Data Protection Officer

GAIN

Mumbai

On-site

INR 1,400,000 - 2,400,000

Full time

44 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equal opportunities employer

Job summary

GAIN is seeking a Data Protection Officer to own and advance our privacy compliance framework across multiple regions. You will partner with IT, Operations, Engineering, HR, Procurement and business units to embed privacy controls and enable compliant growth.

You will manage DPIAs, LIAs, DPAs and cross-border transfer provisions, while advising on lawful bases and data subject rights. A senior role requiring 5+ years of experience and professional certifications is preferred.

Qualifications

  • 5+ years in data protection, privacy compliance or information governance with hands-on privacy activity.
  • Proven experience reviewing and negotiating client and supplier DPAs.
  • Strong experience producing DPIAs, maintaining ROPAs and supporting data subject rights.
  • Working knowledge of UK GDPR, EU GDPR and international privacy requirements across multiple regions.
  • Professional privacy certifications (CIPP/E, CIPM, EU GDPR Practitioner) desirable.
  • Ability to translate privacy risk into business impact and influence stakeholders.

Responsibilities

  • Own and maintain the data protection governance framework (policies, standards, procedures).
  • Maintain ROPA, document data flows, systems, suppliers and transfers.
  • Lead DPIAs, LIAs, EU SCCs and other privacy risk assessments.
  • Review, negotiate and advise on DPAs and privacy clauses.
  • Monitor compliance across UK, EU, India, Philippines, US and Canada; drive remediation.
  • Provide guidance on lawful bases, data subject rights, retention, minimisation and privacy by design.
  • Support data breach management, triage, risk assessment and client communications.
  • Work with procurement to assess third-party privacy risk and due diligence.
  • Develop privacy training and respond to client privacy questionnaires.
  • Define privacy KPIs and report to senior leadership.

Skills

Data protection
Privacy compliance
Information governance
DPIA
LIAs
DPAs
GDPR
Stakeholder influence

Education

CIPP/E
CIPM
EU GDPR Practitioner

Job description

To own, maintain and improve our data protection and privacy compliance framework, ensuring lawful, fair and transparent processing of personal data across our processing sites in the UK, EU, India, Philippines, US and Canada.

Main Responsibilities:

The Data Protection Officer is responsible for proactively managing and improving our data protection compliance framework, driving privacy accountability and lawful processing across the organisation, partnering with IT, Operations, Engineering, HR, Procurement and business stakeholders to embed practical data protection controls and support compliant growth.

  • Own and maintain the data protection governance framework, including policies, standards, procedures and supporting documentation.
  • Maintain and manage the Record of Processing Activities (ROPA), ensuring processing activities, data flows, systems, suppliers and international transfers are accurately documented and kept up to date.
  • Lead and produce Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments (LIAs), EU Standard Contract Clauses (SCC) and other privacy risk assessments for new and changed processing activities and transfers.
  • Review, negotiate and advise on client and supplier data processing agreements (DPAs), privacy clauses and international data transfer provisions.
  • Monitor compliance with applicable privacy and data protection legislation across our processing sites in the UK, EU, India, Philippines, US and Canada, escalating gaps and driving remediation actions.
  • Provide practical guidance on lawful bases for processing, data subject rights, retention, minimisation, privacy by design and cross-border transfers.
  • Support the management of personal data breaches, including triage, risk assessment, notification decision-making, client communications and post-incident review.
  • Work with supplier owners and procurement teams to assess third-party privacy risk and ensure appropriate due diligence and contractual controls are in place.
  • Develop and deliver data protection training and awareness to employees and support responses to client privacy questionnaires, audits and compliance requests.
  • Define and report privacy KPIs, incidents, risks, audit findings and action plans to senior leadership, while working with IT, Operations, Engineering and wider business units to identify risks and scale good practice.
Professional skills/ experience:
  • 5+ years in data protection, privacy compliance or information governance with hands‑on responsibility for operational privacy activities.
  • Proven experience reviewing and negotiating client and supplier DPAs and advising on practical contractual privacy requirements.
  • Strong experience producing DPIAs, maintaining ROPAs and supporting data subject rights, retention and international transfer compliance.
  • Working knowledge of UK GDPR, EU GDPR and broader international privacy requirements across the UK, EU, India, Philippines, US and Canada.
  • Professional certification such as CIPP/E, CIPM, EU GDPR Practitioner or equivalent privacy qualification desirable.
  • Able to translate privacy risk into business impact and influence stakeholders at all levels.
Personal Qualities
  • Great with people, can build trust and rapport across the entire organisation.
  • Good communicator with clients and internally.
  • Team Player commitment and flexible.
  • Ability to prioritise and quickly resolve issues.

GAIN is an equal opportunities employer and positively encourages applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, sexual orientation, gender reassignment, religion or belief, marital status, or pregnancy and maternity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GAIN - Central IT - Data Protection Officer
GAIN - Central IT - Data Protection Officer

GAIN • Mumbai

On-site
INR 1,200,000 - 1,800,000
Senior Executive-Data Privacy
Senior Executive-Data Privacy

IGT Solutions • Gurugram District

On-site
INR 600,000 - 800,000
Data Protection Consultant
Data Protection Consultant

Weekday • Mumbai

On-site
INR 500,000 - 1,200,000
Data Protection Consultant
Data Protection Consultant

Weekday AI (YC W21) • Mumbai

On-site
INR 900,000 - 1,300,000
Data Protection Consultant/Assistant Manager
Data Protection Consultant/Assistant Manager

Privacypillar • Bengaluru, Mumbai

On-site
INR 900,000 - 1,200,000
Advisor - Privacy & Data Protection
Advisor - Privacy & Data Protection

Infosys • Bengaluru

On-site
INR 1,000,000 - 2,000,000
Deputy/Assistant Manager -(DATPRO)
Deputy/Assistant Manager -(DATPRO)

Maruti Suzuki India Ltd. • New Delhi

On-site
INR 1,200,000 - 1,800,000
IN_Associate 2_Data Privacy_ RC C&DR AITH_Advisory_Noida
IN_Associate 2_Data Privacy_ RC C&DR AITH_Advisory_Noida

PwC • Dadri

On-site
INR 1,200,000 - 2,400,000
Mentorship
Training programs
Flexible benefits
+1
Data Protection Officer
Data Protection Officer

Prodapt Solutions • Bengaluru, Chennai District

Hybrid
INR 1,500,000 - 2,500,000
Data Privacy Professional
Data Privacy Professional

r3 Consultant • Gurugram District

On-site
INR 1,200,000 - 1,800,000