30 Sep
|
Pernod Ricard India
|
Gurugram
30 Sep
Pernod Ricard India
Gurugram
JOB SUMMARY:
The Data Privacy Analyst (DPA) is an operational, execution-focused role within Data Governance & Strategy function. The role is responsible for translating data privacy strategy into day-to-day execution across the organisation. Acting as the operational backbone of DPDPA compliance programme, the DPA leads data privacy risk assessments, Data Principal rights fulfilment, grievance-handling activities, vendor privacy due diligence, data cataloguing, and KRI/KPI tracking, while coordinating with Data Stewards across business functions.
KEY RESPONSIBILITIES
Data Privacy Risk Assessments
- Lead execution of data privacy risk assessments and Data Protection Impact Assessments (DPIAs) for major projects, systems, and changes.
- Coordinate implementation of privacy controls across departments and monitor departmental compliance, escalating gaps to the DG Lead.
- Support, draft and maintain Privacy policies, procedures, and controls across functions.
Data Principal Rights, Consent & Grievance Support
- Own end-to-end coordination of Data Principal Access Requests (DPARs), including intake, tracking, and closure within defined turnaround times.
- Support consent management processes and coordinate with Tech Proximity on consent capture and withdrawal mechanisms.
- Support the DG Lead in grievance redressal, incident detection, documentation, response coordination, and investigations.
Data Cataloguing and Retention practises
- Maintain and continuously update PRI's enterprise data catalogue; identify and tag PII elements across systems.
- Own data quality, data lineage, and metadata management for Personal data
- Ensure Data Stewards maintain accurate, current personal data inventories and Records of Processing Activities (RoPA); provide first-line support on RoPA queries.
- Enable data minimization at personal data collection touchpoints in coordination with Tech Proximity.
- Coordinate with the DG Lead on retention execution and secure disposal of personal data as per aligned retention schedule.
Vendor & Third-Party Privacy
- Execute vendor data privacy due diligence questionnaires (DDQs) and coordinate remediation of gaps identified during onboarding or periodic review.
- Support review of Data Processing Agreements and privacy clauses in coordination with Legal.
Data Governance Administration, Training & Reporting
- Maintain minutes, action tracker, and decision log for all data governance council meetings.
- Plan, conduct, and assist in delivering privacy training and awareness programs for employees and contractors.
- Track and report privacy KPIs/KRIs (breach metrics, DPAR volumes and TAT, training completion, vendor assessment pipeline, retention compliance) to the DG Lead and Data Governance Council on a recurring basis.
- Act as the internal privacy subject-matter resource, providing day-to-day guidance to Data Stewards on control implementation and interpretation of legal requirements.
- Collaborate cross-functionally with Tech, HR, Legal, Procurement, and business pillars (S2P, F2S, O2C, R2D) to embed privacy into operations, including LEAP S/4HANA workstreams as required.
INTERACTIONS
INTERNALLY
- Data Stewards (across all business functions)
- Tech Proximity Team
- Legal
- Cyber Security Team
EXTERNALLY
- Vendors
KEY PERFORMANCE INDEX
- Timely closure of DPARs, grievances and privacy risk assessments/DPIAs within defined turnaround times.
- Adherence of applicable processes and statutory rules.
- Data catalogue,
RoPA and vendor DDQ coverage maintained at target currency.
- Training and awareness completion.
PROFILE DETAILS
QUALIFICATION:
Essential/Must-have: Bachelor's or Master’s degree in information technology, Data Management, Business Administration, Law, or a related discipline.
Desirable/Good to have: Any Data Privacy Related certifications (CIPP/E, CIPM, or CIPT); any data governance certification (e.g. CDMP, DCAM) is an added advantage given the data quality and cataloguing scope of this role
EXPERIENCE: Consumer Durable, FMCG, Alcobev / Bev / Banking
Essential/Must-have:
- 3–6 years of experience in data privacy, data protection, information governance, or compliance roles, ideally within a regulated or multinational environment (AlcoBev / Bev experience is added advantage)
- Working knowledge of the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, including Data Principal rights, consent, and breach notification requirements.
- Practical experience with RoPA maintenance, DPIA/privacy risk assessment execution, and vendor privacy due diligence.
- Robust documentation, stakeholder coordination, and cross-functional communication skills — this role interfaces regularly with Legal, Cybersecurity, Tech Proximity, and business-side Data Stewards.
Desirable/Good to have: Exposure to data privacy, data governance, data cataloguing or data quality practices is an added advantage
FUNCTIONAL COMPETENCIES:
Essential/Must-have:
- Analytical rigor and attention to detail in policy interpretation and control design
- Ability to operate independently on execution while escalating judgment calls appropriately to the DG Lead
- Comfort working across a matrixed stakeholder base without direct reporting authority
- Discretion and confidentiality in handling sensitive personal data and grievance matters
- Relationship Building
📌 Data Privacy Analyst (Gurugram)
🏢 Pernod Ricard India
📍 Gurugram