04 Sep
|
sarc
|
New Delhi
Associate – Data Privacy & Protection (DPDP)
About SARC's DPDP Practice
SARC Global is a multidisciplinary advisory firm with 40+ years of heritage, 100+ partners, and 500+ professionals across India, UK, USA, Singapore, and UAE.
SARC is building India's most comprehensive DPDP and GRC practice, built from the DPDP Act upward. Our clients include India's largest enterprises across banking, NBFCs, insurance, stock exchanges, fintechs, and technology platforms.
Experience: 1–2 years
Location: Recent Delhi / Hybrid
Client-site travel may be required during fieldwork.
Reports To: Manager / Engagement Lead – SARC Data Protection Practice
Availability: Immediate to Max 30 days
Domain
Must have: DPDP Act 2023 and DPDP Rules 2025
Good to have: ISO 27701, ISO 27001, NIST, GRC / Privacy Technology Platforms
Role
As an Associate – Data Privacy & Protection (DPDP), you will support the delivery of DPDP readiness assessments and implementation engagements for Indian enterprises.
You will work alongside Managers and senior consultants on client engagements, supporting stakeholder discussions, documentation, assessments, data mapping, gap analysis, report preparation, and implementation activities.
This is a client-facing consulting role, providing exposure to CISOs, DPOs, Compliance teams, Legal teams, HR, IT, Procurement, and other business stakeholders.
Key Responsibilities
- Support DPDP Readiness Assessments covering Governance, Data Inventory & RoPA, Consent Management, Processor Governance, Security Safeguards, Data Principal Rights, Children's Data, Cross-Border Transfers, Breach Management, Training, Technology Enablement, and Ongoing Compliance.
- Participate in stakeholder interviews with business, HR, Legal, IT, Information Security, Procurement, Marketing, Compliance, and other relevant teams.
- Support the preparation and maintenance of Records of Processing Activities (RoPAs) and data inventories.
- Assist in creating Data Flow Diagrams (DFDs)
for key processing activities and identifying data flows, control points, gaps, and cross-border transfers.
- Research and analyse requirements under the DPDP Act 2023 and DPDP Rules 2025 and support documentation of statutory references.
- Assist in conducting PIAs / DPIAs / privacy gap assessments, including evidence collection, control assessment, gap identification, risk rating, and report preparation.
- Support preparation of assessment reports, presentations, remediation roadmaps, and management-level deliverables.
- Assist in identifying and documenting privacy and data protection gaps and recommending practical remediation actions.
- Support implementation activities across DPDP workstreams, including privacy notices, consent management, Data Principal Rights / DSR workflows, DPAs, breach management, policies, procedures, and training.
- Assist in assessing privacy technology solutions such as OneTrust, Securiti AI, BigID, Privasapien, or structured manual processes.
- Support mapping of DPDP requirements against sector-specific regulatory requirements such as RBI, SEBI, IRDAI, and CERT-In requirements.
- Support the design and documentation of consent architecture across different processing scenarios.
- Contribute to internal DPDP research, methodology development, sector-specific templates, training material, and practice-building initiatives.
Experience & Skills
- 1–2 years of relevant experience in data privacy, data protection, information security, GRC, risk consulting, compliance, or related areas.
- Exposure to DPDP Act 2023 and DPDP Rules 2025.
- Basic understanding of privacy assessments, audits,
compliance assessments, or information security assessments.
- Exposure to PIAs / DPIAs, privacy gap assessments, data inventories, or RoPA is preferred.
- Ability to understand and document data flows, business processes, systems, and processing activities.
- Solid research and documentation skills with the ability to interpret regulatory requirements and translate them into practical business requirements.
- Good written and verbal communication skills.
- Comfortable interacting with client stakeholders and working in a consulting / advisory environment.
- Strong attention to detail and ability to manage multiple deliverables and deadlines.
- Exposure to privacy technology platforms such as OneTrust, Securiti AI, BigID, or similar tools is a strong plus.
Education & Certifications
Candidates should have one of the following:
- B.Tech / B.E. in Computer Science, Information Technology, or related engineering discipline; OR
- LLB / BA LLB / BBA LLB with technology / privacy exposure; OR
- MBA with specialisation in Information Systems, Risk Management, Compliance, or related areas; OR
- Any graduate degree with relevant privacy, security, GRC, or compliance experience.
Preferred Certifications
- CIPP/E (IAPP)
- CIPM (IAPP)
- DCPP (DSCI/Nasscom)
- ISO 27701
- ISO 27001
Privacy technology certifications such as OneTrust, Securiti AI, or BigID are an additional advantage.
What You'll Gain
- Hands-on exposure to DPDP Act and Rules implementation.
- Experience working with large enterprises across banking, financial services, insurance, fintech, and technology sectors.
- Exposure to senior client stakeholders and privacy / security leadership.
- Practical experience in RoPA, data mapping, DPIA/PIA, privacy assessments, and DPDP implementation.
- Opportunity to work across privacy advisory and GRC engagements.
- Opportunity to contribute to and grow with SARC's expanding DPDP & Data Privacy practice.
📌 Associate, Data Privacy and Protection ( DPDP) (New Delhi)
🏢 sarc
📍 New Delhi