13 Sep
|
RethinkingWeb
|
Thane
13 Sep
RethinkingWeb
Thane
Job Overview
We are looking for a DPDP Analyst to support the organization and its clients in implementing and maintaining compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and other applicable data privacy requirements.
The role involves privacy assessments, data inventories, regulatory monitoring, policy development, stakeholder coordination, documentation, and supporting privacy awareness initiatives.
Key Responsibilities1. Regulatory Compliance Guidance
- Advise internal teams and clients on the application of the DPDP Act and other applicable privacy and data protection regulations.
- Monitor regulatory developments, guidelines, notifications, and industry practices related to data protection.
- Assess the potential impact of regulatory changes on business operations, processes, and data handling practices.
- Support the development of action plans to address identified compliance gaps.
1. Data Privacy Assessments
- Conduct Data Protection Impact Assessments (DPIAs) and privacy risk assessments for new projects, products, processes, and technologies.
- Prepare and maintain Records of Processing Activities (ROPA) .
- Create, maintain, and update Personal Data Inventories (PDI) .
- Review data processing activities to identify privacy risks, gaps, and areas requiring remediation.
- Assist in creating and maintaining data flow maps , processing inventories, and other privacy documentation.
- Support periodic privacy audits and compliance assessments.
1. Policy and Procedure Development
- Develop, review, and maintain data protection policies, procedures, standards, and guidelines.
- Assist in aligning organizational privacy practices with the DPDP Act and applicable regulatory requirements.
- Support teams in drafting and reviewing Data Processing Agreements (DPAs) and privacy-related contractual clauses.
- Assist with third-party and vendor privacy assessments and documentation.
- Support the implementation of privacy-by-design principles across business processes and projects.
1. Training and Awareness
- Develop and deliver data privacy and data protection awareness sessions for employees and stakeholders.
- Create training materials, presentations, guidelines, FAQs, and awareness communications.
- Promote best practices for handling, storing, sharing, retaining, and disposing of personal data.
- Support periodic privacy awareness campaigns and employee training programs.
1. Ongoing Monitoring and Reporting
- Monitor privacy compliance activities, identified risks, remediation actions, and compliance status.
- Track privacy-related observations and follow up with stakeholders to ensure timely closure.
- Prepare periodic privacy compliance and risk management reports for management and clients.
- Maintain appropriate records and evidence of privacy compliance activities.
- Provide recommendations to improve privacy controls and compliance maturity.
1. Stakeholder Management
- Collaborate with Legal, IT, Information Security, HR, Procurement, Business, and other internal teams to integrate privacy requirements into business processes.
- Coordinate with stakeholders to collect information required for privacy assessments, ROPA, PDI, audits, and compliance reviews.
- Act as a point of contact for clients and internal stakeholders on day-to-day data privacy matters.
- Ensure effective coordination, communication, and follow-up for privacy-related activities.
- Support client meetings, assessments, presentations,
and compliance reviews.
Key Skills & Competencies
- Valuable understanding of the Digital Personal Data Protection (DPDP) Act, 2023 and fundamental data privacy concepts.
- Familiarity with privacy frameworks, principles, and data protection practices.
- Understanding of DPIA, ROPA, Personal Data Inventory, data flow mapping, consent, data retention, data subject rights, and third-party risk .
- Familiarity with privacy-enhancing technologies and data privacy management tools.
- Understanding of information security concepts and their relationship with data privacy.
- Ability to analyze business processes and identify privacy risks.
- Strong documentation and report-writing skills.
- Good communication and presentation skills.
- Strong coordination, stakeholder management, and follow-up skills.
- Ability to work with cross-functional teams and clients.
- Good attention to detail and ability to manage multiple compliance activities simultaneously.
Qualifications & Experience
- Bachelor's degree in Law, Information Technology, Cybersecurity, Information Security, Business Administration, or a related field .
- 1–3 years of experience in data privacy, compliance, information security, GRC, risk management, or a related field.
- Experience working on privacy assessments, compliance documentation, audits, or policy development will be an advantage.
- Certifications such as CIPP/E, CIPP/US, CIPM, CIPT, ISO 27001, or other privacy/GRC certifications are desirable.
Preferred Candidate Profile The ideal candidate should be analytical, detail-oriented, proactive, and comfortable working with both technical and business stakeholders . The candidate should be able to understand how an organization collects, processes, stores, shares, and manages personal data and translate privacy requirements into practical business actions.
📌 DPDP Analyst (Thane)
🏢 RethinkingWeb
📍 Thane