Director, Regional DPO Coordination and Governance
Singapore
Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region. SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network. We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.
With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.
Key Responsibilities
- Lead and enhance SMBC's regional data privacy governance framework across APAC.
- Coordinate and oversee country DPOs to ensure consistent implementation of privacy requirements and controls.
- Act as the regional subject matter expert on Singapore PDPA and provide guidance on APAC privacy regulations.
- Monitor regulatory developments and drive compliance programs across multiple jurisdictions.
- Oversee Privacy Impact Assessments (PIAs), privacy risk assessments, and remediation initiatives.
- Establish governance and controls for cross-border data transfers and third-party data processing.
- Lead privacy incident and breach management governance, including regulatory reporting and escalation.
- Deliver privacy reporting and insights to senior management and governance committees.
- Drive privacy awareness, training, and a strong culture of data protection across the organization.
- Partner with Legal, Compliance, Risk, Technology, Information Security, and business stakeholders on privacy-related initiatives.
Requirements
- Bachelor's degree in Law, Information Systems, Risk Management, Business, or related field; advanced degree preferred.
- 12+ years of experience in data privacy, data governance, compliance, risk management, or related disciplines, with significant regional leadership experience.
- Strong knowledge of Singapore PDPA and other APAC privacy regulations, including cross-border data transfer requirements.
- Experience within banking, financial services, or other highly regulated industries.
- Proven ability to engage regulators, senior executives, and stakeholders across multiple jurisdictions.
- Strong leadership, communication, stakeholder management, and program delivery skills.
- Professional certifications such as CIPP/A, CIPM, CIPT, CDMP, CISSP, CISA, or CRISC are advantageous.