Opportunity brief
NPCI is hiring for the role of Associate Data Protection & Privacy!
Responsibilities of the Candidate:
- Ensure compliance with ISO 27701:2019, DPDPA, GDPR, and other applicable data privacy laws and regulations. - Develop, implement, and maintain data privacy policies, procedures, and controls. - Conduct regular privacy audits and assessments to identify non-compliance and recommend corrective actions. - Implement and manage encryption and data masking techniques to protect sensitive information. - Conduct technical privacy risk assessments to identify and address potential vulnerabilities. - Prepare Business Requirement Documents (BRDs) for the development and enhancement of privacy tools and technologies. - Collaborate with IT and development teams to integrate privacy-by-design principles into systems and applications. - Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new projects and initiatives. - Govern privacy settings and controls across cloud environments and third-party applications. - Develop and maintain data inventories and data flow diagrams to map the movement and processing of personal data. - Apply anonymization and pseudonymization techniques to protect personal data while maintaining data utility. - Ensure secure data transfer protocols are implemented for data sharing and processing activities. - Identify, assess, and evaluate data privacy risks and recommend appropriate mitigation measures. - Monitor data processing activities to ensure compliance with applicable data protection requirements. - Manage and respond to Data Subject Requests (DSRs) and other privacy rights requests under GDPR and DPDPA. - Ensure timely, accurate, and compliant responses to data subject requests. - Develop and deliver data privacy training and awareness programs across the organization. - Provide guidance to employees on data privacy requirements, controls, and best practices. - Support the investigation and management of data breaches and privacy incidents. - Prepare privacy incident reports and implement corrective and preventive measures to reduce the risk of recurrence. - Maintain and manage the organization-wide Personally Identifiable Information (PII) inventory across products. - Conduct periodic database and endpoint scanning to identify PII and sensitive data. - Analyze identified PII and sensitive data and take appropriate actions in accordance with defined procedures. - Maintain comprehensive records of data processing activities. - Prepare documentation, reports, and evidence required for internal and external privacy audits. - Collaborate with cross-functional teams to integrate data privacy requirements into business processes and technology solutions. - Work closely with team members and stakeholders to ensure privacy initiatives align with organizational goals and objectives.
Requirements:
- Excellent knowledge of data protection principles, regulations, and best practices. - Strong analytical and problem-solving skills. - Effective written, verbal, and interpersonal communication skills. - Ability to work independently as well as collaboratively within a team. - Proficiency in data privacy management tools and software.