
Key Responsibilities:
1. Data Protection Governance & Strategy:
Design, implement, and maintain a Bank-wide Data Protection & Privacy Framework aligned with:
1. DPDP Act, 2023
2. RBI IT Governance & Cyber Security Guidelines
3. Industry best practices (ISO 27701, NIST Privacy Framework)
- Embed privacy-by-design and privacy-by-default into digital products, mobile banking platforms, APIs, and analytics initiatives.
- Define and maintain data classification, retention, consent management, and lawful processing standards.
2. Regulatory Compliance & Advisory:
- Act as the Bank's principal advisor on personal data protection obligations.
- Interpret regulatory requirements and provide guidance to business, technology, digital, and marketing teams.
- Serve as the single point of contact for the Data Protection Board of India (DPBI) and coordinate regulatory inspections, audits, and submissions.
3. Customer & Employee Data Rights:
Oversee end-to-end handling of Data Principal requests, including:
1. Access, correction, erasure
2. Withdrawal of consent
3. Grievance redressal
- Ensure automated and scalable handling of requests across high-volume digital channels.
4. Privacy Risk Management & DPIA:
Lead Data Protection Impact Assessments (DPIAs) for:
1. New digital products and platforms
2. AI/ML, analytics, and profiling initiatives
3. Fintech, Open Banking, and API-based integrations
- Identify data-driven business risks and recommend pragmatic controls without hindering innovation.
5. Data Breach & Incident Oversight:
- Be a core member of the Bank's Cyber and Data Incident Response Team.
- Assess data breach impact, determine regulatory notification requirements, and ensure timely communication to:
1. Regulators
2. Affected customers (where applicable)
- Coordinate closely with CISO, Legal, Compliance, and Corporate Communications.
6. Third-Party, Fintech & Outsourcing Oversight:
Define data protection requirements for:
1. Fintech partners
2. Cloud and SaaS providers
3. Outsourced service providers and call centers
- Review contracts, ensure DPDP-aligned clauses, and monitor ongoing compliance of vendors.
7. Training & Culture:
Design and deliver role-based privacy training for:
1. Employees
2. Product owners
3. Senior management
- Promote a privacy-first culture across digital and physical banking operations.
8. Reporting & Board Engagement:
Prepare periodic dashboards and reports covering:
1. Privacy risk posture
2. Complaints and data subject requests
3. Breaches and near-misses
4. Regulatory compliance status
- Present findings to senior management and Board committees
Didn’t find the job appropriate? Report this Job