Overview
The Data Privacy Manager ("DPM") is responsible for upholding PepsiCo's privacy and data protection compliance policies, principles and standards across all functions in Greater China markets.
The DPM will report into the China Data Privacy Officer ("China DPO") and have a dotted reporting line into the APAC Data Privacy Officer ("APAC DPO").
The DPM will manage and support: (i) the operation of key privacy business processes, such as recording personal data processing activities, conducting risk assessments and handling personal data breaches; (ii) the Regional Data Privacy Councils; (iii) activities designed to promote a compliance culture and streamline and improve business privacy processes.
Responsibilities
• Stay close with business and ensure data processing activities are on data privacy compliance radar: Developing relationships with key stakeholders across the business to understand their current and planned data processing activities and comfortable in presence and communicate with director and senior director stakeholders
• Risk mitigation: Developing internal processes and policies and support the roll out of global/APAC Sector processes and policies to Greater China to mitigate key privacy risks
• Counselling and oversight: Providing privacy advisory and data management oversight for the Greater China business, projects and initiatives
• Standards, controls and policies: Driving and supporting the integration of and embedding of privacy standards, controls and policies into standard business processes
• Privacy risk assessments for functions engaged in data processing: Manages execution of privacy risk assessments, documents remediation plans, monitors their execution and provides appropriate updates to Privacy Councils. Connects on a regular basis with key stakeholders across BU and Functions to understand their current and planned data processing activities and develops strategies to ensure they are appropriately advised. Exercises judgement to raise key risk and compliance issues to the DPO and/or Legal and/or the Privacy Councils.
• Record of Processing Activities: Leads development of a baseline for and manages maintenance of a record of all personal data processing activities for the China BU on TrustArc or One Trust (e.g. personal data across all business areas from higher priority such as employee, consumer, direct customers, to lower priority business customers, partners, suppliers and contractors, investors). This will involve data mapping, assessment and remediation of PepsiCo China's existing systems and ensuring that going forward all new applications and processes processing personal information are appropriately recorded and assessed to determine whether they require a DPIA and (if so) ensuringone is undertaken and remediation actions are issued and closed out.
• Exercise of Data Subject Rights: Manages the data subject rights request process, partnering with data subject facing functions (Consumer Services, Insights and HR) in continuously endeavouring to improve the management of processes to permit data subjects to exercise their rights of access and deletion (including facilitating records location/extraction/consolidation/deletion) in a timely manner.
• Data protection by design: Supports the embedding of current privacy standards, controls and policies into "Business As Usual" and into overall ways the Business works with third parties who process PepsiCo personal data. This will involve assisting to formulate, embed and enforce protocols and ways of working with IT system owners across the business to ensure privacy is flagged and addressed in system design as early as possible and prior to PepsiCo onboarding.
Training and Awareness: Develops and manages the operation of a comprehensive privacy compliance training programme. Promotes privacy awareness throughout the business and maintains a regular cadence of communications to keep privacy on the business agenda.
• Privacy Councils: Supports the China DPO to lead quarterly Regional Privacy Councils as part of the PepsiCo global privacy governance framework, ensuring privacy risk/key privacy matters are raised and escalated appropriately and in accordance with PepsiCo's privacy policies and standards.
Qualifications
• A Bachelor degree or above in law or information technology/cyber security and data security
• 6+ years of dedicated working knowledge , and real-world experience of data protection and privacy best practice across multiple functions and geographies;
• Comprehensive knowledge of the requirements of the privacy, data and cybersecurity laws relevant to mainland China, Hong Kong and Taiwan market and the regulatory framework relating to privacy;
• Appreciation of IT architecture considerations, data encryption, data loss prevention with experience of online privacy issues and working knowledge of technologies which give rise to privacy considerations and solid risk assessment capabilities in complex and constantly evolving regulated areas;
• Experience on advising on digital products, marketing, sales and advertising technology, technology infrastructure, or other applications of privacy to tech configurations
• A deep understanding of the use of personal data and privacy risks faced by a large and complex multinational consumer goods company;
• Experience in using and navigating TrustArc (or similar online privacy management software);
• The ability to interpret legal advice and relate this to organisational practices and solutions
• The ability to quickly and accurately assess privacy and business risks in a fast-paced environment and make sound judgements
• Outstanding written and verbal communication skills in both English and Mandarin
• A commitment to high professional and ethical standards
• A strategic thinker with excellent judgement and the ability to communicate effectively with all levels of the organisation
• Excellent interpersonal skills
• CIPP, IAPP Certification, admission to practice law in PRC would be an advantage
Enthusiasm, a sense of humour and a love of getting the job done!