
Job Description DSAR / Data Privacy Professional
Job Title: Data Subject Access Request (DSAR) Professional
Location: Noida
Experience: 3-5 Years
Notice Period: Immediate to Maximum 30 Days
Working Days: 5 Days a Week
Role Overview:
We are looking for a Data Privacy / DSAR Professional to manage end-to-end Data Subject Rights Requests across applicable privacy regulations. The role involves handling access, deletion, correction, portability, opt-out, restriction, and consent withdrawal requests while ensuring accuracy, confidentiality, regulatory compliance, and adherence to defined SLAs. The ideal candidate should have hands-on experience in DSAR operations, data privacy, GDPR/DPDPA or other global privacy regulations, case management, stakeholder coordination, and compliance documentation.
Key Responsibilities:
- Manage the complete lifecycle of Data Subject Rights Requests (DSARs) from intake to closure.
- Handle requests related to:
1. Right of Access
2. Right to Deletion / Erasure
3. Right to Rectification / Correction
4. Data Portability
5. Opt-Out Requests
6. Restriction of Processing
7. Withdrawal of Consent
- Review incoming requests and assess request validity, identity verification requirements, and applicable regulatory obligations.
- Coordinate with Legal, IT, HR, Security, Business, Product, and other internal stakeholders to identify, collect, and review responsive data.
- Ensure DSAR requests are completed within applicable regulatory and internal SLA timelines.
- Support compliance with regulations such as GDPR, UK GDPR, CCPA/CPRA, DPDPA, and other applicable privacy laws.
- Identify and escalate complex, high-risk, sensitive, or non-standard privacy requests.
- Handle requests submitted through authorized agents, legal representatives, or privacy brokers.
- Support the drafting and preparation of DSAR responses for review and approval.
- Maintain accurate case records, evidence, correspondence, decisions, and closure documentation.
- Track DSAR volumes, SLA adherence, aging, turnaround time, and other operational metrics.
- Prepare periodic MIS, dashboards, and management reports.
- Support internal audits, compliance reviews, regulatory inquiries, and privacy assessments.
- Identify opportunities for process improvement, automation, standardization, and operational efficiency.
- Develop and maintain DSAR SOPs, process documents, playbooks, templates, and knowledge repositories.
- Work closely with cross-functional stakeholders to resolve data discovery, collection, and privacy-related challenges.
Required Skills & Experience:
- 3-5 years of experience in Data Privacy, DSAR operations, Privacy Operations, Compliance, Risk, or Cybersecurity-related roles.
- Hands-on experience in managing or supporting Data Subject Rights Requests / Data Subject Access Requests.
- Strong understanding of GDPR and data subject rights.
- Exposure to privacy regulations such as UK GDPR, CCPA/CPRA, DPDPA, or other global privacy frameworks.
- Experience with DSAR case management, request validation, identity verification, data collection, and stakeholder coordination.
- Understanding of data protection principles, consent, data retention, data minimization, and privacy rights.
- Experience working with multiple internal teams to gather and review personal data.
- Strong documentation, reporting, and communication skills.
- Ability to manage multiple requests simultaneously while meeting strict SLAs.
- Experience with privacy tools, GRC tools, ticketing systems, or workflow management platforms would be an advantage.
- Knowledge of automation and process improvement is preferred.
Preferred Qualifications:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Law, or a related field.
- Certifications or training in GDPR, Data Privacy, DPDPA, CIPP/E, CIPM, ISO 27701, ISO 27001, or related areas would be an advantage.
- Exposure to Privacy Operations, GRC, Information Security, Compliance, or Risk Management.
Ideal Candidate Profile:
We are looking for candidates who have practical DSAR experience, not just theoretical knowledge of GDPR or data privacy. The candidate should be comfortable handling privacy requests end-to-end, coordinating with multiple stakeholders, managing SLAs, maintaining documentation, and dealing with sensitive personal data. Candidates from Data Privacy, Privacy Operations, DSAR Operations, GDPR Compliance, Trust & Safety, Compliance Operations, GRC, Cybersecurity Compliance, and Information Security backgrounds may be considered, provided they have relevant hands-on DSAR exposure.
Didn’t find the job appropriate? Report this Job