Data Protection Officer
MISSION: The Data Protection Officer is responsible for the implementation of data privacy compliance across Vietnam. This role supports teams within their scope in meeting regulatory requirements, fosters a culture of privacy and protection, and supports the practical application of privacy controls reflecting the Data Risk Assurance Framework & relevant SE policies, including BCR.
This role's key responsibilities include support to operational implementation, incident response & training. For country-level roles, the Officer also serves as the primary point of contact for local Data Protection Authorities
RESPONSIBILITIES
Regulatory Compliance Leadership
- Advise on and monitor operational compliance with Vietnamese personal data protection law and its implementing regulations, together with other applicable regulations on cybersecurity, data, electronic transactions and sector-specific privacy requirements; support day-to-day compliance, compliance governance and processes, and ensure that consent-based processing satisfies Vietnamese law requirements.
- Support the execution of the Data Risk Assurance Framework using Company tools, templates, and guidelines.
- Perform regular compliance audits.
Data Risk Assurance Framework Implementation
- Build and execute a data risk assurance action plan using the centrally provided Data Risk Assurance Framework
- Maintain a processing register - using Company centrally provided tools and processes - to inventory data processing activities within their scope.
- Promote and support the digital certification of all digital assets within their scope
- Draft, review, and negotiate data protection clauses, including data processing agreements, data sharing agreements, cross-border transfer terms, confidentiality and security obligations, and privacy terms in customer and vendor contracts, ensuring alignment with Vietnamese law and Schneider Electric policies.
Training & Awareness
- Reduce potential risk exposure for the company by promoting a culture of data protection through awareness campaigns and training sessions.
- Provide regular training and guidance to employees on their privacy responsibilities and best practices.
Data Breach Management
- Report privacy incidents and, from a data privacy perspective, document and lead investigation, assessment, remediation and escalation activities in accordance with the Cyber Incident process, Company policies and applicable Vietnamese statutory notification requirements.
- Prepare required regulatory notifications, incident reports and supporting records for submission or explanation to competent Vietnamese authorities, where applicable.
- Promote that all privacy incidents are reported via the Cyber Incident process.
- Ensure awareness of data breach management process within their scope.
- Maintain a register of data breaches.
Want more jobs like this?
Get Administration and Office jobs in Ho Chi Minh City, Vietnam delivered to your inbox every week.

Governance & Reporting
- Establish and maintain privacy governance structures, including steering committees, annual action plan and actions/risk reporting mechanisms within their scope and to the central team.
- Collaborate with the Privacy Governance Leader in the Group Data Protection Office to ensure alignment with group policies & local privacy regulations.
- Monitor and report on privacy compliance using KPIs, KRIs, maturity assessments, and other relevant metrics and assessments.
- Queries and Claims
- Act as contact point for data subjects. Handle queries and claims in accordance with Company policies and applicable laws.
Specific to Geographies (countries) only
- Act as the person/department in charge of personal data protection for Schneider Electric commercial and manufacturing entities in Vietnam, as applicable, in accordance with Vietnamese laws and regulations on personal data protection, cybersecurity, data governance, electronic transactions and artificial intelligence where relevant.
- Advise on the development, implementation and periodic review of internal policies, procedures, regulations, notices, consent forms and records to ensure compliance with Vietnamese law and Schneider Electric global requirements.
- Collaborate with and build strong relationships with relevant Vietnamese data protection and cybersecurity competent authorities; assist with interactions, inspections or requests from competent authorities.
- Lead the preparation, maintenance, update and submission/filing of regulatory dossiers, including Personal Data Processing Impact Assessments and Cross-Border Personal Data Transfer Impact Assessments, and coordinate communications with competent authorities where required.
- Participate in the design and implementation of appropriate technical, managerial and organisational measures for personal data security, including access controls, processing procedures, confidentiality measures, incident response plans and evidence-retention practices for personal data protection incidents.
- Ensure compliance with requirements for sensitive personal data, including enhanced protection measures, restricted access controls, documented processing procedures, and separate/explicit consent where required by applicable Vietnamese law.
- Ensure personal data retention policies are defined, implemented, and enforced, including deletion or anonymisation when data is no longer required.
- Ensure mapping, monitoring, and control of personal data flows across systems, including cloud platforms, SaaS environments, processors, sub-processors and third-party recipients where applicable.
- Ensure visibility and compliance of data storage locations, cross-border transfers and applicable data localisation or regulated-data requirements where applicable.
- Assure all local regulatory interactions are shared with the Group DPO and the Privacy Governance Leader.
- Manage and respond to data subject rights requests within regulatory deadlines and according to Company processes and policies, including requests relating to access, correction, withdrawal of consent, restriction, objection, deletion and other rights recognised under Vietnamese law.
QUALIFICATIONS
- Having at least 02 years of demonstrated post-graduation working experience with a strong focus in privacy and data protection, cybersecurity, information technology, legal, compliance, human resources or risk management in Vietnam and/or the wider Asia region.
- Demonstrated understanding of: Vietnamese personal data protection law and its implementing regulations, the Cybersecurity Law, the Data Law, the Law on Electronic Transactions, relevant labour/privacy requirements, sector-specific regulations and other applicable Vietnamese legislation relating to personal data, cybersecurity and digital governance.
- Certificates of completion from:
- recognized data protection training providers
- legal, compliance, or cybersecurity institutions
- While not strictly mandatory, candidates with the following will be preferred:
- Data privacy certifications or training relevant to Vietnam and international privacy frameworks (e.g., Vietnamese personal data protection training, ISO/IEC 27701, CIPM, CIPP/E, CIPP/A, or equivalent)
- Cybersecurity or risk certifications
- Legal or compliance-related qualifications
Rewards designed for you
Our Total Rewards is our way of saying: We see you and we value you. It's more than just pay and benefits-it's a meaningful investment in you. It is designed to help you perform, grow, feel safe, and elevate your potential. The package helps you care for yourself and your family, plan your future, grow your skills and career, collaborate in an inclusive workplace, and contribute to your community. At Schneider Electric, we're here for what matters most to you. Discover more at our Career Page .
* Country-specific programs and initiatives may be available.
Looking to make an IMPACT with your career?
When you are thinking about joining a new team, culture matters. At Schneider Electric, our values and behaviors are the foundation for creating a great culture to support business success. We believe that our IMPACT values - Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork - starts with us.
IMPACT is also your invitation to join Schneider Electric where you can contribute to turning sustainability ambition into actions, no matter what role you play. It is a call to connect your career with the ambition of achieving a more resilient, efficient, and sustainable world.
We are looking for IMPACT Makers; exceptional people who turn sustainability ambitions into actions at the intersection of automation, electrification, and digitization. We celebrate IMPACT Makers and believe everyone has the potential to be one.
Become an IMPACT Maker with Schneider Electric - apply today!
40 billion global revenue
+9% organic growth
150 000+ employees in 100+ countries
You must submit an online application to be considered for any position with us. This position will be posted until filled.
Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and 'inclusion' is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do.
At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust Charter here
Schneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status, or any other legally protected characteristic or conduct.
Perks and Benefits
Health and Wellness
Parental Benefits
Work Flexibility
Office Life and Perks
Vacation and Time Off
Financial and Retirement
Professional Development
Diversity and Inclusion