Corporate Director / Manager - Data Privacy & Compliance
The Indian Hotels Company Limited (IHCL) · Mumbai Metropolitan Region
Apply & track with Apply EdgeIHCL and its subsidiaries bring together a group of brands and businesses that offer a fusion of warm Indian hospitality and world-class service. These include Taj – the iconic brand for the most discerning travellers, and ranked as ‘World’s Strongest Hotel Brand’ and ‘India’s Strongest Brand’ across sectors as per Brand Finance Hotels 50 and India 100 reports 2024 respectively; SeleQtions, a named collection of handpicked, storied hotels; Vivanta, a chain of contemporary upscale hotels that celebrate joie de vivre; Ginger, a brand that is revolutionizing the lean-luxe segment, and amã Stays & Trails, a charming portfolio of private bungalows and villas set in picturesque locales.Location: MumbaiFunction: Information Systems / Digital & ITReporting : AVP-IT About the RoleIHCL is seeking a Data Privacy professional to support the implementation and operation of the enterprise Data Privacy Program, ensuring compliance with the Digital Personal Data Protection (DPDP) Act, 2023, GDPR and privacy requirements across hotels, digital platforms, loyalty programs, corporate functions, and third-party ecosystems.Key ResponsibilitiesDrive Data Privacy and DPDP compliance initiatives across business and technology functions.Develop and maintain Personal Data Inventory, Data Flow Diagrams, and Records of Processing Activities (RoPA).Conduct Privacy Impact Assessments (PIA/DPIA) and identify privacy risks.Review privacy notices, consent mechanisms, and customer data collection practices across websites, mobile apps, and digital platforms.Manage Data Principal Rights requests, including access, correction, erasure, and consent withdrawal.Perform privacy due diligence and assessments of third-party vendors and service providers.Deliver privacy awareness programs, training sessions, and stakeholder engagement initiatives.Prepare privacy dashboards, compliance metrics, audit evidence, and management reports.Desired Candidate ProfileEducationBachelor’s degree in information technology, Information Systems, Computer Science, Cyber Security, Law, Risk Management, or related disciplines.Experience3-5 years of experience in Data Privacy, Data Protection, Information Security Compliance, GRC, or Risk Management.Experience in implementing privacy frameworks and compliance programs.Exposure to consumer-facing industries such as Hospitality, Travel, Retail, Healthcare, BFSI, or E-commerce preferred.Knowledge & SkillsDPDP Act 2023, GDPR, Privacy by Design.Data Mapping, RoPA, Consent Management, Privacy Assessments.ISO 27701 and ISO 27001 awareness.Strong documentation, stakeholder management, and analytical skills.Hands-on experience with Microsoft 365, Excel, Power BI, SharePoint, and process-mapping tools.Preferred CertificationsCIPP, CIPM, CIPT (IAPP)ISO 27701 / ISO 27001DSCI Privacy Certification