An application made for this job — a tailored resume and cover letter that speak straight to the posting.
This is Gain Ltd is seeking a Data Protection Officer in Mumbai to own and improve our data protection framework across multiple regions. You will drive lawful processing, partner with IT, HR and procurement, and embed practical privacy controls across processing sites in the UK, EU, India, and beyond.
The role requires 5+ years in data protection, strong DPIA and ROPA experience, and the ability to advise on cross-border transfers and contractual privacy clauses.
Job Title:
Data Protection Officer
Location:
Mumbai
Reports to:
Primary Purpose
To own,maintainand improve our data protection and privacy compliance framework, ensuring lawful,fairand transparent processing of personal data across our processing sites in the UK, EU, India, Philippines,USand Canada.
Main Responsibilities:
The Data Protection Officeris responsible forproactively managing and improving our data protection compliance framework, driving privacy accountability and lawful processing across the organisation, partnering with IT, Operations, Engineering, HR,Procurementand business stakeholders to embed practical data protection controls and support compliant growth.
Own andmaintainthe data protection governance framework, including policies, standards, procedures and supporting documentation.
Maintain and manage the Record of Processing Activities (ROPA), ensuring processing activities, data flows, systems,suppliersand international transfers are accurately documented and kept up to date.
Lead and produce Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments (LIAs), EUStandard Contract Clauses (SCC)and other privacy risk assessments for new and changed processing activitiesandtransfers.
Review, negotiate and advise on client and supplier data processing agreements (DPAs), privacyclausesand international data transfer provisions.
Monitor compliance with applicable privacy and data protection legislation across our processing sites in the UK, EU, India, Philippines, US and Canada, escalating gaps and driving remediation actions.
Providepractical guidance on lawful bases for processing, data subject rights, retention, minimisation, privacy by design and cross-border transfers.
Support the management of personal data breaches, including triage, risk assessment, notification decision-making, clientcommunicationsand post-incident review.
Work with supplier owners and procurement teams to assess third-party privacy risk and ensureappropriate duediligence and contractual controls are in place.
Develop and deliver data protection training and awareness to employees and support responses to client privacy questionnaires,auditsand compliance requests.
Define and report privacy KPIs, incidents, risks, auditfindingsand action plans to senior leadership, while working with IT, Operations,Engineeringand wider business units toidentifyrisks and scale good practice.
Professional skills/ experience:
5+ years in data protection, privacycomplianceor information governance with hands-on responsibility for operational privacy activities.
Proven experience reviewing and negotiating client and supplier DPAs and advising on practical contractual privacy requirements.
Strong experience producing DPIAs,maintainingROPAs and supporting data subject rights,retentionand international transfer compliance.
Working knowledge of UK GDPR, EU GDPR and broader international privacy requirements across the UK, EU, India, Philippines,USand Canada.
Professional certification such as CIPP/E, CIPM, EU GDPR Practitioner or equivalent privacy qualification desirable.
Able to translate privacy risk into business impact and influence stakeholders at all levels.
Personal Qualities
Problem solver.
Great with people, can build trust and rapport across the entire organisation.
Good communicator with clients and internally.
Team Player commitment and flexible.
Ability to prioritise and quickly resolve issues.
Attention to detail.