Senior Assistant Director / Deputy Director, Group Compliance
Job Summary
Frasers Property is seeking an experienced and commercially minded Group Data Protection Officer (DPO) to lead and strengthen our data privacy and protection programme across multiple international markets. Being part of the Group Compliance function within Group Risk Management, this role offers the opportunity to influence data privacy / protection at an enterprise level, working closely with Business Unit (BU) Data Protection Officers and senior stakeholders across the Group. You will play a critical role in ensuring that our personal data protection framework remains robust, practical and aligned with evolving regulatory requirements across the jurisdictions in which we operate.This position is ideal for a proactive compliance professional who enjoys working in a complex, multinational environment, balancing regulatory requirements with business objectives while driving a strong culture of data protection and accountability.
Why Join Us
This is a unique opportunity to lead and shape the privacy agenda for a diversified multinational organisation operating across multiple markets. You will work closely with senior leaders, influence strategic decision-making and play a key role in strengthening data governance and compliance across the Group while contributing to broader risk and compliance initiatives. If you are passionate about privacy, governance and building best-in-class compliance programmes, we would love to hear from you.
Job Description
Data Privacy / Protection Leadership
- Serve as the Group Data Protection Officer (DPO) and provide strategic leadership for the Group's data privacy and protection programme:
Develop, enhance and oversee the implementation of the Group Personal Data Protection Framework, ensuring compliance with applicable data protection laws and regulations across all operating markets. - Maintain and continuously improve related policies, standards and guidelines, including:
- Personal Data Protection Policy
- Data retention and records management requirements
- Data breach management procedures
- Privacy governance standards and controls
Privacy Risk Management
- Partner with Business Unit Data Protection Officers and relevant functions to drive consistent adoption of the Group framework across all jurisdictions.
- Monitor regulatory developments and assess their impact on the Group's privacy obligations and governance practices.
- Provide practical and risk-based guidance on privacy-related matters, ensuring compliance requirements are embedded into business operations.
- Review and advise on Data Protection Impact Assessments (DPIAs), identifying privacy risks and recommending effective mitigation measures.Oversee key privacy governance processes:
- Records of Processing Activities (ROPA)
- Data Subject Requests (DSRs)
- Data Processing Agreements (DPAs)
- Privacy incident and breach management
- Support and coordinate responses to personal data breaches, including assessment, investigation, remediation and regulatory notification requirements where applicable.
Stakeholder Engagement & Advisory
- Act as the primary point of contact for data protection authorities, regulators and data subjects on privacy-related matters.
- Build strong partnerships with business, legal, technology and risk stakeholders to promote effective privacy governance across the organisation.
- Provide regular updates and reporting on the Group's privacy programme, emerging risks and compliance status to senior management and governance committees.
Culture, Training & Awareness
- Champion a strong culture of data protection and responsible data management throughout the organisation.
- Design and deliver privacy training, awareness initiatives and guidance materials in collaboration with Business Unit DPOs to enhance employee understanding and compliance.
Broader Compliance Responsibilities
- Support wider Group Compliance and Risk Management initiatives as required.
- Undertake additional compliance-related projects and responsibilities assigned by the Group Head of Risk Management.
What We're Looking For
- Strong experience in data privacy, compliance, risk management, legal or governance roles within a multinational organisation.
- Deep understanding of data protection regulations and privacy governance frameworks across multiple jurisdictions.
- Experience serving as a Data Protection Officer or leading enterprise-wide privacy programmes.
- Strong stakeholder management skills with the ability to influence and collaborate across diverse business functions and geographies.
- Excellent analytical, communication and problem-solving capabilities.
- Ability to balance regulatory requirements with practical business considerations in a fast-paced environment.
Key Qualification
- At least 12-18 years of relevant experience
- Degree in Law, Accounting, Business, Finance or a related field
- Professional certification in data privacy e.g. CIPP, CIPM