify compliance gaps and work with responsible functions to develop and track remediation plans.
Prepare regular reports on the organisation's data protection compliance status, key risks, incidents and improvement initiatives for senior management.
Maintain appropriate compliance registers, including records of processing activities, DPIAs, privacy incidents and data protection actions where applicable.
Data Protection Awareness & Training
Develop and promote a strong data protection and privacy culture throughout the organisation.
Develop and deliver awareness programmes, briefings and training for employees and relevant stakeholders.
Provide targeted guidance to functions that regularly handle personal or sensitive personal data.
Keep employees informed of changes to data protection requirements and internal policies.
Regulatory & Stakeholder Engagement
Act as the organisation's key contact on personal data protection matters with the Personal Data Protection Commissioner / JPDP and other relevant regulatory or external stakeholders.
Coordinate regulatory correspondence, submissions and information requests relating to data protection matters.
Ensure the organisation's DPO information and relevant regulatory records are maintained and updated as required.
Management & Continuous Improvement
Provide regular updates to senior management on significant data protection risks, compliance matters and emerging regulatory developments.
Recommend improvements to strengthen the organisation's privacy governance framework.
Benchmark the organisation's practices against relevant industry standards and emerging privacy practices.
Perform other data protection and privacy-related responsibilities as assigned by management or required by applicable regulatory requirements.
Qualifications
- Bachelor's degree in Law, Information Technology, Cybersecurity, Compliance, Risk Management or a related discipline.
- Strong knowledge of the Personal Data Protection Act 2010 (Act 709) and relevant data protection requirements.
- Proven experience in privacy compliance, DPIA, data breach management and data protection risk assessment.
- Good understanding of data security, IT systems and personal data processing operations.
- Strong communication, analytical and stakeholder management skills, with high integrity and professional ethics.
- Proficient in Bahasa Melayu and English, both written and spoken.
- Relevant data protection/privacy certification (e.g. CIPP, CIPM) is an advantage.
- Strong communication, analytical and stakeholder management skills, with high integrity and professional ethics.
- Proficient in Bahasa Melayu and English, both written and spoken.
- Relevant data protection/privacy certification (e.g. CIPP, CIPM) is an advantage.
- Minimum 5 years of relevant experience in data protection, privacy, compliance or a related field, with hands-on DPO/Privacy Officer experience.
More Info
Key Skills
Personal Data Protection Act 2010 (Act 709)
Data breach management
Privacy by Design
IT systems
Data protection risk assessment
Bahasa Melayu
CIPM
Personal data processing operations
Data Protection Impact Assessment (DPIA)


