Skip to main content
Grant Thornton logo

Data Privacy Manager

Grant Thornton
2 hours ago
Full-time
On-site
Makati, Metro Manila, Philippines
Manager

Key Responsibilities


Privacy Program Governance
•    Support the design, implementation, and continuous improvement of the GCS’ privacy compliance framework in the Philippines.
•    Assist in establishing governance mechanisms, standards, policies, procedures, and controls related to personal data processing that align to GTA requirements
•    Monitor ongoing compliance with relevant privacy laws, regulations, and organizational requirements.
•    Provide guidance to business teams on privacy compliance obligations and best practices.
•    Creation and update of Records of Processing Activities (ROPAs) for both GCS and global privacy operations.
•    Ensure that GTA incident reporting policy is implemented in GCS operations and assist in implementation of technologies supporting incident reporting and processing globally.
•    Coordinate and attend meetings, emailing internal contacts for information as directed. 
•    Supporting Privacy review of products and services, creating review templates and identifying areas for more effective review.


Regulatory Compliance
•    Serve as the local privacy compliance resource for Philippine data protection matters.
•    Support compliance with the Philippine Data Privacy Act of 2012 and applicable implementing regulations.
•    Coordinate privacy registrations, regulatory submissions, and documentation requirements with relevant authorities when required.
•    Monitor legislative, regulatory and case law developments and recommend updates to internal processes and controls.
•    Consolidate requirements of, enforce and audit against privacy frameworks like DCPP, GDPR, CCPA, NIST, ISO (27001, 27559, 29100, 27701, 27559, DORA, EU AI Act, EU-US DPF)

Privacy Risk Management
•    Conduct privacy risk assessments and support Privacy Impact Assessments (PIAs).
•    Supporting Privacy review of products and services, creating review templates and identifying areas for more effective review.
•    Identify privacy risks associated with business processes, projects, systems, and third-party engagements.
•    Recommend mitigation controls and monitor remediation activities.
•    Maintain privacy risk registers and compliance documentation.


Incident Management
•    Support the investigation, assessment, and management of privacy incidents and data breaches.
•    Coordinate with Legal, Information Security, Risk, Compliance, and business stakeholders during incident response activities.
•    Assist in determining notification requirements and regulatory reporting obligations.
•    Maintain records of privacy incidents and corrective actions.


Global Privacy Operations Support
•    Report to the Global Privacy Team and support  
o    strategic privacy initiatives.
o    cross-border privacy compliance activities and global privacy governance programs.
o    privacy assessments, audits, reporting, and compliance monitoring activities.
o     privacy maturity across the organization.


Third-Party and Vendor Privacy Management
•    Review vendor privacy practices and support privacy due diligence activities.
•    Assist in evaluating data processing agreements and privacy-related contractual requirements.
•    Monitor privacy compliance obligations of third-party service providers.


Training and Awareness
•    Develop and deliver privacy awareness programs and training sessions.
•    Promote a strong culture of data protection and responsible information handling.
•    Create targeted training for employees, leaders, and stakeholders on privacy-related matters.


Audit and Compliance Support
•    Support internal and external audits involving privacy compliance requirements.
•    Assist with evidence gathering, control testing, and remediation activities.
•    Prepare privacy KPI metrics, governance reports, and management updates.


Qualifications


Education
•    Bachelor’s degree in law, Information Technology, Information Security, Business Administration, Risk Management, Compliance, Human Resources, or a related field.
•    Postgraduate qualification in Data Privacy, Law, Compliance, Risk Management, or Information Security is an advantage.


Experience
•    Extensive experience in implementing data privacy processes in global organizations to include implementation of privacy by design, risk management and compliance support.
•    Bachelor's degree or equivalent (computer science, data science, IT) 
•    5+ years’ experience implementing privacy enhancing technologies in data lakes, software, IT infrastructure and applications.
•    Certifications (e.g., CISSP, CISM, or CISA preferred)
•    AI product development experience.
•    Project planning experience (PMP or similar certification).
•    Experience in professional services organizations.
•    Excellent verbal and written communication skills.
•    Travel percentage: 5% (may be occasional travel if required)
 


Preferred Certifications
One or more of the following certifications is highly preferred:
•    Certified Information Privacy Professional (CIPP/A, CIPP/E, or CIPP/US)
•    Certified Information Privacy Manager (CIPM)
•    Certified Information Privacy Technologist (CIPT)
•    ISO 27701 Lead Implementer or Lead Auditor
•    Certified Information Systems Security Professional (CISSP)
•    Data Privacy Competency certification from the National Privacy Commission (NPC)


Key Competencies
Technical Competencies
•    Privacy compliance and governance
•    Data Protection Impact Assessments (DPIAs)
•    Privacy incident management
•    Regulatory compliance
•    Third-party risk management
•    Privacy by Design principles
•    Data lifecycle management
•    Records management


Behavioral Competencies
•    Strong stakeholder management
•    Analytical and problem-solving capability
•    Excellent communication and presentation skills
•    High professional integrity and confidentiality
•    Ability to influence across functions and geographies
•    Strong project management and organizational skills


Success Measures
Within the first 12 months, the successful candidate will:
•    Support the establishment and maturation of the Philippines privacy compliance framework.
•    Improve visibility and governance of personal data processing activities.
•    Strengthen privacy risk assessment and monitoring capabilities.
•    Enhance privacy awareness across business teams.
•    Contribute to global privacy initiatives and cross-border compliance programs.
•    Establish effective partnerships with Risk, Legal, Compliance, Information Security, HR, and Operations teams.