Position Summary
Are you passionate about data privacy and eager to gain hands-on experience in a dynamic and impactful industry?
We are seeking a Data Privacy Analyst Intern to support our APAC data privacy and compliance initiatives within the healthcare and medical technology sector.
This 6-month internship offers a unique opportunity to gain practical experience in data privacy, compliance frameworks, and data governance across multiple jurisdictions.
You will work closely with the APAC Data Privacy & Compliance Manager and Director, assisting with data flow mapping, policy reviews, risk assessments, and aligning business practices with regional privacy regulations.
Key Responsibilities
Data Mapping & Records Management
- Lead the development of a Record of Processing Activities (RoPA) in compliance with GDPR and local privacy laws.
- Map and document personal data flows across departments and systems.
- Build and maintain a comprehensive data inventory, including categories of personal data, legal basis for processing, retention periods, and third-party sharing.
Risk Analysis & Compliance
- Identify privacy risks and assist in implementing mitigation strategies.
- Support privacy impact assessments (PIAs) and compliance reviews for new projects, tools, or processes.
Stakeholder Collaboration
- Work cross-functionally with teams such as Legal, HR, IT, Marketing, Operations, and third-party vendors.
- Reconcile and validate processing activities with actual operational practices.
Privacy Governance & Policy Support
- Align data mapping with broader privacy programs (e.g., consent management, data subject rights, retention policies).
- Assist in updating privacy policies and standard operating procedures to reflect APAC privacy laws.
Monitoring & Process Improvement
- Track regulatory or business changes that impact data privacy.
- Recommend improvements to data classification, access controls, and governance practices.
- Conduct research on emerging privacy regulations and best practices.
Qualifications & Skills
Essential:
- Bachelor's degree (or currently studying) in Law, Information Security, Computer Science, Data Management, or a related field.
- 0–1+ years of experience or academic background in data privacy, compliance, or governance.
- Familiarity with data mapping, RoPA creation, and privacy documentation.
- Understanding of APAC privacy laws and GDPR principles.
- Strong analytical and critical thinking skills.
- Excellent communication and stakeholder engagement skills.