Manager- Data Protection & Privacy | ISS Department - DFCC Bank Colombo 03
Posted November 5, 2025 by DFCC Bank
Closing Date : November 11, 2025
About the job
Assistant Manager/ Manager - Data Protection & Privacy
ISS Department
Colombo
You should ideally:
- possess a minimum of 5 years of experience in data protection, legal compliance, information security, or data governance
- possess a bachelor’s degree in law, Information Security, Data Governance, or Information Technology; a master’s degree in a related field is highly preferred
- possessing relevant certifications in Data Protection (e.g., CIPP/E, CIPM, CDPSE), Information Technology, or GRC are advantageous
- Being familiar with the PDPA Act No. 19 of 2022 and international data protection frameworks (e.g., GDPR) is essential
You will be responsible for:
- establishing a comprehensive data protection framework for PDPA and legal compliance, collaborating with CISO to integrate data protection into cybersecurity
- ensuring data practices align with GRC standards and legal requirements across all subsidiaries, and overseeing data privacy risk management
- advising senior management on data privacy, including anonymization and retention policies
- guiding DPIAs and privacy-by-design strategies, and collaborating with legal to apply PDPA requirements in transactions and partnerships
- creating and enforcing organisation-wide data protection policies to ensure PDPA and global standards compliance
- regularly updating policies to align with legal and technological changes
- overseeing personal data governance in analytics, ensuring legal compliance and responsible data use for insights, in line with privacy regulations
- establishing processes and a contingency plan to effectively address data subject rights under the PDPA
- assessing and monitoring third-party vendors for data protection compliance, ensuring proper data handling agreements
- coordinating with risk and audit teams for continuous vendor performance monitoring
- collaborating with the CISO to mitigate cyber risks related to data, focusing on encryption, access control and secure storage
- ensuring ethical and secure data use across operations, including marketing and customer analytics
- leading data protection and privacy training for employees, ensuring they understand their roles and responsibilities in maintaining compliance
- monitoring data processing activities, reporting compliance to senior management, and highlighting risks and improvements
- collaborating with auditors to ensure PDPA and international standards compliance, preparing for audits as needed
- serving as the primary contact for the Data Protection Authority of Sri Lanka, ensuring compliance with regulatory requirements
We are an equal opportunity employer, committed to promoting an inclusive and diverse environment. Recruitment to the Bank is based solely on merit and competency, irrespective of other characteristics that make our employees unique.
Any form of canvassing is discouraged. Correspondence will only be with the short-listed candidates.
If you believe you're a good fit for the position described above, please send your updated CV to recruit@dfccbank.com within 14 days of this advertisement.
සෑලකිය යුතුයි : අපි ඔබව මෙම රැකියාව උපුටා ගත් පිටුවට හරවා යවන්නෙමු . අපි ඔබ වෙනුවෙන් ඔබේ CV , තොරතුරු අදාළ ආයතනය වෙත නොයවන බව කරුණාවෙන් සලකන්න
கவனமாக இருக்க வேண்டும் : இந்த வேலை மேற்கோள் காட்டப்பட்டுள்ள பக்கத்திற்கு உங்களை திருப்பி விடுவோம். உங்களுக்கான CV, தகவல்களை சம்பந்தப்பட்ட நிறுவனத்திற்கு நாங்கள் அனுப்ப மாட்டோம் என்பதை நினைவில் கொள்ளவும்
Disclaimer : By clicking the button below, you consent for CareerFirst and partners to use automated technology, including pre-recorded messages, cell phones and texts, and email to contact you at the number and email address provided. This includes if the number is currently on any Do Not Call Lists. This consent is not required to make a purchase. We are redirecting you to the employer's career page. Please note that we are not sending your CV to the employer on your behalf. Privacy Policy.
RELATED JOBS
IFS Sri Lanka
Closing Date: 2025-12-04
Virtusa Pvt Ltd
Closing Date: 2025-12-03
HCLTech Sri Lanka
Closing Date: 2025-12-03
MAS Holdings
Closing Date: 2025-11-12
MAS Holdings
Closing Date: 2025-11-06
Commercial Bank PLC
Closing Date: 2025-12-04
LAUGFS Holdings
Closing Date: 2025-11-10
Seylan Bank
Closing Date: 2025-11-10
Axiata Digital Labs Pvt Ltd
Closing Date: 2025-11-30
Regional Development Bank (RDB)
Closing Date: 2025-11-10
Commercial Bank PLC
Closing Date: 2025-11-26
HSBC Bank
Closing Date: 2025-11-23
IFS Sri Lanka
Closing Date: 2025-11-22
George Steuarts Recruitment (Pvt) Ltd
Closing Date: 2027-10-20
CodeGen International
Closing Date: 2025-11-21
In Talent Asia
Closing Date: 2025-11-20
InfoMate Pvt Ltd
Closing Date: 2025-11-19