Assistant Vice President - Group Data Protection Office, Privacy Advisory & Implementation
HKEX Career
·Today
- Location
- HK-TWO ES 9/F, Hong Kong
- Type
- Full-time
- Department
- Management
- Seniority
- VP
- Source
- Workday
Description
Company Introduction:
We’re home to Asia's most dynamic and vibrant capital markets.
Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.
HKEX is a purpose-driven company. Our commitment to the long-term development of our business and our markets is articulated in our purpose: "To Connect, Promote and Progress our Markets and the Communities they support for the prosperity of all."
Job Summary:
At HKEX Group, we are committed to best practices in handling personal data and ensuring compliance with applicable privacy and data protection laws. The Assistant Vice President, Group Data Protection Office, Privacy Advisory & Implementation, will support the SVP and wider GDPO team in delivering both privacy legal advisory and privacy programme implementation across the Group.Working in the HKEX Group Legal Services Department, the role combines privacy subject matter expertise with strong execution capability, helping to interpret legal and regulatory requirements and translate them into practical controls, processes, and business solutions. Our ideal team member will be a proactive individual with the knowledge and confidence to handle and drive operational tasks.
Job Duties:
1. Privacy Legal Advisory & Regulatory Compliance
- Provide day-to-day privacy and data protection advice to business and functional teams on personal data handling activities, new initiatives, technology deployments, and operational processes.
- Support the interpretation and application of privacy and data protection laws and regulations across jurisdictions in which HKEX operates.
- Assist with privacy reviews of contracts, vendor arrangements, outsourcing initiatives, data sharing arrangements, and cross-border data transfer activities.
- Conduct or support Privacy Impact Assessments (PIAs), Transfer Impact Assessments (TIAs), Legitimate Interest Assessments (LIAs), and related privacy reviews.
- Monitor regulatory developments and emerging privacy risks and assist with updating policies, standards, guidance, and training materials.
2. Privacy Programme Implementation & Governance
- Support the GPDO in the review of internal privacy and data protection policies, standards, guidelines, and procedures, in consultation with key stakeholders across the business, support units, and control functions (including Internal Audit);
- Assist in the implementation of privacy compliance mechanisms for HKEX at a group level and coordinate privacy enhancement initiatives, remediation programmes, and implementation projects across the Group.
- Support business and functional teams in embedding privacy-by-design and privacy-by-default principles into projects, systems, and operational processes.
- Monitor and provide regular update on implementation status and timely escalation and carry out ad-hoc assignments as required.
3. Controls, Monitoring & Assurance
- Assist with maintaining a mapping of data flows and Record of Processing Activities – performing quality control to ensure consistency and alignment with documented procedures.
- Drive consistency of processes across workstreams that impact privacy and data protection risk.
- Support internal audits, regulatory reviews, and assurance activities relating to privacy and data protection.
- Coordinate follow-up actions arising from privacy incidents, assessments, audits, and reviews.
.
4. Stakeholder Engagement & Privacy Culture
- Act as a trusted privacy advisor to divisional stakeholders and privacy representatives.
- Support governance forums, working groups, and management reporting.
- Deliver privacy awareness and training initiatives across the Group.
- Promote a culture of accountability and responsible personal data handling.
Requirements
- Bachelor’s degree in Law, Business, Risk Management, Information Management, Governance, or a related discipline.
- Minimum 4-6 years working experience with 3 years of direct interactions with senior stakeholders, preferably in in privacy law, data protection, compliance, data governance, risk management, or related fields.
- Practical experience implementing privacy frameworks, policies, controls, governance programmes, or related regulatory requirements within a complex organisation.
- Ability to balance legal, regulatory, operational, and business considerations, and translate requirements into practical, business-friendly solutions.
- Strong project management, stakeholder management, and communication skills, with the ability to influence outcomes across functions and jurisdictions.
- Strong analytical mindset, attention to detail, and ability to identify risks, control gaps, dependencies, and pragmatic remediation options.
- Technology savvy (preferably with solid understanding of and interest in IT infrastructure and technology and working experience on Microsoft Power Platform).
- Experience in employment legal advisory, workplace investigations, employment litigation, or employee relations matters would be advantageous.
- Experience in financial services, regulated environments, technology risk, operational risk, compliance transformation, or data governance is preferred.
- Proficiency in English and Chinese (Cantonese and/or Putonghua) preferred.
HKEX is committed as an Equal Opportunity Employer. Diversity is one of our core values and we look to support, respect diverse perspectives, abilities, culture and experiences within our workplace.
Location:
HKEX - Exchange SquareShift:
Standard - 40 Hours (Hong Kong SAR)Scheduled Weekly Hours:
40Worker Type:
Permanent