06 Aug
|
BOBCARD
|
Goregaon
The Data Protection Officer (DPO) will be responsible for designing, implementing, and overseeing a comprehensive data protection and privacy governance framework encompassing customer, borrower, employee, vendor, and partner data. The role requires close collaboration with Compliance, Risk, IT, Information Security, Legal, Operations, and Internal Audit to ensure enterprise-wide alignment with regulatory requirements. The DPO will also own and maintain the organizations Record of Processing Activities (ROPA), ensuring accurate, up-to-date, and audit-ready documentation of all personal data processing activities across the data lifecycle.
Key highlights of the role are listed below (purely indicative and not limiting):
Regulatory Compliance & Governance • Ensure compliance with DPDPA 2023 and applicable RBI circulars (IT Governance, Cybersecurity Framework, Outsourcing Guidelines, Digital Lending Guidelines). • Serve as the official point of contact for the Data Protection Board of India and coordinate regulatory communications. • Provide periodic updates to the Board and senior management on data protection posture and risks
Record of Processing Activities (ROPA) Management • Design, implement, and maintain a centralized Record of Processing Activities (ROPA) covering all personal data flows across business units. • Map end-to-end data lifecycle: collection, purpose, storage, sharing, retention, and deletion. • Ensure ROPA is regularly updated and audit-ready for internal audit, RBI inspection, and regulatory review. • Integrate ROPA with data classification, retention schedules, vendor management, and risk assessments.
Customer Data Protection • Oversee lawful processing of financial, KYC, credit bureau, and transaction data • Implement mechanisms for managing consent, legitimate uses, and purpose limitation • Manage data principal rights requests (access, correction, erasure, grievance redressal)
Risk Assessment & Monitoring • Conduct Data Protection Impact Assessments (DPIAs) for credit card issuance, digital lending platforms, analytics initiatives, and third-party integrations. • Identify privacy risks in loan origination systems (LOS), core lending systems, CRM platforms, and fintech partnerships. • Ensure vendor due diligence for data processing partners and outsourcing service providers
Data Breach & Incident Response • Lead data breach investigation, documentation, and reporting to the Data Protection Board and other regulators, where applicable. • Align breach reporting timelines with RBI cybersecurity reporting requirements • Strengthen internal detection and response mechanisms.
Policy & Controls • Develop and maintain Privacy Policy, Data Retention Policy, Data Classification Framework, and Cross-Border Data Transfer assessments. • Ensure alignment between DPDPA compliance and Information Security controls (ISO 27001, ISO 27701 or equivalent). • Maintain records of processing activities and compliance documentation
Training & Awareness • Conduct periodic privacy and data handling training for frontline lending teams, collection teams, and digital platform users. • Promote privacy-by-design principles in digital lending and fintech integrations
📌 AVP - Data Protection Officer (Goregaon)
🏢 BOBCARD
📍 Goregaon