Mott MacDonald logo

Senior Privacy and Data Protection Advisor

Mott MacDonald
1 hour ago
Full-time
On-site
Bengaluru, Karnataka, India
Advisor

Mott MacDonald is a global engineering, management, and development consultancy committed to delivering impactful work that shapes the future.


We are a team of over 20,000 experts working across the world in more than 50 countries.
We are proud to be part of an ever-changing global industry, delivering transformative work that’s defining our future. It’s our people who power that performance. As an employee-owned business, we invest in creating a space for everyone to feel safe and valued and empowered with the right tools and support. 


Whether you want to pursue excellence in your specialism or broaden your experience with flexible roles across our business, you’ll be connected to a community of global experts championing you to be your best. Join us and shape your story with Mott MacDonald, where everyone has the opportunity to be brilliant.

 

Job profile 

 

The Group Privacy and Data Protection Officer and his team operate as a global advisory, compliance, and assurance function. The role of Senior Privacy and Data Protection Advisor is focussed on supporting these activities across South Asia, Southeast Asia, East Asia, Australia, and New Zealand. 

 

Although India (the location of approximately 1,800 of our employees), Australia (hosting around 900 employees) and Hong Kong (hosting around 400 employees) are Mott MacDonald’s largest hubs within the Asia-Pacific region, the Group also has a presence in the following jurisdictions: China, Indonesia, Japan, Malaysia, New Zealand, Singapore, South Korea, Taiwan and Thailand (with approximately 800 employees distributed across those countries). 

 

Job description 

 

  • Informing and advising colleagues across the Asia-Pacific of their obligations under our global privacy and data protection compliance framework and applicable privacy and data protection laws (including the Indian Digital Personal Data Protection Act, Australian Privacy Act, Hong Kong Personal Data (Privacy) Ordinance, Singapore Personal Data Protection Act, Thailand Personal Data Protection Act, New Zealand Privacy Act, Indonesian Personal Data Protection Law, UK GDPR, and EU GDPR). 

  • Working with colleagues in our legal, procurement, and commercial functions to ensure that appropriate contractual safeguards (covering the collection, use, disclosure, storage, and destruction of personal information) are in place between Mott MacDonald and its clients, suppliers, and other commercial partners.  

  • Working with internal stakeholders (including IT and cyber/information security teams) to co-ordinate the timely identification, reporting, logging, investigation, notification (to relevant regulatory authorities and affected individuals), and resolution of personal data breaches. 

  • Supporting the completion and maintenance of our ‘record of processing activities’ to ensure compliance with record-keeping, transparency, and accountability requirements under relevant policies and legislation. 

  • Advising colleagues when/how to complete Privacy Impact and Risk Assessments (PIRAs), AI Risk Assessments (AIRAs), International Transfer Risk Assessments (ITRAs), PII Integrity and Compliance Assessments (PICAs), PII Asset Discovery Questionnaires (ADQs) in the context of new/evolving projects, initiatives and technologies. 

  • Evaluating completed assessments (PIRAs, AIRAs, TIRAs, PICAs, and ADQs), providing feedback, recommending appropriate risk treatments/mitigations, and then monitoring their implementation. 

  • Providing advice and guidance to colleagues on the identification, logging, evaluation, and timely resolution of individual rights requests (for example, requests from job applicants or former employees who want to obtain copies of their personal information). 

  • Working with colleagues in our legal function (and with external legal advisers) to ensure appropriate arrangements are in place covering international intra-group transfers of personal information. 

  • Contributing to the development and maintenance of our privacy and data protection compliance framework (including policies, requirements, guidance, work instructions, consent statements, and privacy information notices). 

  • Co-ordinating the activities of internal privacy and data protection champions across the Asia-Pacific, arranging quarterly briefings and helping to maintain appropriate coverage (at least one ‘Privacy Practitioner’ in each jurisdiction). 

  • Delivering training and contributing to the development of eLearning and Intranet content which helps colleagues understand their responsibilities under privacy and data protection legislation. 

  • Providing advice and guidance to colleagues on the identification, definition, recording, evaluation, mitigation, and treatment of risks related to the processing of personal information. 

  • Investigating and responding to privacy and data protection concerns/complaints raised by individuals (including employees, job applicants, client contacts, and members of the public) whose personal information is processed by Mott MacDonald.  

  • Providing advice and guidance to HR colleagues on the handling of disciplinary matters involving employee misuse of (or unauthorised access to) personal information. 

  • As required, liaising with privacy and data protection regulators across the Asia-Pacific and building constructive working relationships with those organisations. 

 

 

Candidate specification 

Essential: 

 

  • Experience of providing pragmatic expert advice on the interpretation and application of privacy and data protection laws (and associated regulatory frameworks) in one or more jurisdictions within the Asia-Pacific region. 

  • Able to identify and respond to a range of privacy and data protection compliance challenges (including changes to the law, new regulatory guidance, and emerging technologies) and work with colleagues to identify pragmatic cost-effective solutions.  

  • Experience of co-ordinating the resolution of individual rights requests and/or complaints by individuals about the processing of their personal information. 

  • Experience of contributing to the response to personal data breaches and assessing their potential impact on the affected individuals (as well as the organisations involved). 

  • A confident and articulate self-starter able to manage and prioritise a large and varied workload, work independently, take decisions on your own initiative within defined parameters, and meet challenging deadlines (whilst managing the expectations of others). 

  • Able to assimilate and interpret information quickly; and can explain complex processes or requirements to colleagues without using confusing technical or legal jargon. 

  • Able to communicate and negotiate effectively with colleagues at all levels of an organisation and influencing decision-making by linking compliance requirements to business objectives/outcomes. 

  • Able to communicate effectively (and respectfully) with colleagues, data subjects, commercial partners and other external stakeholders irrespective of national boundaries and cultures. 

  • Able to handle confidential information with discretion; with a strong commitment to maintaining their personal/professional integrity and upholding the highest ethical and professional standards.  

  • Excellent IT and administrative skills (including extensive experience of using SharePoint and other Microsoft applications). 

  • Possesses the confidence and self-awareness required to identify gaps in their own knowledge and the intellectual curiosity required to continually develop their professional expertise. 

 

Desirable: 

 

  • An awareness of privacy and data protection laws (and associated regulatory frameworks) in jurisdictions outside the Asia-Pacific region, including the United Kingdom and/or European Union.  

  • An awareness of the privacy law reforms being implemented across the Asia-Pacific region and their potential impact on commercial enterprises (including multinational companies). 

  • Experience of evaluating systems and/or processes and recommending corrective actions required to achieve compliance with applicable privacy and data protection legislation/policies. 

  • Experience of co-ordinating the response to investigations by privacy and data protection regulators. 

  • Experience of supporting and promoting behaviour change (focussed on building an effective privacy and data protection compliance culture) within a large, complex, multi-site organisation.  

  • Holds at least one recognised privacy and data protection qualification or certification (for example the CIPP/A, CIPT, CIPM, or CIPP/E). 

  • Experience of using OneTrust, CoreStream, or the privacy management and compliance modules of another SaaS GRC system/application. 

 

Flexible working
At Mott MacDonald, we support our staff to create work-life balance which works for them and welcome candidates looking for career flexibility. We are open to discussing flexible working at interview stage.

 

Our benefits package is designed to enhance your experience:

  • Agile working
  • Critical illness and compassionate leave
  • Paternity Leave
  • Group term life insurance, and Group medical insurance coverage
  • Career mobility options
  • Short and Long-term global employment opportunities
  • Global collaboration and knowledge sharing

 

Employment Compliance Requirement

As part of our global compliance requirements, all candidates must hold a valid Right to Work (RTW) document in India, which will be verified during the recruitment process.
Acceptable documents include a Passport, Voter ID, or Birth Certificate.
By applying, you confirm that you can provide valid documentation if and when required.