Develop, implement, and maintain the APAC Data Protection Framework, aligned to global GIDS standards
Ensure compliance with applicable privacy laws, including the Australian Privacy Act, the Australian Privacy Principles and other relevant APAC regulations
Embed consistent data governance, privacy, and protection standards across the business
Lead and oversee Privacy Impact Assessments (PIAs) and data risk assessments
Provide guidance on the identification, assessment, and mitigation of privacy and data risks
Maintain oversight of key privacy risks, incidents, and control effectiveness
Partner with Product, Technology, and Business teams to: o ensure privacy-by-design and data protection principles are embedded in solution design o support new product development and change initiatives
Provide subject matter expertise on data handling, cross-border transfers, and regulatory obligations
Support the business in assessing and governing the use of AI and emerging technologies
Ensure appropriate data governance and protection frameworks are in place to support responsible AI adoption
Provide oversight to ensure compliance with privacy and ethical data use standards
Provide oversight and guidance on privacy incidents and breaches
Support regulatory reporting obligations where required
Act as a key point of contact for privacy-related regulatory matters in APAC
Develop and deliver privacy and data protection training programs
Promote a strong privacy and data protection culture across the organisation
Establish and support privacy governance forums and reporting frameworks
Provide regular reporting to: o APAC Risk & Compliance leadership o Global Data Protection Office
Support audits, reviews, and assurance activities
Work closely with the UK Director, Data Protection to ensure alignment with the global GIDS Data Protection Framework
Collaborate with the broader Global Data Protection Office and enterprise Line 2 teams
Contribute to global initiatives and continuous improvement of data protection practices
Requirements
Proven experience in data protection, privacy, or data governance roles (ideally within financial services).
Minimum 5 years experience preferred.
Strong knowledge of: o Australian Privacy Act, Australian Privacy Principles and APAC privacy regimes o Data governance and protection frameworks and practices o Regulatory expectations in outsourcing / financial services environments.
Experience supporting product development and technology change.
Familiarity with AI governance, data ethics, and emerging technology risks.
Relevant qualifications or certifications (e.g. CIPP, CIPM, Law, Risk/Compliance) preferred.