Data Protection Officer : 3-7 Years The Data Protection Officer shall serve as the central point of accountability for privacy and data protection matters within Onextel. The DPO will advise management on privacy obligations, monitor compliance with applicable regulations, oversee privacy risk management activities, and act as the primary point of contact for Data Principals, customers, and regulatory authorities.
The role requires close collaboration with Legal, Information Security, Engineering, Product, HR, Procurement, Customer Success, and Operations teams to embed privacy-by-design principles across the organization and support business growth while protecting individual privacy rights.
Key Responsibilities
1. Privacy Compliance and Governance
- Monitor and ensure compliance with applicable data protection and privacy laws, including the Digital Personal Data Protection Act (DPDPA), 2023, the Information Technology Act, 2000 and rules made thereunder, GDPR, and other relevant regulations.
- Establish, maintain, and continuously improve the organization's privacy governance framework.
- Develop privacy policies, standards, procedures, and controls aligned with legal and regulatory requirements.
- Conduct periodic privacy compliance reviews, audits, and assessments to identify and address compliance gaps.
- Prepare privacy compliance reports and provide updates to senior management regarding privacy risks and mitigation measures.
2. Privacy Risk Management
- Identify, assess, and manage privacy risks arising from business operations, products, services, and technology initiatives.
- Maintain a privacy risk register and track remediation activities.
- Advise management on privacy-related risks associated with business decisions and strategic initiatives.
- Recommend technical and organizational measures to mitigate identified risks.
3. Data Protection Impact Assessments (DPIAs)
- Conduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments for new products, services, systems, technologies, vendors, and data processing activities.
- Review existing data processing activities and recommend improvements where necessary.
- Ensure privacy considerations are incorporated throughout the lifecycle of products and services.
4.
Privacy by Design and Business Enablement
- Promote and implement Privacy by Design and Privacy by Default principles across the organization.
- Participate in product and technology reviews to ensure privacy requirements are considered during design, development, and deployment.
- Support business teams in achieving operational objectives while maintaining compliance with applicable privacy requirements.
5. Data Principal Rights and Grievance Redressal
- Act as the primary point of contact for Data Principals regarding privacy inquiries, grievances, and requests.
- Manage requests concerning access, correction, deletion, consent withdrawal, and other rights available under applicable privacy laws.
- Ensure timely and effective resolution of privacy-related complaints and concerns.
- Maintain records of complaints and track their resolution within prescribed timelines.
6. Regulatory Engagement
- Serve as the principal liaison between Onextel and data protection regulators, supervisory authorities, and government agencies.
- Coordinate responses to regulatory inquiries, inspections, audits, and investigations.
- Monitor developments in privacy laws and regulations and advise the organization on necessary compliance measures.
- Support regulatory reporting and notification obligations where applicable.
7. Third-Party Privacy Risk Management
- Conduct privacy assessments and due diligence reviews of vendors, partners, and service providers.
- Review Data Processing Agreements (DPAs), privacy clauses, and data-sharing arrangements.
- Evaluate cross-border data transfer mechanisms and associated privacy risks.
- Establish ongoing monitoring processes for third-party compliance with privacy requirements.
8. Training and Awareness
- Develop and implement privacy awareness and training programs across the organization.
- Conduct workshops and targeted training sessions for employees,
contractors, and management.
- Promote a company-wide culture of privacy, accountability, and responsible data handling.
9. Privacy Incident and Breach Management
- Lead the privacy incident response process in coordination with Information Security, Legal, and relevant business teams.
- Assess privacy incidents and determine legal and regulatory notification requirements.
- Coordinate communication with regulators, customers, partners, and affected Data Principals where required.
- Conduct root-cause analysis and drive corrective and preventive actions to minimize future incidents.
10. Cross-Functional Collaboration
- Work closely with Legal, Information Security, Procurement, HR, Product, Engineering, Operations, and Customer Support teams.
- Provide privacy guidance during new projects, business initiatives, partnerships, and acquisitions.
- Support contract negotiations involving privacy and data protection obligations.
Qualifications and Experience
- Bachelor's degree in Law, Information Technology, Computer Science, Information Security, Business Administration, or a related discipline.
- Minimum 6-8 years of relevant experience in privacy, compliance, information security, legal, governance, or risk management roles.
- Demonstrated experience in implementing and managing privacy compliance programs.
- Strong working knowledge of:
- Digital Personal Data Protection Act (DPDPA), 2023
- Information Technology Act, 2000
- GDPR
- Global privacy and data protection frameworks
- Experience working within technology, telecommunications, SaaS, CPaaS, cloud, or digital service environments will be preferred.
- Experience interacting with regulatory authorities and managing audits or investigations is desirable.
Preferred Certifications
One or more of the following certifications will be considered advantageous:
- Certified Information Privacy Professional (CIPP)
- Certified Information Privacy Manager (CIPM)
- Certified Information Privacy Technologist (CIPT)
- ISO 27701 Lead Implementer / Lead Auditor
- ISO 27001 Lead Implementer / Lead Auditor
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Qualified (CISSP)
📌 Data Protection Officer (Noida)
🏢 OneXtel
📍 Noida