Sr. Associate - Data Privacy & Protection - Infosec (New Delhi)

Sr. Associate - Data Privacy & Protection - Infosec (New Delhi)

08 Aug
|
Hero FinCorp
|
New Delhi

08 Aug

Hero FinCorp

New Delhi

Key Responsibilities

The Data Privacy Lead will be responsible for designing, implementing, and managing the organization's data privacy framework in compliance with applicable regulatory requirements (such as DPDP Act, RBI guidelines etc.). The role involves ensuring the protection of customer and employee personal data, embedding privacy-by-design principles, and minimizing privacy risks across business operations.

1. Privacy Governance Framework

- Develop, implement, and maintain enterprise-wide data privacy policies, standards, and procedures.
- Establish a robust privacy governance framework aligned with regulatory and business requirements.
- Drive privacy-by-design and privacy-by-default principles across products and services.

2. Regulatory Compliance

- Ensure compliance with applicable laws such as:
- Digital Personal Data Protection (DPDP) Act, India
- RBI guidelines for NBFCs

- Liaise with regulators, auditors, and legal teams during assessments and reviews.
- Conduct periodic compliance assessments and gap analysis.

3. Data Lifecycle Management

- Oversee data classification, retention, and deletion frameworks.
- Ensure proper handling of sensitive personal data across its lifecycle.
- Monitor third-party data processing and ensure contractual privacy obligations.

4. Privacy Risk Management

- Conduct Data Protection Impact Assessments (DPIAs) and Privacy Impact Assessments (PIAs).
- Identify privacy risks and implement mitigation strategies.
- Integrate privacy risks into enterprise risk management frameworks.

5. Incident Management Breach Response

- Define and manage processes for personal data breach identification, escalation, and reporting.
- Ensure timely breach notifications as per regulatory requirements.




- Coordinate with IT Security and Legal teams during incidents.

6. Stakeholder Engagement

- Partner with business, technology, HR, legal, and compliance teams to embed privacy controls.
- Provide guidance on recent products, digital initiatives, and data sharing arrangements.

7. Awareness Training

- Drive privacy awareness programs across the organization.
- Conduct training sessions on data protection obligations and best practices.

8. Third-Party Risk Management

- Evaluate privacy controls of vendors, partners, and service providers.
- Ensure appropriate Data Processing Agreements (DPAs) are in place.

9. Other Deliverables

- Responsible for maintenance of company privacy and data protection policies, processes and standards that address privacy and data protection regulations
- Provides mentoring and technical leadership for privacy implementations.
- Provides consultation and support to business units and functions and promotes awareness of privacy concepts, legal and regulatory requirements, company privacy and data protection policies, processes, and standard methods and tools.
- Communicates and collaborates with key stakeholders on internal privacy matters.
- Leads privacy and data protection impact assessments against business activity that involves personal information.
- Identifies privacy risks, leads resolution and the development of mitigation plans,



and recommends safeguards and controls.
- Maintains understanding of organization's privacy and information protection policies, processes, controls, standard practices, and global regulatory requirements.
- Leads the documentation of processes and improvements.
- Monitors privacy regulations, technology trends, business process changes, and developments in the privacy field; evaluates potential business impacts; and implements applicable changes to Company privacy and data protection governance in response.
- Leads development of privacy policy compliance measures and consults and reports on Company privacy activities to ensure adherence with policies and procedures, regulations, and industry best practices.
- Leads development and manages privacy risk management processes.
- Leads response to data subject rights requests and response to privacy incidents.
- Guides development of privacy and data protection training and awareness materials for employees.
- Collaborates with internal audit to review appropriate privacy measures, procedures and evidence to ensure continuous compliance, quality and efficiency.
- Leads due diligence for mergers and acquisitions, and subsidiary integrations, ensuring privacy risks are addressed and resolved.
- Guides efforts of Sales and Marketing campaigns and projects to ensure privacy by design and compliance with privacy and data protection requirements.
- Represents the company's privacy interests with external parties.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Sr. Associate - Data Privacy & Protection - Infosec (New Delhi)
🏢 Hero FinCorp
📍 New Delhi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr. associate - data privacy & protection - infosec (new delhi) / new delhi

Subscribe to this job alert:

Get the latest job offers by email for: sr. associate - data privacy & protection - infosec (new delhi) / new delhi