Tempo Indeterminato
SELANGOR
Petaling Jaya
Legal
Full - Time
31-lug-2026

Data Protection Officer & Senior Counsel- L'Oréal Business Expertise, Services & Technologies Center

 

Who We Are

 

Change is the DNA of L'Oréal; we are constantly leading the beauty industry to go beyond. In 1909, we began as a small store selling hair dye. Today, we have a portfolio of 37 international brands and a global presence in 150 countries.  

 

At L'Oréal, there are 6 Zone Business Expertise, Services & Technologies Centers supporting the Group with a mission of providing Finance, HR, Data Operations and E-Commerce transformation and delivering efficient and effective processes whilst maintaining integrity. 

 

One of centers set up is in Kuala Lumpur, Malaysia – BEST KL (BEST stands for Business Expertise, Services & Technologies), providing services to over 20 L’Oréal markets across North Asia & SAPMENA (South Asia Pacific, Middle East & North Africa) regions.  

 

Core Job Scope 

 

As the Data Protection Officer for BEST KL (“the Entity”), you are responsible for promoting, coordinating, supporting and monitoring Data Compliance across the services. You will be required to advise and support a broad range of data privacy, AI and cybersecurity regulations for the Entity and liaise with the markets across the SAPMENA and North Asia Zone.

 

As the Senior Counsel, you will be responsible for negotiating, reviewing and drafting contracts, providing legal advice for matters relating to the Entity. 

 

You Will…

 

Act as the Data Protection Officer for the Entity

  • Fulfil all applicable statutory DPO obligations for the Entity   
  • Ensure that applicable legal obligations regardless of market are identified and operationalized within the services provided, recognizing that each market’s laws may impose obligations on centrally processed data regardless of where processing physically occurs 
  • Provide expert guidance on data privacy obligations, advising on data compliance, and embedding privacy-by-design principles in processes from the outset 
  • Report regularly to leadership on the data compliance program, evolution of regulations and risk exposure 

 

Drive Data Compliance Across the Entity

  • In alignment with the Group Data Compliance program, implement a data compliance framework — covering data privacy, AI, and cybersecurity 
  • On data privacy, operationalize standard processes including maintaining Records of Processing Activities, conducting DPIAs, implementing lawful cross-border data transfer mechanisms, managing data incidents, responding to data subject requests and monitoring compliance through dashboards and KPIs
  • On AI governance, identify and assess AI tools and automated decision-making processes deployed within the services to ensure they are used in a manner consistent with applicable AI regulations and Group frameworks
  • On cybersecurity compliance, advise on applicable legal obligations arising from cybersecurity laws and liaise with IT and Security teams to support compliance with applicable cybersecurity laws and Group security standards 
  • Develop and animate the data compliance community including sharing of best practices, teaching and training appointed champions, providing practical guidance on day-to-day data compliance issues, coordinating regularly with country DPOs, Zone and Group stakeholders
  • Project manage rollouts from Group/Zone 

 

Provide Strategic Counsel to the Entity

  • Act as the primary legal point of contact for the Entity
  • Provide legal support on diverse topics including intellectual property, competition law, corporate governance, communications/marketing claims and real estate
  • Negotiating, reviewing and drafting all types of contracts and legal documents for the Entity 
  • Upskill employees of the Entity by designing and conducting engaging training sessions on key legal topics, business compliance requirements, and internal policies.

 

Who We Are Looking For

  • Skilled in Data Privacy, AI and Cybersecurity regulations and practices in countries across the region 
  • Background in building GDPR-compliant programs in Asia (CIPP/E or CIPP/A preferred)
  • A qualified lawyer of at least a 10 years PQE
  • Able to coordinate among key stakeholders and manage relationships at multiple levels
  • Strong communication skills to work in a diverse and multi-national environment
  • Able to manage cross-border projects, with a demonstrated ability to navigate and reconcile overlapping or conflicting multi-market regulatory requirements in a shared-services or centralized processing context
  • Experienced in data processing environments, with a clear understanding of specific data privacy sensitivities associated with data management at scale over multiple markets
  • Comfortable engaging with and advising senior management 
  • You can apply to up to three jobs within a rolling 30-day window.
  • You cannot withdraw your application once you applied, so please make sure to choose a job that matches your dreams.
  • Please visit "Your Application Space" to see the jobs you have already applied to.
  • Please don’t create another account with a different email. If you do so, your account might be merged and your application record will be deleted.