
Position Title: Data Protection Officer (DPO)
Department: Information Security / Risk Management
Reporting To: Chief Risk Officer (CRO)
Location: Head Office Bangalore
Job Purpose:
The Data Protection Officer (DPO) shall be responsible for establishing, implementing, monitoring, and continuously improving the Company's Data Privacy and Personal Data Protection Framework. The role ensures compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), RBI/NHB regulatory guidelines, Information Security Policies, and other applicable laws governing customer and employee data. The DPO will act as the focal point for data privacy governance, customer data protection, regulatory compliance, breach management, privacy impact assessments, and awareness across the organization.
Key Roles & Responsibilities:
1. Data Privacy Governance:
- Develop and implement the Company's Data Protection and Privacy Framework.
- Ensure compliance with the Digital Personal Data Protection Act, 2023 and applicable RBI/NHB guidelines.
- Establish enterprise-wide data governance standards and privacy controls.
- Maintain the Company's Data Privacy Policy, Data Retention Policy, and Consent Management Framework.
2. Regulatory Compliance:
- Monitor compliance with applicable data protection laws and regulatory requirements.
- Advise management on emerging privacy regulations and regulatory changes.
- Coordinate with Regulatory Authorities whenever required.
- Ensure compliance with customer confidentiality requirements applicable to Housing Finance Companies.
3. Data Protection Impact Assessment (DPIA):
- Conduct Privacy Impact Assessments for new products, systems, applications, and vendors.
- Identify privacy risks and recommend mitigation measures.
- Review new digital initiatives from a privacy-by-design perspective.
4. Personal Data Management:
- Identify and classify Personal Data, Sensitive Personal Data, and Critical Business Information.
- Maintain Data Inventory and Data Flow Mapping across business functions.
- Ensure lawful collection, processing, storage, sharing, and disposal of personal data.
5. Data Breach Management:
- Establish Data Breach Response Procedures.
- Lead investigations into personal data breaches.
- Coordinate with IT, Information Security, Compliance, HR, Legal, and Business Units during security incidents.
- Recommend corrective and preventive actions.
6. Vendor & Third-Party Risk Management:
- Assess privacy controls of vendors, service providers, FinTech partners, cloud service providers, and outsourcing agencies.
- Ensure Data Processing Agreements (DPAs) are executed with all applicable third parties.
- Conduct periodic privacy compliance reviews of outsourced service providers.
7. Customer Rights Management:
Facilitate requests relating to:
1. Access to Personal Data,
2. Data Correction,
3. Data Erasure,
4. Consent Withdrawal,
5. Grievance Redressal.
- Ensure requests are addressed within prescribed timelines.
8. Policy Development:
Develop, review, and periodically update:
1. Data Privacy Policy,
2. Data Retention Policy,
3. Data Classification Policy,
4. Consent Management Policy,
5. Data Sharing Policy,
6. Cross-Border Data Transfer Procedures,
7. Data Breach Response Framework.
9. Monitoring & Audit:
- Conduct periodic privacy compliance reviews.
- Coordinate Internal Audit and Regulatory Audits related to data privacy.
- Monitor implementation of audit observations.
- Report privacy compliance status to Senior Management and the Board.
10. Training & Awareness:
- Conduct organization-wide privacy awareness programs.
- Develop employee training modules on data protection.
- Promote a culture of privacy and responsible data handling.
11. Reporting & Governance:
Prepare periodic reports on:
1. Privacy Compliance Status,
2. Data Breaches,
3. Privacy Incidents,
4. Regulatory Compliance,
5. Vendor Privacy Assessments,
6. Customer Grievances,
7. Risk Assessments,
8. Action Taken Reports.
- Present periodic updates to the Risk Management Committee, Audit Committee, and Board, as required.
Key Deliverables (KPIs):
- 100% compliance with applicable data privacy regulations.
- Timely resolution of privacy incidents and customer grievances.
- Completion of Privacy Impact Assessments for all new initiatives.
- Periodic review of data protection policies.
- Closure of audit observations within agreed timelines.
- Completion of privacy awareness training across the organization.
- Effective monitoring of third-party privacy compliance.
- Timely reporting to Management and Board Committees.
Qualification:
Essential:
- Bachelor's Degree in Engineering, Computer Science, Information Technology, Law, Finance, Business Administration, or related discipline.
Preferred:
- Master's Degree (MBA/MCA/LLM/Information Security/Risk Management).
Professional Certifications (Preferred):
- Certified Information Privacy Professional (CIPP)
- Certified Information Privacy Manager (CIPM)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- ISO 27001 Lead Implementer / Lead Auditor
- Certified Data Protection Officer (CDPO)
Experience:
- Minimum 8-12 years of experience in Information Security, Risk Management, Compliance, Data Privacy, IT Governance, or Cyber Security.
- At least 3-5 years in Data Privacy, Regulatory Compliance, or Information Security within a Bank, Housing Finance Company (HFC), NBFC, or Financial Institution.
- Experience in implementing enterprise-wide data protection frameworks and regulatory compliance.
Didn’t find the job appropriate? Report this Job