Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
SMBC Group is seeking a Data Protection Officer in India to lead privacy governance, establish and enhance the data protection framework, and ensure compliance with DPDP, RBI guidelines, and global privacy practices. You will advise senior management and coordinate with Legal, Risk, IT, Compliance, and Operations to embed privacy-by-design and manage DPIA/PIA processes.
The role includes managing data subject requests, privacy incidents, and reporting privacy metrics to executive forums, with a
The Data Protection Officer will serve as the central privacy leader responsible for establishing, implementing, governing, and continuously enhancing the Bank’s data protection and privacy framework. The role is accountable for supporting compliance with applicable data protection requirements, including the Digital Personal Data Protection Act, 2023, DPDP Rules, relevant RBI expectations / guidelines, and appropriate global privacy best practices.
The DPO will advise senior management and coordinate with Business, Technology, Information Security, Data Governance, Compliance, Legal, Risk, Operations and other relevant teams to embed privacy governance, privacy-by-design, risk assessment, incident response, grievance redressal and management reporting across the Bank.
The role is also responsible for promoting effective data governance, data management, data preparation and responsible data analysis and utilization practices to support regulatory compliance, risk management and business decision-making, including policies guided by applicable regulations in the offices supervised by SMBC India.
Knowledge Requirements: Strong understanding of privacy laws and data governance frameworks, including DPDP Act / Rules, RBI expectations, privacy governance, data governance management, privacy risk management, DPIA / PIA, data subject rights, grievance redressal, privacy incident management and third-party data protection obligations.
Specialist / technical skills: Ability to design and implement privacy, data governance and data management frameworks, policies, controls and monitoring mechanisms; familiarity with data flow mapping, data inventory, data preparation, data quality, data analysis / utilization governance, consent management, data masking, anonymisation, security protocols, IT infrastructure and privacy management tools.
Behavioural / management skills: Executive stakeholder management, regulatory interpretation, enterprise governance, strategic leadership, programme management, risk management, communication, cross-functional collaboration and ability to develop privacy and data governance capabilities.
Relevant Experience: At least 15+ years of experience across data privacy & protection, information security and risk. Prior experience in implementing EU GDPR and / or leading and managing organisation-wide data privacy, data protection or data governance programme(s), such as DPDP. Experience in cross-functional stake-holder management including but not limited to IT/IS, operations, governance, risk & compliance.