Key Responsibilities
1. Regulatory Compliance & Governance
- Ensure compliance with DPDP Act 2023 and other applicable privacy regulations.
- Develop and maintain privacy policies, standards, procedures, and controls.
- Establish enterprise-wide privacy governance framework.
- Monitor changes in data protection laws and advise management accordingly.
- Conduct regular privacy compliance assessments and audits.
2. Data Privacy Risk Management
- Identify and assess privacy risks across business processes.
- Implement risk mitigation measures and monitor effectiveness.
- Maintain privacy risk register and management reports.
- Integrate privacy controls into enterprise risk management programs.
3. Personal Data Lifecycle Management
- Oversee collection, processing, sharing, storage, retention, and disposal of personal data & health data.
- Ensure lawful basis and purpose limitation for data processing.
- Review data retention schedules and deletion practices.
- Monitor compliance with data minimization principles.
4. Privacy Impact Assessments
- Conduct or oversee:
- Data Privacy Impact Assessments (DPIA)
- Privacy Risk Assessments
- Third-Party Privacy Assessments
- Record of Processing Activities
- Review new projects, applications, and technologies from a privacy perspective.
- Provide privacy-by-design recommendations.
5. Data Subject Rights Management
- Manage requests related to:
- Access
- Correction
- Erasure
- Nomination
- Consent withdrawal
- Grievance handling
- Establish processes for timely response to data principal requests.
6. Incident & Breach Management
- Participate in investigation of privacy incidents and data breaches.
- Coordinate breach notification requirements.
- Work closely with Cyber Security, Legal and IT teams.
- Conduct post-incident privacy impact reviews.
7. Third-Party & Vendor Privacy Management
- Review privacy clauses in contracts.
- Conduct privacy due diligence of vendors and service providers.
- Ensure appropriate contractual safeguards for data sharing.
- Monitor compliance of outsourced partners.
8. Awareness & Training
- Develop organization-wide privacy awareness programs.
- Conduct training for employees handling personal data & health data.
- Promote privacy culture across business units.
9. Regulatory & Stakeholder Engagement
- Act as primary contact point for:
- Data Protection Board of India
- Regulatory authorities
- Internal and external auditors
- Data principals
- Support regulatory inspections and audits.
10. Reporting & Metrics
- Prepare periodic privacy dashboards and compliance reports.
- Report privacy risks and non-compliances to senior management.
- Present privacy posture updates to governance committees.
Educational Qualification
- Bachelor's degree in Information Security, Computer Science, Information Technology, Law, Risk Management, or related field.
Professional Certifications (at least 2 to 3 of following certifications)
- Certified Information Privacy Professional (CIPP)
- Certified Information Privacy Manager (CIPM)
- Certified Information Privacy Technologist (CIPT)
- Certified Data Protection Officer (CDPO)
- CISSP
- ISO 27701 Lead Implementer/Lead Auditor
Experience
- Minimum 5 years in Data Privacy or Data Protection role exclusively.
- Experience with privacy regulations such as:
- DPDP Act 2023
- GDPR
- ISO 27701
- ISO 27001
- HIPAA (if applicable)
- PCI DSS (if applicable)
Education
Master of Law (M.L/L.L.M), Bachelors of Law (B.L/L.L.B)
Skills Required
Data Protection, Data Protector