Data Privacy | One of the leading Big4
Acme Services · Mumbai, Maharashtra, India
Apply & track with Apply EdgeRole: Data PrivacyYears of Experience: 9-13 YearsLocation: Mumbai This Job Role:Design, execution, and sustained management of the organization's data privacy compliance program across all business verticals, ensuring demonstrable adherence to applicable laws, regulatory guidelines and internal policies.Regulatory & Legislative AlignmentCompliance Reporting & Stakeholder AssuranceJob Roles & Responsibilities:Own the end-to-end execution and maintenance of the enterprise data privacy compliance program across the group and individual business verticals (retail, healthcare, education, etc.), ensuring all processing activities meet regulatory obligations and internal policy standards.Lead DPDPA compliance operationalization across all businesses — including data inventory and records of processing activities (RoPA), lawful basis documentation, consent mechanism implementation, and cross-border data transfer compliance under applicable adequacy and contractual frameworks.Drive the attainment and sustained compliance of Privacy Information Management System (PIMS) / ISO 27701 certification across business units, while maintaining alignment with the ISO 27001 information security management system.Act as a primary compliance interface for internal business teams, auditors, and regulatory authorities on data privacy matters.Maintain a dynamic regulatory compliance register mapping applicable obligations under the ITAct 2000, DPDP Act 2023, DPDP Rules 2025, GDPR, and other relevant global privacy statutes to organizational processes, controls, and accountable owners.Conduct periodic compliance assessments across business units to identify gaps, partial compliance, or emerging obligations, and drive structured remediation plans through to verified closure.Oversee the execution of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new products, services, technology deployments, and data processing changes from compliance perspective.Lead the compliance dimension of data breach response — including regulatory notification obligations, Data Protection Board filings, record-keeping requirements, and post-breach compliance remediation — in coordination with IT, Cyber Security, Legal, and business teams.Draft, review, and maintain the repository of data protection policies, standard operating procedures, consent templates, privacy notices, and data processing agreements, ensuring they remain current with evolving regulatory requirements.Oversee third-party and vendor privacy compliance through an ongoing compliance monitoring program for external data processors and sub-processors.Support with preparation of compliance dashboards, audit findings, and regulatory readiness reports to senior management and governance committees, as needed.CompetenciesExpert-level knowledge of the Indian and global data privacy regulatory landscape — specifically the IT Act 2000, DPDPA 2023, DPDP Rules 2025, and GDPR — with the ability to translate legislative text into operational compliance requirements and control frameworks.Proven track record in managing end-to-end compliance lifecycles, including regulatory readiness assessments, gap remediation, audit coordination, and sustained compliance monitoring at enterprise scale.Hands-on experience with privacy and compliance management platforms (e.g., OneTrust, TrustArc, BigID, or equivalent), particularly in configuring consent management, DSAR workflows, and compliance evidence repositories.Strong familiarity with audit and assurance methodologies, including ISO 27701, ISO 27001, and regulatory inspection protocols — with experience in preparing for and supporting internal and external audits.Demonstrated ability to build and maintain compliance documentation ecosystems — policies, RoPAs, privacy notices, DPIAs, and contractual templates — in a structured, version- controlled, and audit-ready manner.Excellent stakeholder management and coordination skills, with experience working across Legal, IT, HR, Marketing, and business unit teams to operationalize compliance requirementsBackground in legal, audit, internal controls, or enterprise risk management is a distinct advantage.Ability to operate effectively under pressure, exercise sound judgment on sensitive matters, and handle confidential information with the highest degree of integrity.Excellent verbal and written communication skills.Key Attributes (Experience and Qualifications)BE/B.Tech/ME/M.Tech/MCA/MS from a reputed/recognized institute9+ years of progressive experience in data privacy, regulatory compliance, or information governance, with demonstrable depth in building and operating privacy compliance programs across complex, multi-sector organizations.Professional certifications preferred: CIPP/A, CIPP/E, CIPM, CDPSE, ISO 27701 Lead Auditor/Implementer, or equivalent privacy/compliance credentials.Should have experience of handling a large team.Personal drive and positive work ethic to deliver results within tight deadlines and demanding situationsOwnership mind-set and should demonstrate persistence in following up on tasks to be performed by other stakeholders so that project timelines can be met