You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do. Discover how you can make a difference in the lives of individuals, families and communities around the world.
Job Description:
The Privacy Compliance Specialist shall serve as a subject matter expert with respect to Data Privacy Program. The successful candidate shall help the Data Privacy Officer (DPO) in the promotion, facilitation, monitoring and assessment of compliance of Sun Life Philippines entities to certain requirements and policies in accordance with the Privacy Policy and the Compliance Risk Management Framework (CRMF).
Job description / Description du poste
- Provide advisory service on privacy incident reporting, which includes (i) assisting management in identifying, assessing, tracking, and coordinating resolution of privacy incidents; and (ii) overseeing contact with regulators, with respect to privacy incident management and reporting;
- Conduct Privacy Impact Assessment (PIA) for new initiatives or if there are significant changes to processes involving the processing of personal information. Identify privacy gaps and recommend controls to mitigate privacy risks, if any;
- Review contracts and service agreements of Business Units (BUs) to ensure inclusion of data privacy requirements;
- Provide day-to-day communication and collaboration with functional teams and points of contact for the effective implementation of data privacy policy and operating guidelines.
- Support compliance reviews for key business projects, digital initiatives, and process changes;
- Support the development and execution of training and awareness programs for internal and external stakeholders on all data privacy policy and operating guidelines. This includes supporting business group wide awareness training as well as detailed guideline training within the business areas, if required;
- Assess risk and control effectiveness within the business unit as it relates to data privacy and identify and prioritize opportunities to improve risk management by conducting periodic independent testing/monitoring of the effectiveness of key process controls;
- Monitor the roll-out of new/changed compliance requirements and support internal clients in designing solutions that meet business objectives; Ensure that regulatory and internal requirements are implemented, and controls are in place to ensure compliance with requirements, including assisting in educating the BU on new policies, guidelines, and regulatory requirements and to provide inputs on potential impact to their operations;
- Assist the business in performing risk assessments for data privacy;
- Maintain records of all data processing activities carried out by the Company;
- Prepare periodic compliance reports for Management and Regional and Corporate Office and ensure timely and accurate responses to internal and external queries;
- Support reviews conducted by Internal Audit and internal monitoring and testing team as well as external auditors and regulators;
- Ensure that interactions with National Privacy Commission (NPC) is well coordinated and regulatory requests are managed and implemented without delay;
- Perform any other relevant tasks, as may be required by the team.
Preferred skills / Compétences particulières
- Knowledge and experience of data privacy laws and regulations governing financial institutions, particularly on asset management, insurance, and banking operations.
- Experience in performing control functions, privacy operations or data/information analytics or similar roles.
- Knowledge of Agile values and principles from the Agile Manifesto and/or familiarity with Agile methodologies like Scrum, Kanban, etc.,
- Proficient in MS Office Applications and related applications
- Demonstrated ability to make sound recommendations to the business and influence business decisions based on thorough analysis, business knowledge and risk consulting expertise.
- Strong and flexible problem-solving capabilities, willing to challenge the ‘status quo’ and recommend innovative control solutions.
- Strong analytical, comprehension, and presentation skills.
- Strong time management and prioritization skills.
- Confident verbal and written communication skills.
- Ability to work with various stakeholders across different levels in the organization, including senior management.
Qualifications / Compétences
- The candidate should have the following: (i) a 4-year university degree; and (ii) at least 3 to 5 years technical experience in data privacy.
- Professional certification in data privacy (e.g., CIPP/E, CIPM) and experience in compliance, risk, and internal audit in life insurance, mutual funds, banks or financial services industry is an advantage.
Job Category:
Compliance
Posting End Date:
30/03/2025