04 Aug
|
Sftwtrs.ai
|
Gurugram
04 Aug
Sftwtrs.ai
Gurugram
Data Protection Officer Sftwtrs.AI Gurugram, Haryana
About us Sftwtrs.AI builds enterprise AI infrastructure. Knowledge graph systems, industrial computer vision, voice AI platforms handling call volumes at national scale, and browser automation. Our clients are manufacturers, infrastructure companies, and government departments, in India and abroad.
Alongside the product work we run a cybersecurity and compliance practice. Security architecture and assessment, data discovery and classification, data loss prevention, database activity monitoring, identity and access assurance, incident response, and regulatory compliance across the DPDP Act, ISO 27001 and sector frameworks. Our leadership comes from a cybersecurity and digital forensics background, so this is where the company started rather than something bolted on later.
Which means we sit in an unusual place. We are not a privacy consultancy that advises from the outside. We build the systems that process the data, we secure them, and increasingly our clients need someone who can answer for how that processing stands up under the Digital Personal Data Protection Act, 2023.
About the role The Act came into force with the Rules published in November 2025, and the bulk of obligations commence eighteen months from that date. Government departments running citizen databases at real scale are working out what compliance means in practice, largely without precedent. Enterprise clients deploying AI systems face a harder version of the same question, because inference and derived attributes do not map cleanly onto a framework written around collection and consent.
You will be the named Data Protection Officer on our engagements, the person who represents client departments before the Data Protection Board of India, and the one who decides what good practice looks like here.
You will not do it alone. This role sits inside our cybersecurity and compliance team, alongside security architects, forensics and incident response specialists, and the engineers who deploy our discovery, DLP and monitoring stack. Privacy questions in practice are rarely only legal ones, and you will have the technical people next to you when they are not.
The distinctive part of this role is that you will sit next to engineers. When a discovery tool needs to classify children's data, or a consent withdrawal has to propagate through a knowledge graph, or an AI system has to be prevented from inferring something a data principal never consented to, you will be in that design conversation rather than reviewing it afterward.
What you will do Act as named DPO. Serve as the designated Data Protection Officer for client organisations under Section 10(2)(a), and represent them before the Data Protection Board of India in all proceedings. You are the single point of contact for Board communications, notices and show-cause proceedings.
Build the policy foundation. Draft and maintain privacy policies,
consent notice templates in Hindi and English as required under Section 5(3), data retention policies, data subject rights procedures, and vendor data processing agreements.
Run impact assessments. Conduct periodic Data Protection Impact Assessments under Section 10(2)(c) and Rule 13, maintain the DPIA register, and file the annual DPIA report with the Board under Rule 13(2).
Handle data principal rights. Manage and respond to Data Subject Access Requests under Sections 11 to 13 within statutory timelines, maintain the DSAR log, and oversee client grievance mechanisms under Section 8(10) within the ninety-day limit set by Rule 14(3).
Advise on the build. Work with our engineering teams on privacy questions that arise inside the products: consent propagation, purpose binding, retention enforcement, and the treatment of inferred and derived personal data in AI systems.
Lead compliance assessments. Run gap assessments against the Act and Rules: data flow mapping, legal basis classification under Sections 4 to 7, children's data review under Section 9 and Rule 10, processor contract review, and cross-border transfer assessment under Section 16. Produce the gap report, remediation roadmap and executive summary that clients act on.
Track the regulation as it moves. Monitor amendments to the Act, the Rules, Board regulations and MeitY notifications, and issue monthly regulatory update notes to clients.
Report. A short monthly compliance status report to each client, and an annual compliance posture report.
Shape the practice. Set the methodology our gap assessments run on. Build the templates the rest of the team works from. Mentor the privacy analysts we hire behind you.
What you need Essential
- LLB or LLM from a recognised university
- Minimum five years of demonstrable data privacy experience
- A current privacy certification: CIPP, CIPM, CDPSE, or an equivalent recognised privacy credential
- At least two prior engagements in which you were the named or acting Data Protection Officer, evidenced by an appointment or engagement letter
- Working knowledge of Hindi, sufficient to review consent notices and correspond with government officials
- Willingness to be named as the designated DPO in client and tender documentation, and to remain in that role for the duration of engagements
Valued, not required
- Experience with Indian public sector or PSU clients
- Familiarity with GDPR, and the judgement to know where it does and does not map onto the DPDP framework
- Prior work on consent management platforms or data discovery tooling
- Comfort with technical architecture. You do not need to write code,
but you should be able to read a data flow diagram and ask the right question about it
- Experience appearing before a regulator or tribunal
- Enrolment with a State Bar Council
What this role asks of you Worth being direct about, because it shapes the day.
You will be a named individual in formal government documentation. Your CV, degree and certification will be submitted to and verified by client organisations and procurement authorities. Changing the named DPO mid-engagement requires client approval and carries contractual consequence, so this is a role that needs someone intending to stay.
Client engagements carry response commitments: queries answered within four business hours, DSARs managed within thirty days. Each client is allocated a minimum of eight hours per week, with escalation response inside four hours.
Travel within Haryana is part of the work. Clients are in Chandigarh, Panchkula, Gurugram and elsewhere across the state, and some of this cannot be done remotely.
What we offer Compensation. Competitive and negotiable against experience. We would rather pay properly for the right person than fill the seat.
Standing. You are the practice, not a resource inside someone else's. Your name goes on the work.
Range. Government departments, manufacturing, infrastructure and enterprise clients. Data protection sitting alongside real security engineering rather than as a document exercise.
A team, not a seat. You join a cybersecurity and compliance practice that is growing, with security, forensics and compliance colleagues to work against rather than a solo advisory post.
Support. Certification renewal and continuing education funded. Conference and qualified body membership covered.
Autonomy. A small team, short decisions, and no layer between you and the client.
How to apply Send a CV and a short note to [email] with the subject line DPO Application.
The note matters more than the covering letter. Tell us about one privacy problem you worked on that did not have a clean answer, and how you decided. We read these.
Please include
- Degree and certification details, with certification number and validity
- The two or more DPO engagements you would rely on, with dates and scope. Client names may be withheld at this stage if you are under confidentiality obligations
- Notice period and earliest availability
- Confirmation that you are not currently a serving government employee, and that you are not a relative of an official at any procurement authority we bid to. This is a declaration requirement in government tenders where key personnel are named, so we have to ask early
We respond to every application.
Sftwtrs.AI is the brand under which Nilesh AI Systems Pvt Ltd operates. Employment is offered by Nilesh AI Systems Pvt Ltd, CIN U46512HR2023PTC116126, Gurugram.
We are an equal opportunity employer. We assess candidates on capability and judgement.
📌 Data Protection Officer (Gurugram)
🏢 Sftwtrs.ai
📍 Gurugram