AXA logo

Manager - Data Privacy Compliance

AXA
19 hours ago
Full-time
On-site
Bangkok, Thailand
Manager

The Manager - Data Privacy Compliance is responsible for supervising and strengthening the organization's data privacy and personal data protection framework in compliance with Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA), applicable regulatory requirements, and relevant group policies. The role supports the Deputy DPO and DPO in providing independent oversight, advisory support, and practical governance across the Company and relevant group entities, with particular focus on the life insurance and financial services environment.

Key Responsibilities:

  • Supervise the day-to-day activities of the Data Privacy Team and ensure that privacy-related work is prioritized, completed accurately, and delivered within agreed timelines.
  • Support the Deputy DPO and DPO in overseeing compliance with the PDPA, subordinate regulations, regulatory guidance, and internal data protection policies across the Company and relevant group entities.
  • Develop, maintain, and enhance the organization's privacy governance framework, including policies, standards, procedures, operating guidelines, templates, and control mechanisms.
  • Advise business units and support functions on the lawful collection, use, disclosure, transfer, retention, and disposal of personal data throughout the information lifecycle.
  • Review and provide privacy advice on new products, services, distribution channels, digital initiatives, marketing activities, data analytics, artificial intelligence use cases, outsourcing arrangements, and material business changes.
  • Coordinate with the AI Compliance Officer and relevant Legal, Compliance, Risk, Information Security, Technology, and business teams to assess and manage AI systems and use cases integrated into personal data processing activities, including privacy-by-design requirements, lawful basis, transparency, data minimization, automated decision-making, security safeguards, human oversight, third-party risk, and ongoing compliance monitoring.
  • Lead or coordinate privacy impact assessments, data protection impact assessments, legitimate interest assessments, and other privacy risk assessments, as applicable.
  • Oversee the maintenance of records of processing activities, data inventories, consent and preference management processes, privacy notices, data retention schedules, and data-sharing documentation.
  • Coordinate the handling of data subject rights requests and ensure responses are complete, consistent, legally compliant, and delivered within statutory timelines.
  • Support the assessment, escalation, investigation, documentation, and regulatory notification of personal data breaches in collaboration with Information Security, Legal, Compliance, Risk, Operations, and other relevant stakeholders.
  • Review privacy clauses in contracts, data processing agreements, intra-group arrangements, vendor agreements, and cross-border data transfer mechanisms, in coordination with Legal and Procurement.
  • Monitor third-party and service-provider privacy risks, including due diligence, contractual safeguards, control assessments, remediation tracking, and ongoing compliance monitoring.
  • Design and deliver privacy awareness, role-based training, communications, and practical guidance for employees, management, agents, business partners, and other relevant stakeholders.
  • Establish and monitor privacy compliance metrics, key risk indicators, control testing results, incident trends, remediation plans, and management reporting for the Deputy DPO, DPO, senior management, and relevant committees.
  • Coordinate with regulators, external auditors, internal auditors, group privacy functions, and other assurance providers, as assigned by the Deputy DPO or DPO.
  • Promote a strong privacy culture and embed privacy-by-design and privacy-by-default principles into business processes, systems, products, and organizational decision-making.
  • Perform other data privacy, governance, compliance, or risk-management duties assigned by the Deputy DPO or DPO.

Qualifications:

  • Bachelor's degree or higher in Law, Information Technology, Computer Science, Cybersecurity, Information Security, Risk Management, Compliance, Business Administration, Finance, Insurance, or another relevant discipline.
  • At least 5 years’ experience in Compliance, Legal, Risk Management, Information Security Governance, Internal Control, or any related field; managerial or team-supervision experience is preferred.
  • Preferred 3 - 5 years of relevant experience in Data Privacy / Data Protection.
  • Experience in the financial services sector is preferred, with life insurance, insurance, banking, securities, or other regulated financial-sector experience considered a strong advantage.
  • Practical knowledge of the PDPA and its application to business operations, customer data, employee data, marketing activities, digital channels, vendors, and regulated financial services.
  • Hands-on experience implementing PDPA compliance frameworks and supporting the governance, risk assessment, or compliant deployment of artificial intelligence (AI) solutions in business operations, particularly where AI is integrated into personal data processing activities, is preferred.
  • Experience working with senior management and cross-functional stakeholders, including Legal, Compliance, Risk, Information Security, Technology, Operations, Human Resources, Marketing, Procurement, and Internal Audit.
  • Completion of recognized PDPA, data protection, privacy management, or DPO training programs offered by reputable educational institutions, professional bodies, or recognized training providers.
  • Relevant professional certification is preferred, such as equivalent privacy, compliance, information security, or risk-management credential.
  • Strong analytical, problem-solving, judgment, and risk-assessment capabilities, with the ability to translate legal and regulatory requirements into practical business controls.
  • High level of integrity, discretion, independence, and professionalism when handling confidential or sensitive information.
  • Good command of English, particularly effective listening and speaking skills, is preferred; strong business writing and presentation skills in English are an advantage.
  • Proficiency in Microsoft Office applications and the ability to work with privacy governance, risk, compliance, incident-management, or data inventory tools is advantageous.

 

About Krungthai-AXA Life Insurance 

Krungthai-AXA Life Insurance Public Company Limited, created from a solid co-investment partnership between Krungthai Bank PCL. and the AXA Group, global financial protection and asset-management specialists.

 

The trademark of Krungthai-AXA Life Insurance is designed to indicate the combination of the two corporations. Krung Thai Bank PCL. and AXA Group logos are aligned with Thai characters displaying the company name as Krungthai-AXA Life Insurance placed above the red line and the new company signature. Redefining/Life Insurance.

 

Today Krungthai-AXA Life Insurance Public Company Limited is a fast-growing life insurance company with a vision – Ambition AXA.

 

Our Perks and benefits 

  • Employee and Family Health Insurance Benefits
  • Life and Accident Insurance Benefits
  • Hybrid Working and Flexible Working Hours
  • Annual Leave & Birthday Leave
  • Salary Increment & Bonus
  • Digital Learning - Self Learning Organization
  • Annual Health Check up
  • Provident Fund