About the role
The doxxing amendments, a more active enforcement posture from the PCPD and a run of publicised breach investigations have made data privacy a board-level question for Hong Kong companies that used to treat it as an IT problem. Compliance Quarter has been building a practice around that for three years. This role leads the delivery side of it.
You will run privacy programmes for six to eight clients at once: a retail group with two million loyalty members, a healthcare operator, a payments firm and several SMEs. The work spans collection statement drafting, data inventories, cross-border transfer assessments and, when it goes wrong, breach response.
You report to Alistair Ng and work alongside our financial crime and regulatory teams, because privacy questions rarely arrive on their own. Hybrid, with client visits typically two days a week.
What you'll do
- Design and implement personal data protection programmes aligned to the PDPO and the six Data Protection Principles.
- Draft Personal Information Collection Statements, privacy policies and consent flows that would survive a PCPD complaint.
- Run data inventory and mapping exercises, including cross-border transfer analysis for Mainland and overseas processing.
- Lead breach response: containment advice, PCPD notification drafting, affected-individual communications and post-incident review.
- Conduct privacy impact assessments for new products, CCTV deployments and employee monitoring proposals.
- Deliver training to client staff at every level, from the board to the call centre floor.
- Track PCPD guidance and PRC PIPL developments where clients are exposed to them.
What we're looking for
- Six or more years in data privacy, information governance, compliance or technology law.
- Deep working knowledge of the PDPO, the Data Protection Principles and PCPD guidance notes.
- Experience running at least one live data breach response from notification through to remediation.
- Excellent written English, plus Cantonese for client workshops and staff training.
- Able to explain a legal obligation to an engineer and a technical control to a director, in the same afternoon.
Nice to have
- CIPP/A, CIPM or an equivalent certification.
- Familiarity with the PRC Personal Information Protection Law and the standard contract regime.
- A legal background, with or without admission.
What you get
- Certification sponsorship including CIPP/A and CIPM
- Hybrid working with two fixed office days a week
- 20 days' annual leave, with unused days paid out
- Medical, dental and critical illness cover
- Visa sponsorship and relocation support for the right candidate
Skills & keywords
Alistair Ng
Director, Data Governance · reviews applications personally
Listing ID JOB-PROF-011 · Closes 23 Oct 2026 · HKjobs never asks candidates to pay a fee. Report this listing