JOB SUMMARY
Work assigned is not limited to the job scope listed below, may be assigned to another function based on the workload and requirement:
- Support the implementation, administration, and monitoring of EPF's Data Protection Programme to ensure compliance with the Personal Data Protection Act (PDPA), internal policies, standards, procedures, and governance requirements.
- Support the operationalisation of data protection requirements across business processes, projects, systems, and initiatives to promote the lawful, secure, and responsible handling of personal data throughout its lifecycle.
- Support the identification, assessment, monitoring, and reporting of data protection risks, and the implementation of appropriate controls to safeguard personal and sensitive personal data.
- Support the administration and coordination of Data Protection Impact Assessments (DPIAs), personal data breach management, data subject rights requests, external data sharing assessments, cross-border transfer reviews, cloud data usage reviews, third-party privacy assessments, and other privacy-related activities.
- Support the maintenance of data protection records, inventories, registers, repositories, and trackers to facilitate monitoring, reporting, compliance, and audit readiness.
- Promote awareness, accountability, and good data handling practices across EPF to foster a strong data protection culture.
JOB RESPONSIBILITIES
- Assist in implementing, maintaining, and reviewing data protection policies, procedures, standards, guidelines, templates, checklists, and operational controls to support compliance with the PDPA, regulatory requirements, and internal governance requirements.
- Support advisory activities relating to the collection, use, disclosure, sharing, retention, storage, transfer, and disposal of personal data by gathering information, preparing documentation, and coordinating responses to business units and stakeholders.
- Assist in monitoring regulatory developments, emerging privacy trends, industry best practices, and internal policy updates through research, impact assessments, and the preparation of supporting materials.
- Support the administration, coordination, and documentation of DPIAs, Records of Processing Activities (ROPA), external data sharing assessments, cross-border transfer reviews, cloud data usage reviews, third-party privacy assessments, and other data protection risk assessments
- Assist in identifying, documenting, monitoring, and reporting data protection risks, control gaps, remediation actions, and control improvements arising from assessments, incidents, projects, audits, and stakeholder engagements.
- Prepare and maintain data protection reports, dashboards, metrics, governance materials, minutes, and supporting documentation for management reporting, regulatory submissions, governance forums, audits, inspections, awareness programmes, training initiatives, and other data protection activities.
- Coordinate with Data Owners, Data Stewards, Information Security, Legal, Risk, Human Capital, Procurement, technology teams, business units, and other stakeholders to support the implementation and operationalisation of data protection requirements.
- Support the monitoring and administration of the EPF's Data Protection Programme, including tracking compliance activities, action plans, governance initiatives, and programme deliverables.
- Perform any other data protection, governance, compliance, reporting, documentation, administrative, or operational duties assigned by the Head of Unit from time to time.
- Act as the secretariat for the Data Governance Working Committee (DGWC) and Data Governance Committee (DGC), ensuring timely coordination and communication of initiatives and progress
JOB REQUIREMENTS
- Malaysian citizen.
- Pass Malay Language, including an oral test, at the Sijil Pelajaran Malaysia (SPM) level or equivalent as recognised by the Government.
- Possess Bachelor's degree in Law, Information Security, Cybersecurity, Computer Science, Information Systems, Data Science, Risk Management, Business Administration, or any other relevant discipline.
- Possess 2 - 4 years relevant experience in data protection, privacy, data governance, information security, risk management, regulatory compliance, technology governance, or related fields.
- Basic knowledge of data protection/privacy laws and frameworks (e.g. PDPA, GDPR), data lifecycle management, privacy risk assessment, and information governance practices.
- Professional certifications such as CIPP/E, CIPM, CDMP (DAMA), or equivalent are an advantage.
- Proficient in Microsoft Office Suite.
- Resourceful, proactive, and technology-savvy, with the ability to leverage digital and AI-enabled tools to improve productivity, analytical capabilities, and work efficiency.
- Strong analytical, organisational, communication, and interpersonal skills, with the ability to work independently and collaboratively in a team environment and deliver effectively under pressure.
JOB STATUS
Permanent
PLACEMENT
Data Governance Office Section, Investment Services Department
All applications are strictly CONFIDENTIAL and only shortlisted candidates will be called in for interview. Applications are deemed UNSUCCESSFUL if there is no feedback from the EPF 2 MONTHS after the closing date of advertisement.