07 Aug
|
SMFG India Credit
|
Mumbai
07 Aug
SMFG India Credit
Mumbai
Key Responsibilities
Policy & Framework Management
Design, implement, and maintain enterprise-wide data privacy policies, standards, and procedures
Align internal frameworks with regulatory requirements such as DPDP Act and global best practices
Periodically review and update policies to reflect regulatory and business changes
Data Privacy Legal SME knowledge
Design / Draft / Review the notice framework, notices and consent statements during the implementation
Draft / Review the legal agreements as a part of the privacy operations. TPRM / Vendor management framework deliverables from a legal standpoint.
Legal interpretation of the DPDP Act, DPR responses, Breach Management, etc.
Governance & Oversight
Establish and run data privacy governance forums and reporting structures
Define roles and responsibilities across business units (Data Fiduciary, Processor, etc.)
Drive accountability for privacy compliance across functions
Regulatory Compliance & Advisory
Interpret privacy regulations and translate them into actionable internal controls
Provide advisory to business, legal, and technology teams on privacy requirements
Ensure readiness for regulatory audits and inspections
Risk Management & Controls
Define and monitor privacy risk frameworks, controls, and KRIs
Oversee DPIA/PIA frameworks and ensure effective implementation
Track and mitigate privacy risks across business processes
Training & Awareness
Develop and drive enterprise-wide privacy awareness programs
Ensure policy understanding and adoption across employees and stakeholders
Stakeholder Management
Collaborate with Legal, IT, Security, Compliance, and Business teams
Act as a key liaison with regulators, auditors, and external stakeholders
Key Deliverables
Robust and up-to-date data privacy policy framework
Governance dashboards and compliance reporting
Vendor agreement reviews
Draft / Review DP addendums
DPIA/PIA implementation maturity
Audit readiness and closure of observations
Organization-wide awareness and adherence to privacy standards
Qualifications & Skills
Education:
Bachelors degree in IT, Law (Cyberlaw), Risk, or related field
Certifications preferred: CIPP, CIPM, DCPP (India), ISO 27701 Lead Implementer
Experience:
8–15 years in data privacy, compliance, or risk management
Robust experience in policy drafting and governance frameworks
Experience in banking/financial services preferred
📌 Senior Manager / Avp Data Protection Mumbai
🏢 SMFG India Credit
📍 Mumbai