06 Aug
|
SMFG INDIA CREDIT
|
Mumbai
06 Aug
SMFG INDIA CREDIT
Mumbai
Key Responsibilities
1. Policy & Framework Management
- Design, implement, and maintain enterprise-wide data privacy policies, standards, and procedures
- Align internal frameworks with regulatory requirements such as DPDP Act and global best practices
- Periodically review and update policies to reflect regulatory and business changes
2. Data Privacy Legal SME knowledge
- Design / Draft / Review the notice framework, notices and consent statements during the implementation
- Draft / Review the legal agreements as a part of the privacy operations. TPRM / Vendor management framework deliverables from a legal standpoint.
- Legal interpretation of the DPDP Act, DPR responses, Breach Management, etc.
3. Governance & Oversight
- Establish and run data privacy governance forums and reporting structures
- Define roles and responsibilities across business units (Data Fiduciary, Processor, etc.)
- Drive accountability for privacy compliance across functions
4. Regulatory Compliance & Advisory
- Interpret privacy regulations and translate them into actionable internal controls
- Provide advisory to business, legal, and technology teams on privacy requirements
- Ensure readiness for regulatory audits and inspections
5. Risk Management & Controls
- Define and monitor privacy risk frameworks, controls,
and KRIs
- Oversee DPIA/PIA frameworks and ensure effective implementation
- Track and mitigate privacy risks across business processes
6. Training & Awareness
- Develop and drive enterprise-wide privacy awareness programs
- Ensure policy understanding and adoption across employees and stakeholders
7. Stakeholder Management
- Collaborate with Legal, IT, Security, Compliance, and Business teams
- Act as a key liaison with regulators, auditors, and external stakeholders
Key Deliverables
- Robust and up-to-date data privacy policy framework
- Governance dashboards and compliance reporting
- Vendor agreement reviews
- Draft / Review DP addendums
- DPIA/PIA implementation maturity
- Audit readiness and closure of observations
- Organization-wide awareness and adherence to privacy standards
Qualifications & Skills
Education:
- Bachelors degree in IT, Law (Cyberlaw), Risk, or related field
- Certifications preferred: CIPP, CIPM, DCPP (India), ISO 27701 Lead Implementer
Experience:
- 8–15 years in data privacy, compliance, or risk management
- Robust experience in policy drafting and governance frameworks
- Experience in banking/financial services preferred
📌 Senior Manager / AVP - Data Protection (Mumbai)
🏢 SMFG INDIA CREDIT
📍 Mumbai