- Develop and maintain the Bank’s Data Privacy and Protection Framework in alignment with corporate data strategy and regulatory requirements (DPDP Act 2023, GDPR, etc.).
- Establish and monitor policies for lawful data collection, storage, usage, sharing, and disposal.
- Support the Risk and Data Department in integrating privacy principles into data governance, architecture, and analytics workflows.
- Maintain a central register of all personal data processing activities.
- Conduct Data Protection Impact Assessments (DPIAs) for new systems, digital products, and third-party integrations.
- Identify and mitigate risks related to data sharing, cross-border data transfers, and data retention.
- Collaborate with Compliance, Legal, and IT Security teams to ensure regulatory alignment and timely reporting of data breaches.
- Support periodic internal and external audits on data privacy compliance.
- Partner with Data Engineering and IT teams to embed privacy controls, encryption, masking, and anonymization techniques within data pipelines.
- Evaluate and recommend privacy-enhancing technologies and tools that improve compliance and customer trust.
- Ensure metadata, classification, and lineage tools properly capture privacy attributes.
- Continuously improve the privacy framework based on audit findings, risk reviews, and emerging best practices.
- Monitor evolving privacy laws and advise the Data Department on required updates to systems or policies.
- Education:
- Bachelor’s or Master’s in Data Science, Information Security, Law, Computer Science, cyber security or a related discipline.
- Preferred certifications: CIPP/E, CIPM, CIPT, CDPO, ISO 27701 Lead Implementer, or equivalent.
- Experience:
- 6–10 years of experience in data protection, governance, or information risk roles — ideally within a bank or financial services institution.
- Strong knowledge of data privacy regulations (DPDP Act 2023, GDPR, RBI data directives, etc.).
- Excellent analytical, communication, and stakeholder management skills.
- Ability to translate regulatory requirements into actionable data controls and processes.
- High integrity, confidentiality, and attention to detail.
- Demonstrated understanding of data lifecycle management, data governance frameworks (e.g., DAMA-DMBOK), and privacy compliance