Data Privacy Manager
Grant ThorntonKey Responsibilities
Privacy Program Governance
• Support the design, implementation, and continuous improvement of the GCS’ privacy compliance framework in the Philippines.
• Assist in establishing governance mechanisms, standards, policies, procedures, and controls related to personal data processing that align to GTA requirements
• Monitor ongoing compliance with relevant privacy laws, regulations, and organizational requirements.
• Provide guidance to business teams on privacy compliance obligations and best practices.
• Creation and update of Records of Processing Activities (ROPAs) for both GCS and global privacy operations.
• Ensure that GTA incident reporting policy is implemented in GCS operations and assist in implementation of technologies supporting incident reporting and processing globally.
• Coordinate and attend meetings, emailing internal contacts for information as directed.
• Supporting Privacy review of products and services, creating review templates and identifying areas for more effective review.
Regulatory Compliance
• Serve as the local privacy compliance resource for Philippine data protection matters.
• Support compliance with the Philippine Data Privacy Act of 2012 and applicable implementing regulations.
• Coordinate privacy registrations, regulatory submissions, and documentation requirements with relevant authorities when required.
• Monitor legislative, regulatory and case law developments and recommend updates to internal processes and controls.
• Consolidate requirements of, enforce and audit against privacy frameworks like DCPP, GDPR, CCPA, NIST, ISO (27001, 27559, 29100, 27701, 27559, DORA, EU AI Act, EU-US DPF)
Privacy Risk Management
• Conduct privacy risk assessments and support Privacy Impact Assessments (PIAs).
• Supporting Privacy review of products and services, creating review templates and identifying areas for more effective review.
• Identify privacy risks associated with business processes, projects, systems, and third-party engagements.
• Recommend mitigation controls and monitor remediation activities.
• Maintain privacy risk registers and compliance documentation.
Incident Management
• Support the investigation, assessment, and management of privacy incidents and data breaches.
• Coordinate with Legal, Information Security, Risk, Compliance, and business stakeholders during incident response activities.
• Assist in determining notification requirements and regulatory reporting obligations.
• Maintain records of privacy incidents and corrective actions.
Global Privacy Operations Support
• Report to the Global Privacy Team and support
o strategic privacy initiatives.
o cross-border privacy compliance activities and global privacy governance programs.
o privacy assessments, audits, reporting, and compliance monitoring activities.
o privacy maturity across the organization.
Third-Party and Vendor Privacy Management
• Review vendor privacy practices and support privacy due diligence activities.
• Assist in evaluating data processing agreements and privacy-related contractual requirements.
• Monitor privacy compliance obligations of third-party service providers.
Training and Awareness
• Develop and deliver privacy awareness programs and training sessions.
• Promote a strong culture of data protection and responsible information handling.
• Create targeted training for employees, leaders, and stakeholders on privacy-related matters.
Audit and Compliance Support
• Support internal and external audits involving privacy compliance requirements.
• Assist with evidence gathering, control testing, and remediation activities.
• Prepare privacy KPI metrics, governance reports, and management updates.
Qualifications
Education
• Bachelor’s degree in law, Information Technology, Information Security, Business Administration, Risk Management, Compliance, Human Resources, or a related field.
• Postgraduate qualification in Data Privacy, Law, Compliance, Risk Management, or Information Security is an advantage.
Experience
• Extensive experience in implementing data privacy processes in global organizations to include implementation of privacy by design, risk management and compliance support.
• Bachelor's degree or equivalent (computer science, data science, IT)
• 5+ years’ experience implementing privacy enhancing technologies in data lakes, software, IT infrastructure and applications.
• Certifications (e.g., CISSP, CISM, or CISA preferred)
• AI product development experience.
• Project planning experience (PMP or similar certification).
• Experience in professional services organizations.
• Excellent verbal and written communication skills.
• Travel percentage: 5% (may be occasional travel if required)
Preferred Certifications
One or more of the following certifications is highly preferred:
• Certified Information Privacy Professional (CIPP/A, CIPP/E, or CIPP/US)
• Certified Information Privacy Manager (CIPM)
• Certified Information Privacy Technologist (CIPT)
• ISO 27701 Lead Implementer or Lead Auditor
• Certified Information Systems Security Professional (CISSP)
• Data Privacy Competency certification from the National Privacy Commission (NPC)
Key Competencies
Technical Competencies
• Privacy compliance and governance
• Data Protection Impact Assessments (DPIAs)
• Privacy incident management
• Regulatory compliance
• Third-party risk management
• Privacy by Design principles
• Data lifecycle management
• Records management
Behavioral Competencies
• Strong stakeholder management
• Analytical and problem-solving capability
• Excellent communication and presentation skills
• High professional integrity and confidentiality
• Ability to influence across functions and geographies
• Strong project management and organizational skills
Success Measures
Within the first 12 months, the successful candidate will:
• Support the establishment and maturation of the Philippines privacy compliance framework.
• Improve visibility and governance of personal data processing activities.
• Strengthen privacy risk assessment and monitoring capabilities.
• Enhance privacy awareness across business teams.
• Contribute to global privacy initiatives and cross-border compliance programs.
• Establish effective partnerships with Risk, Legal, Compliance, Information Security, HR, and Operations teams.