About this role
Data Compliance Officer (Legal)
- · Work Location:
o Ha Noi: Technopark, Gia Lam
Job overview
As a DPO, you will will lead the organization’s data protection, privacy, and compliance function, acting as a strategic partner to senior leadership in ensuring regulatory compliance while enabling sustainable business growth.
Key Responsibilities:
1 - Data Protection Officer (DPO)
- · Serve as the designated Data Protection Officer (DPO) in accordance with applicable personal data protection regulations.
- · Act as the official point of contact with competent regulatory authorities and data subjects.
- · Oversee personal data processing activities and ensure compliance with applicable legal and regulatory requirements.
- · Develop, maintain, and continuously enhance the organization's Personal Data Protection Framework, including policies, standards, and procedures.
2 - Data Compliance Governance
- · Monitor, document, and maintain records of data processing and data-sharing activities across member entities.
- · Conduct Personal Data Processing Impact Assessments (DPIA) and Cross-Border Data Transfer Impact Assessments.
- · Manage consent collection and consent management mechanisms, and oversee requests related to data subject rights.
- · Establish and operate incident response processes for personal data breaches and data leakage events, ensuring timely reporting in accordance with regulatory requirements.
- · Draft, review, and maintain data-sharing agreements between internal entities and third-party partners.
- · Translate legal and regulatory requirements into internal policies, standards, and operational controls; monitor regulatory developments and assess their impact on the organization.
- · Provide legal and compliance risk advisory for data-related use cases and initiatives.
- · Collaborate with Governance Partners and technical teams to implement and monitor compliance across business units, including data classification initiatives and onboarding of new entities.
Qualifications Required:
- · Bachelor's degree in Law or a related discipline; certifications or formal training in Personal Data Protection are preferred.
- · Minimum of 3 years of experience in legal, compliance, and/or personal data protection functions, meeting the qualification requirements for appointment as a Data Protection Officer (DPO) under applicable PDPL regulations.
- · Strong knowledge of Vietnam's Personal Data Protection Decree (PDPL), Decree No. 356/2025, the Data Law 2024, and Decree No. 165/2025; familiarity with GDPR is a strong advantage.
- · Solid understanding of the data lifecycle and fundamental technical concepts, including data pipelines, data storage, data classification, and data sharing, with the ability to effectively collaborate and communicate with technical teams.
- · Excellent legal drafting, policy development, and bilingual communication skills in both Vietnamese and English.
Preferred Skills:
- · Proven experience serving as a Data Protection Officer (DPO) or in a data compliance role within a large, diversified group structure with multiple subsidiaries.
- · Hands-on experience conducting Data Protection Impact Assessments (DPIAs) and Cross-Border Data Transfer Impact Assessments.
- · Demonstrated ability to drive compliance initiatives within a federated governance model involving multiple business units and stakeholders.
- · Understanding of data risk management principles and privacy considerations related to AI/ML systems and applications.
📩 Apply via:
Email: [email protected]
Zalo: 0372095828
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?