Position - Manager-Data Privacy & Grievance Officer
Department: Data Privacy / Compliance
Experience Required
- Total experience: 8–10 years
- Minimum 2–3 years of hands‑on experience in Data Privacy & Protection
- Experience in privacy governance, regulatory advisory and legal compliance preferred
Qualifications
- Bachelor’s Degree in Law (LLB) mandatory
- LLM or specialization in Cyber/Data Privacy Laws preferred
DCPP
CIPP/E
CIPM
ISO 27701
Role Summary
The Data Privacy Counsel & Grievance Officer will be responsible for managing the organization’s data privacy, act as a grievance officer and compliance framework while providing legal and regulatory support across business functions. The role includes ensuring compliance with the Digital Personal Data Protection (DPDP) Act, 2023, acting as the Grievance Officer, handling monthly compliance activities, monitoring government notifications and regulatory updates, and supporting overall legal operations of the organization.
The position will work closely with DPO, Legal, HR, IT, Information Security, Operations, Procurement, and Business Teams to strengthen privacy governance, mitigate legal risks, address the concerns of data principals, and ensure regulatory compliance.
Key Responsibilities
Data Privacy & DPDP Compliance
- Ensure implementation and continuous monitoring of the organization’s data privacy framework.
- Drive compliance with:
- Digital Personal Data Protection (DPDP) Act, 2023
- Applicable privacy and data protection regulations
- Internal privacy governance standards
- Draft, review, and update:
- Consent notices
- Data processing agreements
- Advise departments on lawful collection, processing, storage, sharing, and retention of personal data.
- Maintain records related to personal data processing and privacy compliance.
- Support privacy impact assessments and privacy-by-design initiatives.
- Coordinate with internal stakeholders for implementation of privacy controls and SOPs.
Grievance Officer Responsibilities
- Act as the designated Grievance Oicer under the DPDP Act.
- Handle and resolve grievances raised by Data Principals regarding:
- Consent withdrawal
- Access requests
- Privacy complaints
- Ensure grievances are acknowledged and resolved within prescribed timelines.
- Maintain grievance registers, audit trails, and complaint records.
- Coordinate with Legal, HR, IT, Security, and Operations teams for investigation and closure of complaints.
- Escalate high-risk privacy matters and breaches to senior management.
Monthly Compliance & Regulatory Monitoring
- Manage monthly legal and compliance tracking activities.
- Monitor and circulate:
- Government notifications
- Regulatory amendments
- Compliance updates
- Industry advisories relating to privacy and legal compliance
- Prepare periodic compliance reports and dashboards for management.
- Ensure timely filing, documentation, and closure of compliance obligations.
Legal & Contractual Support
- Legal & Contractual Support
- Provide legal support on commercial and operational matters.
- Draft, review, and negotiate various agreements.
- Support internal legal documentation and contract management processes.
- Assist in handling notices, disputes, investigations, and regulatory inquiries.
- Coordinate with external legal counsel where required.
Governance & Risk Management
- Develop and strengthen compliance frameworks, SOPs, and governance mechanisms.
- Conduct risk assessments related to privacy and legal exposure.
- Support internal audits and compliance reviews.
- Conduct employee awareness sessions and privacy trainings.
- Assist management in identifying and mitigating regulatory and operational risks.