24 Sep
|
Sumitomo Mitsui Banking Corporation (SMBC)
|
Delhi
24 Sep
Sumitomo Mitsui Banking Corporation (SMBC)
Delhi
Sumitomo Mitsui Banking Corporation
Purpose of the position The Data Protection Officer will serve as the central privacy leader responsible for establishing, implementing, governing, and continuously enhancing the Bank’s data protection and privacy framework. The role is accountable for supporting compliance with applicable data protection requirements, including the Digital Personal Data Protection Act, 2023, DPDP Rules, relevant RBI expectations / guidelines, and appropriate global privacy best practices.
The DPO will advise senior management and coordinate with Business, Technology, Information Security, Data Governance, Compliance, Legal, Risk, Operations and other relevant teams to embed privacy governance, privacy-by-design, risk assessment, incident response, grievance redressal and management reporting across the Bank.
The role is also responsible for promoting effective data governance, data management, data preparation and responsible data analysis and utilization practices to support regulatory compliance, risk management and business decision-making, including policies guided by applicable regulations in the offices supervised by SMBC India.
Primary Responsibilities
1. Develop and maintain the Bank’s privacy governance framework, strategy, policies, standards, procedures and operating model to ensure clear ownership and formal accountability across the data privacy lifecycle.
2. Interpret and monitor applicable privacy requirements, including DPDP Act / Rules, RBI expectations and relevant global privacy practices; advise stakeholders on regulatory impact and required implementation actions.
3. Drive enterprise privacy programme implementation, including privacy controls, monitoring mechanisms, privacy-by-design / default and integration of privacy requirements into products,
processes, technologies and change initiatives.
4. Develop and plan overall policies on data governance management based on applicable regulations in the offices supervised by SMBC India; enhance data preparation, information / data management framework and determine operating policies for data analysis and responsible data utilization.
5. Conduct or oversee privacy risk assessments, DPIA / PIA reviews / audits, high-risk processing reviews, data flow assessments and data inventory maintenance to identify, assess, mitigate and monitor privacy risks.
6. Govern data subject requests, grievance redressal, privacy incidents and breach response by coordinating with Legal, Compliance, Information Security, Technology, Business and Operations teams, including regulatory or data subject communication where applicable.
7. Oversee privacy awareness, training, third-party privacy obligations and vendor compliance monitoring to strengthen organizational privacy capability and third-party accountability.
8. Prepare privacy and data governance dashboards, metrics and periodic reports for senior management, executive / board-level forums and relevant governance committees to monitor progress, adoption, exceptions and residual risks.
Knowledge, Skills, Experience & Qualifications Knowledge Requirements: Strong understanding of privacy laws and data governance frameworks, including DPDP Act / Rules,
RBI expectations, privacy governance, data governance management, privacy risk management, DPIA / PIA, data subject rights, grievance redressal, privacy incident management and third-party data protection obligations.
Specialist / technical skills: Ability to design and implement privacy, data governance and data management frameworks, policies, controls and monitoring mechanisms; familiarity with data flow mapping, data inventory, data preparation, data quality, data analysis / utilization governance, consent management, data masking, anonymisation, security protocols, IT infrastructure and privacy management tools.
Behavioural / management skills: Executive stakeholder management, regulatory interpretation, enterprise governance, strategic leadership, programme management, risk management, communication, cross-functional collaboration and ability to develop privacy and data governance capabilities.
Relevant Experience: At least 15+ years of experience across data privacy & protection, information security and risk. Prior experience in implementing EU GDPR and / or leading and managing organisation-wide data privacy, data protection or data governance programme(s), such as DPDP. Experience in cross-functional stake-holder management including but not limited to IT/IS, operations, governance, risk & compliance.
- Education and Certifications: Relevant graduate / Post-graduate qualification. Preferred Data Privacy / Data Protection certifications include Certified Information Privacy Qualified (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT), Certified Information Systems Security Professional (CISSP), ISO 27701 or equivalent.
📌 Director / VP - Data Protection Officer (Delhi)
🏢 Sumitomo Mitsui Banking Corporation (SMBC)
📍 Delhi