-
Design and implement comprehensive personal data protection policies and procedures (covering GDPR, UK GDPR, CCPA/CPRA, PDPA, and others);
-
Conduct gap assessments across jurisdictions, including review of processing registers, DPIAs, and data storage/transfer mechanisms;
-
Map personal data flows and define controller/processor roles in various countries;
-
Establish incident and PII breach response procedures, including regulator and data subject notification frameworks;
-
Ensure the enforcement of data subject rights (access, deletion, correction, etc.) and help develop user-facing interfaces for rights execution;
-
Support and coordinate Data Protection Officers (DPOs) and local privacy contacts where required;
-
Deliver regular privacy training sessions for staff involved in personal data processing;
-
Collaborate closely with IT and Product teams to embed privacy by design and privacy by default principles;
-
Oversee data localization and international data transfer projects, including Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), etc.;
-
Monitor regulatory developments globally and continuously improve internal data privacy practices;
-
Report regularly to executive leadership and the Board on privacy risks and mitigation strategies.