Data Protection Officer cum IT Executive
Data Protection Officer
IT & Website Management
Company: Utrust Strategy Employment Type: Permanent, Full-time Job Category: Information Technology / Data Protection / Compliance Location: Singapore Monthly Salary: S$3,000 - 4,500
About the Role
We are seeking a hands-on and detail-oriented Data Protection Officer (DPO) with a strong background in information technology and website development.
The successful candidate will be responsible for overseeing the organisation’s compliance with Singapore’s Personal Data Protection Act (PDPA), developing internal data-protection practices and supporting the security, maintenance and development of the organisation’s websites and digital systems.
This role is suitable for someone who understands both the technical and operational aspects of data protection and can translate regulatory requirements into practical business processes.
Key Responsibilities
Data Protection and PDPA Compliance
- Serve as the organisation’s designated Data Protection Officer.
- Develop, implement and maintain the organisation’s data-protection policies, procedures and internal controls.
- Ensure that the organisation’s collection, use, disclosure, storage and disposal of personal data comply with the Singapore PDPA.
- Maintain an inventory of the personal data collected and processed across the organisation.
- Review business processes, application forms, websites and digital platforms to identify potential data-protection risks.
- Conduct periodic data-protection impact assessments and compliance reviews.
- Review and update privacy policies, consent clauses, website notices, marketing consent wording and data-retention policies.
- Establish procedures for handling requests relating to access, correction, withdrawal of consent and deletion of personal data.
- Manage and respond to data-protection enquiries, complaints and suspected data breaches.
- Coordinate the investigation, containment, documentation and reporting of data incidents.
- Assess whether a data breach must be reported to the Personal Data Protection Commission and notify affected individuals where required.
- Maintain records of data incidents, complaints, risk assessments and remedial actions.
- Conduct regular PDPA and cybersecurity awareness training for employees.
- Advise management and employees on data-protection obligations and appropriate handling of confidential information.
- Review data-processing arrangements with vendors, software providers and other third parties.
- Work with external consultants, legal advisers and relevant authorities when required.
Website Development and Management
- Create, develop, update and maintain the organisation’s corporate websites and landing pages.
- Manage website content, layouts, contact forms, online enquiry forms and other digital functions.
- Ensure that websites are mobile-responsive, user-friendly and compatible across commonly used devices and browsers.
- Monitor website performance, security, availability and functionality.
- Carry out regular website backups, updates, maintenance and troubleshooting.
- Manage website domains, hosting accounts, SSL certificates, email configurations and related technical services.
- Implement appropriate privacy notices, consent mechanisms and cookie-management features on company websites.
- Ensure that personal data submitted through websites is securely transmitted, stored and accessed.
- Review website plugins, scripts, analytics tools and third-party integrations for privacy and security risks.
- Work with internal teams and external vendors on website enhancements and digital projects.
- Assist with search engine optimisation, website analytics and basic performance reporting where required.
IT and Information Security
- Support the implementation of appropriate technical and organisational measures to protect personal and confidential information.
- Manage user-access permissions for websites, cloud platforms, shared drives and internal systems.
- Conduct regular reviews of employee access rights and remove access promptly when employees leave the organisation.
- Support the implementation of password controls, multi-factor authentication, encryption, backups and other security measures.
- Monitor systems for potential security vulnerabilities and coordinate corrective actions.
- Maintain records of IT assets, user accounts, software subscriptions and system access.
- Liaise with IT vendors and service providers to resolve technical and security issues.
- Support staff with general website, email, software and system-related matters when required.
Job Requirements
- Diploma or bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Data Protection or a related discipline.
- At least [two to four] years of relevant experience in IT, website development, data protection, cybersecurity or compliance.
- Practical knowledge of Singapore’s Personal Data Protection Act and data-protection principles.
- Experience developing or maintaining corporate websites.
- Familiarity with website platforms such as WordPress, Webflow, Wix, Shopify or similar content-management systems.
- Working knowledge of HTML and CSS. Knowledge of JavaScript, PHP or other programming languages would be an advantage.
- Familiarity with domain management, web hosting, SSL certificates, website security and backup procedures.
- Understanding of cybersecurity risks, access controls, phishing, malware, data breaches and incident-response procedures.
- Experience with cloud-storage platforms, Microsoft 365, Google Workspace or similar business systems.
- Strong analytical and problem-solving abilities.
- Excellent attention to detail and documentation skills.
- Able to explain technical and compliance matters clearly to non-technical colleagues.
- Able to work independently and handle sensitive or confidential information responsibly.
- Strong written and verbal communication skills.
Preferred Qualifications
- Certification in data protection, privacy, cybersecurity or information security would be an advantage.
- Experience serving as a DPO or supporting an organisation’s PDPA compliance programme.
- Experience conducting data-protection impact assessments, internal audits or data-breach investigations.
- Experience managing multiple websites or digital platforms across a group of companies.
- Familiarity with website analytics, search engine optimisation and digital marketing systems.
What We Offer
- Competitive remuneration based on qualifications and experience.
- Exposure to both data-protection compliance and practical technology projects.
- Opportunities to develop and improve the organisation’s data-protection and IT framework.
- A professional and collaborative working environment.
- Opportunities for career development as the organisation continues to grow.
Interested candidates should submit their résumé together with details of their relevant IT, website-development and data-protection experience, current and expected salary, and earliest available commencement date.
Only shortlisted candidates will be contacted.