Job Summary
The Data Risk Advisor (DRA) is responsible for monitoring compliance with the Digital Personal Data Protection (DPDP) Act, 2023, and other applicable data protection laws. The DRA will serve as the primary point of contact for the Data Protection Board of India (DPBI) and data principals (individuals whose data is being processed) regarding all data privacy matters. This role requires a strategic leader who can implement and oversee an effective data privacy governance framework while balancing compliance with business objectives.
Key Responsibilities
Strategy
- Proactively develop regulatory relationships with regulators in Country through a structured engagement programme with consistent adherence to regulatory expectations.
- Ensure that Standard Chartered Bank's operations in the country are in line with regulatory expectations and Group requirements.
- Set and implement the vision, strategy, direction and leadership, consistent with the vision and strategy for CFCR and in support of the Group's strategic direction and growth aspirations.
- Promote the culture and practice of compliance with compliance standards (including conducting business within regulatory requirements, and to high ethical standards) within the Bank and embed a Here for good culture and the Group Code of Conduct.
Business
- Support relevant stakeholders to make decisions based on current and possible future policies, practices, and trends.
- Analyse the impact of regulatory compliance matters on the bank and its operations in conjunction with the relevant stakeholders.
- Use general knowledge of business products undertaken in the jurisdiction to work with business compliance specialists to respond to regulatory questions and keep the in-Country regulators updated on developments in the Bank.
Processes
Data Principal rights and grievance redressal
- Act as the nodal officer for addressing grievances and requests from Data Principals.
- Ensure the organization has procedures in place to honor data principal rights, such as the right to access, correct, and erase personal data.
- Supervise processes for responding to Data Principal requests within the statutory timelines.
- Ensure effective and transparent grievance redressal mechanisms are in place and followed.
Data protection impact assessments (DPIA)
- Supervise and advise on Data Protection Impact Assessments for any new processing activities that pose a high risk to data principals.
- Advise on appropriate risk mitigation strategies for new and existing projects.
- Ensure that data protection principles are integrated into the design and development of new products, systems, and services.
Regulatory liaison and reporting
- Act as the single point of contact for the Data Protection Board of India.
- Collaborate with authorities: Collaborate with the Data Protection Board during any audits, investigations, or inquiries.
- Oversee the development and implementation of an incident management and breach response protocol.
- Ensure timely notification of breaches to the Data Protection Board and affected Data Principals.
- Oversee the investigation and remediation of data security incidents.
Advisory and Training
- Inform and advise the organization and its employees on data protection obligations under the DPDP Act.
- Create and deliver targeted training and awareness programs to foster a company-wide culture of privacy and data protection.
- Integrate the principles of Privacy by Design into the development of new products, services and systems.
- Provide advisory to stakeholders in country and Group on the requirement and the obligations under the DPDP Act.
Policy Development and Management
- Develop, implement and maintain internal data protection policies, guidelines, and procedures.
- Ensure all vendor and third-party contracts include appropriate data protection clauses.
Risk Management
- Supervise and advise on Data Protection Impact Assessments for any new processing activities that pose a high risk to data principals.
- Advise on appropriate risk mitigation strategies for new and existing projects.
- Ensure that data protection principles are integrated into the design and development of new products, systems, and services.
Governance
- Regularly monitor and enforce compliance with the DPDP Act and other applicable data protection laws.
- Develop, implement, and maintain a robust data privacy governance framework and internal policies to ensure compliance.