Ace Recruitment & Placement Consultants Pvt. Ltd.
Website:
aceconsultants.in
Job details:
1. Privacy Governance:
- Evaluate the existing data protection framework to identify areas of no or partial compliance and rectify any issues.
- Translate privacy requirements and risk findings into actionable, prioritised guidance for technical and non-technical stakeholders.
- Periodic reporting on risks, compliance, and related activities with regards to personal data processing within the AMC.
- Design, develop and document policies and procedures and ensure the policies and procedures are in-line with the applicable laws including DPDPA, SEBI & AMFI guidelines.
- Provide advice on processing personal data (investors, distributors, employees) in a lawful and legally compliant manner.
- Review, negotiate and advise on vendor data processing agreements, (DPAs), privacy clauses and data transfer mechanisms.
- Conduct audits based on DPDPA requirements and present the audit report to Senior Management and the Board
- Develop and present privacy metrics, audit status and report to Senior Management and governance Boards.
2. Privacy Operations
- Responsible for ensuring that detailed Records of Processing Activities (RoPA) across all processes are updated and reflect the latest changes (if any) in the said process flow.
- Responsible for establishing a process to define consent management framework for the Company, through which a centralized tracking of consent lifecycle (collection, storage, modification, and revocation) is maintained in an auditable manner.
- Responsible for managing tools and technologies to implement privacy framework for adequately managing the privacy requirements (e.g. data discovery, consent management, RoPA, etc.)
- Responsible for reporting data breaches and thefts to notify the Data Principal and Data Protection Board about the breach as per defined timelines.
3. Privacy Risk Management
- Maintain the privacy incident register, manage privacy related risks, incident response timelines, and ensure regulatory reporting deadlines are met.
- Establish and implement Privacy by Design process which shall include assessments to identify privacy risks at the design level of the application/process development.
- Coordinate with Information Security and Information Technology Teams to ensure that security & technology safeguards and controls are implemented as per the DPDPA requirements.
- Conduct Data Protection Impact Assessment (DPIA) and other privacy risk assessments for new and changed processing activities and transfers in the Company and ensure closure of the identified gaps.
- Advise/consult and undertake assessments to determine the effectiveness of privacy controls implemented with third party service providers/partners/vendors (including RTAs, distributors, Fintech partners, Account Aggregators, etc.) who access /store /process Company’s investors’ personal data.
- Provide advice on and assist Management in the event of any data breaches which arise, including liaising with the Data Protection Board, on behalf of the Organization.
4. Training & Awareness
- Devise training & awareness plans and provide data protection advice to stakeholders.
- Promote a culture of data protection and compliance across all functions of the org.
- Create and increase awareness amongst employees, distributors (IFAs), vendors and other applicable stakeholders processing personal information.
- Keep abreast of the status and direction of privacy issues within the asset management industry in general.
Professional skills/ experience:
- Graduate / Post Graduate / LLB or equivalent law degree, providing a strong foundation in legal interpretation and regulatory engagement.
- 12-15 years of experience in areas of data protection laws and practices, including deep understanding of DPDPA, GDPR, etc.
- Experience in a legal, audit, or risk management role.
- .Strong understanding of data protection laws and privacy program management
- .Shall have strong experience in related disciplines such as information governance, incident response, risk management, etc.
- Proven experience in reviewing and negotiating vendor DPAs and advising on practical contractual privacy requirements.
- Shall have knowledge of company’s business sector (asset management), data processing needs, information technologies and data security.
- Excellent organization, communication (oral and written) skills, including the ability to present to business, legal, and technology partners; Strong project management skills.
- Proactive engagement on privacy and data protection issues, and experience in identifying and escalating legal risks and concerns.
- Ability to work effectively under pressure and to manage sensitive and confidential information.
Click on Apply to know more.