
AVP - Data Privacy Officer
Experience: 10+ Years
Employment Type: On-Roll
Location: Gurugram - On-site
Industry: Banking/Fintech
Responsibilities:
- Lead and oversee the Data Protection programme and related initiatives for a leading payments bank.
- Manage and monitor compliance with all applicable Data Privacy laws, regulations, and standards, including DPDPA, GDPR, etc.
- Perform regular compliance assessments and reporting, including Data Privacy Impact Assessments (DPIA).
- Work with business and technical teams, third-party vendors, and auditors to ensure adherence to applicable Data Protection laws, regulations, and standards.
- Provide periodic and ad-hoc Data Protection awareness and security training for employees/contractors and evaluate training effectiveness.
- Recommend and develop KPIs and metrics to evaluate the Data Protection/Privacy programme and related controls.
- Participate in planning, scheduling, and preliminary analysis for internal and external Data Protection/Privacy audits and assessments.
- Maintain a tracker of outstanding audit actions and work with remediation teams to address identified gaps.
- Oversee process documentation and compliance adherence.
Measures of Success:
- Timely implementation of Data Privacy programmes at the organizational level.
- Completion of Privacy Impact Assessments as per schedule.
- Timely reporting of data privacy incidents internally and to regulators as applicable.
- Timely updation and approval of the Data Privacy Policy.
- No adverse observations in internal/external privacy audits.
- Timely completion of Data Privacy training for eligible users.
- Timely remediation of findings/recommendations raised by internal or external assessors.
- Adherence to the organization's Data Privacy Policy.
Qualifications:
- 10 - 12 years of post-qualification experience.
- At least 5 years of relevant experience working with privacy laws, including drafting privacy policies, technology provisions, and privacy compliance.
- One or more relevant certifications such as CIPP/E, CDPSE, CIPM, DSCI Certified Privacy Professional, CISSP, DCDPO, or equivalent.
- Experience in technical training and conducting Data Privacy awareness sessions.
- Strong experience working with business and external stakeholders.
- Experience working with IT programming or infrastructure, including certification in information security standards.
- Experience in information systems audits, attestation audits, and risk assessments.
- Knowledge of assessing, developing, and implementing Data Privacy programmes, including drafting privacy policies, standards, processes, procedures, and technology provisions.
Didn’t find the job appropriate? Report this Job