أبلاي إيدج ابدأ البحث عن عمل

Data Protection Officer

Infinity Learn · Hyderabad, Telangana, India

قدّم وتابع مع أبلاي إيدج
Role Summary:The DPO oversees the Client's compliance with the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules 2025 (hereinafter together referred to as DPDPA) acting as the primary interface with data principals and the Data Protection Board of India (hence DPBI) to ensure lawful, transparent handling of digital personal data. The role requires an India-based individual accountable to the DPBI, Information Security and Privacy Steering Committee/Board and responsible for monitoring obligations, managing grievances and advising on data protection practices.Key Responsibilities:The DPO ensures secure handling and protection of personal data by supervising data protection efforts, conducting audits, performing DPIAs, and maintaining privacy governance across the organisation. The role also acts as the single point of contact with regulators and individuals, monitoring compliance and reviewing policies to align with applicable data protection laws. Key responsibilities include the following:Ensure organisational compliance with DPDPA and data protection obligationsDevelop and update data protection policies, procedures, and frameworksHandle data principal grievances and requests including access, erasure/deletion and data correction, and retention of personal data with appropriate provisions for children and persons with disabilities.Maintain data processing registers and documentation related to consent management and privacy noticesOversee third-party processor compliance through data processing agreements, audits and reviewsLead and manage data breach detection, assessment and notification to Data Protection Board of India and data principalsProvide data protection training and awareness programsOversee and validate that technical and algorithmic processing measures are risk assessed and do not adversely impact the rights of data principals.Report quarterly to Information Security and Privacy Steering Committee/Board on compliance posture and emerging risksAdvise on international data transfers and cross-border complianceParticipate in product/service design reviews to ensure privacy-by-design principlesEnsure, oversee and conduct Data Protection Impact Assessments for high-risk processing and independent audits are conducted, reviewed and reported to Information Security and Privacy Steering Committee/Board, in case Client is designated as Significant Data Fiduciary.Statutory Requirements under DPDPA:A Data Protection Officer (DPO) given under Section 2(l) under the DPDPA must be:An individual appointed by a Significant Data Fiduciary (SDF) as defined in Section 2(z), DPDPA.A DPO must be based in India and represent the SDF for all regulatory purposes under Section 10(2), DPDPAA Significant Data Fiduciary must appoint a DPO under Section 10(2)(a) of DPDPAA DPO is directly accountable to the Board of Directors or equivalent governing body as under Section 10(2)(a)(iii) of DPDPAA DPO is designated as the primary point of contact for grievance redressal from data principals under Section 10(2)(a)(iv) of DPDPAA DPO shall ensure independent audits and monitor compliances under Rule 13(1) & 13(2) of DPDPAA DPO shall have knowledge of technical and algorithmic processing measures as per Rule 13 (4) of DPDPANote: While Client may not qualify as a Significant Data Fiduciary under the DPDPA, it is required to establish a grievance redressal mechanism. This responsibility may be discharged by a designated professional, who may also serve in the capacity of a Data Protection Officer (DPO).Qualifications:Bachelor's and Master's degree in Law, Computer Science, Engineering, Information Systems, or a related disciplineMinimum 7+ years of relevant experience in data protection, privacy, information security, or regulatory compliance rolesExpertise in the DPDPA, GDPR, and other applicable international data protection laws and standardsExperience in data breach response, incident management, and engagement with regulators or supervisory authoritiesSound technical understanding of information security concepts, including cybersecurity controls, encryption, data architecture, and enterprise systemsStrong analytical, communication, documentation, and stakeholder management skills, with the ability to operate independentlyRelevant professional certifications such as CIPP, CIPM, CDPSE, ISO/IEC 27701 (PIMS), or equivalent, preferred