Data Privacy & AI Trust Officer
Singapore, SG, 068897
Entity: Allianz Insurance Singapore
Within a span of just four years, Allianz Insurance Singapore (AIS) has emerged as the fastest-growing General Insurance company, achieving an unprecedented level of success. Since its inception in Singapore, AIS has consistently doubled its revenue year on year, a testament to its unwavering dedication to excellence. AIS takes great pride in being certified as a Great Place to Work, a reflection of our commitment to fostering a thriving and employee-driven business culture.
Description:
Allianz Insurance Singapore is seeking a versatile and highly motivated Data Privacy & AI Trust Officer with a minimum of 5 years of experience spanning data protection, privacy operations, and AI governance. This is a unique hybrid role combining the operational execution of the data privacy programme with the oversight and governance of AI initiatives across the organisation.
This role is distinct from the statutory Data Protection Officer (DPO) function and is designed to serve as the operational backbone of both the data protection and AI governance frameworks within the second line of defence.
The ideal candidate demonstrates a strong sense of urgency in handling data incidents, a genuine passion for responsible AI development, and the ability to bridge the gap between regulatory requirements and business innovation. Proficiency in OneTrust – across both privacy and AI governance modules – is a significant advantage.
This role reports directly to the Head of Legal & Compliance / DPO and plays a pivotal part in strengthening AIS's data protection posture while enabling the safe and ethical adoption of AI.
Key Responsibilities:
a) Data Incident Management - First Responder Mindset
• Act as the primary operational point of contact for all personal data incidents, ensuring swift triage, containment, and resolution in line with AIS incident management procedures and PDPA requirements.
• Coordinate cross-functional incident response, engaging IT, Legal, and business stakeholders to ensure rapid investigation and root cause analysis.
• Manage regulatory notification timelines (MAS, PDPC) with accuracy and urgency, ensuring all breach notifications are completed within prescribed deadlines.
• Maintain and continuously improve the data incident response playbook, incorporating lessons learned from past incidents.
• Conduct post-incident reviews and drive remediation actions to prevent recurrence.
b) AI Governanance & Trust - Lifecycle Oversight
• Serve as the operational AI Trust Officer, responsible for the day-to-day execution and enforcement of the AIS Master AI Lifecycle SOP across all AI/ML initiatives.
• Maintain and manage the AI Use Case Register, ensuring all AI applications are identified, documented, classified by risk level, and subject to appropriate governance.
• Conduct and lead AI Impact Assessments to evaluate fairness, transparency, explainability, accountability, and bias risks across AI models and systems.
• Monitor AI use cases throughout their lifecycle (design, development, deployment, monitoring, retirement) to ensure ongoing compliance with internal policies and external frameworks.
• Track emerging AI regulations and standards (Singapore's Model AI Governance Framework, FEAT Principles, EU AI Act developments, Allianz Group AI Standards) and translate them into actionable internal guidance.
• Act as the key liaison with Allianz Group on AI governance matters, ensuring alignment with global policies and contributing to regional AI governance forums.
c) AI Development Support - Privacy-by-Design Partner
• Partner with technology, data science, and business teams to embed data protection and ethical AI principles into AI projects from inception to deployment.
• Conduct and support Data Protection Impact Assessments (DPIAs) for AI/ML initiatives, ensuring privacy risks are identified, documented, and mitigated alongside AI-specific risks.
• Advise on lawful bases for data processing in AI contexts (consent, legitimate interest, anonymisation, pseudonymisation) and ensure training data governance.
• Develop and maintain practical guidance documents, checklists, and templates for project teams to self-assess AI privacy and ethics considerations at each development stage.
• Champion a responsible AI culture across the organisation, ensuring AI development is viewed as an opportunity that is enabled – not blocked – by good governance.
d) Privacy Operations and Compliance Monitoring
• Manage and execute the data protection compliance programme, including Records of Processing Activities (ROPA), consent management, and Data Subject Rights (DSR) fulfilment.
• Conduct regular privacy compliance monitoring, gap assessments, and audits across business functions.
• Track and analyse regulatory developments (PDPA amendments, MAS guidelines, sector-specific regulations) and assess their operational impact on AIS.
• Support third-party/vendor due diligence on data protection matters, including Data Processing Agreements (DPA) reviews.
e) OneTrust Platform Management and Optimisation
• Serve as the functional owner/power user of OneTrust, managing modules including: Privacy Management, Incident & Breach Response, DPIA/PIA Automation, Consent Management, Vendor Risk Management, and the AI Governance Module – leveraging OneTrust's AI capabilities to document, assess, and monitor AI use cases.
• Configure and optimise OneTrust workflows to improve efficiency, automate recurring tasks, and enhance reporting across both privacy and AI governance activities.
• Ensure data accuracy and integrity within OneTrust, driving adoption across the organisation.
• Act as the internal subject-matter expert on OneTrust, providing training and support to stakeholders.
f) Training, Awareness and Culture Building
• Design and deliver targeted training programmes covering data privacy, data incident awareness, AI ethics, and responsible AI use for employees at all levels.
• Develop practical guidelines, FAQs, and communications to foster a strong privacy and AI trust culture.
• Act as a privacy and AI governance ambassador, proactively engaging with business teams to build trust and ensure governance is seen as a business enabler, not a blocker.
g) Reporting and Analytics
• Prepare regular and ad-hoc reports on: Privacy KPIs, incident metrics, DPIA progress, DSR volumes, and compliance status; and AI governance KPIs: AI use case inventory status, risk classifications, and remediation tracking.
• Analyse data trends to identify systemic risks, recurring issues, and opportunities for process improvement across both domains.
• Contribute to Group reporting obligations on data protection and AI governance matters.
Qualifications and Skills:
a) Bachelor's degree in Law, Information Technology, Data Science, Business, or a related field. A relevant postgraduate qualification is a plus.
b) At least one of the following certifications: CIPP/A, CIPM, CIPT, or an equivalent data privacy certification; additional AI governance certifications (e.g., ISO/IEC 42001 Lead Implementer, ISACA AI Fundamentals, or Certified AI Governance Professional) are highly valued, while OneTrust certification is advantageous.
c) Minimum 5 years of combined experience in data protection/privacy and AI governance roles, with demonstrable experience in:
• Data incident/breach management in a regulated environment
• Privacy operations (ROPA, DSR, DPIAs)
• AI governance, AI risk assessment, or responsible AI programme implementation
• Supporting technology or AI-related projects from a privacy and ethics perspective
d) Proficiency in OneTrust (strong plus – ideally across privacy AND AI governance modules)
e) Familiarity with data governance and information security frameworks
d) Understanding of AI/ML fundamentals, model risk management, and their data protection implications
e) Awareness of AI tooling ecosystems and emerging AI governance technology
f) Strong working knowledge of:
• Singapore's PDPA and MAS Technology Risk Management (TRM) Guidelines
• Singapore's Model AI Governance Framework and FEAT Principles
• International frameworks awareness (GDPR, EU AI Act, APAC privacy laws)
g) Core competencies
• Sense of urgency – ability to respond to data incidents rapidly and remain composed under pressure
• Dual-hat mindset – comfort operating across both privacy and AI governance domains
• Exceptional attention to detail and organisational skills
• Strong written and verbal communication skills
• Ability to translate complex regulatory requirements into actionable business guidance
• Collaborative mindset with the ability to influence stakeholders at all levels
• Proactive, solution-oriented, and comfortable with ambiguity
• High ethical standards and commitment to integrity
h) Preferred prior experience in the insurance of financial services sector
i) AI-Skills e.g. ChatGPT and Microsoft CoPilot an advantage
107286 | Legal & Compliance | Professional | Non-Executive | Allianz Singapore | Full-Time | Permanent
Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges is what makes us a unique employer. We are united by a shared commitment: to put our customers first and at the center of everything we do. Their needs inspire our thinking and guide our actions. Together, we can build an environment where everyone feels empowered and confident to explore, grow and shape a better future – for our customers and for the world around us.
At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. The foundation for this is our inclusive workplace, where people and performance both matter, and where integrity, fairness, inclusion and trust are at the heart of our culture. We therefore welcome applications regardless of race, ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations.
Join us. Let's care for tomorrow.
Note: Having different strengths, experiences, perspectives and approaches is an integral part of Allianz‘ company culture. One means to achieve this is a regular rotation of Allianz employees across functions, Allianz entities and geographies. Therefore, Allianz expects from its employees a general openness and a high motivation to regularly change positions and collect experiences across Allianz Group.