Presidency University, Bangalore
Website:
presidencyuniversity.in
Job details:
Dear All ,
We are looking for Data Protection Officer To establish, operate and continuously improve Presidency University's personal-data governance programme; advise the University on DPDP compliance; coordinate implementation across academic and administrative functions; oversee data-principal request and grievance processes; support incident response;
and provide independent escalation of material privacy risks to senior governance.
2. Key Responsibilities
• Governance and compliance programme: Maintain the University's DPDP compliance framework,
implementation roadmap, policies, registers, controls and evidence of compliance.
• Data inventory and mapping: Coordinate an institution-wide inventory of personal data, purposes, systems, data sources, recipients, processors, retention periods, locations and cross-border flows.
• Purpose and lawful processing review: Review whether collection and processing are linked to clear lawful purposes and whether consent or another legally permitted ground is appropriately documented.
• Privacy notices and consent: Standardise notices and consent language for admissions, enrolment, student services, examinations, placements, alumni, HR, websites/apps, events, CCTV and other relevant processing.
• Children's data: Identify processing involving children and coordinate legally required consent,
safeguards and restrictions, including controls concerning tracking, behavioural monitoring and targeted advertising where applicable.
• Data-principal rights: Establish and supervise workflows for access, correction, completion, updating, erasure, grievance redressal and nomination requests as applicable.
• Grievance management: Act as or supervise the published privacy/grievance point of contact; ensure requests are logged, assigned, investigated, responded to and escalated.
• Security safeguards: Work with IT/CISO functions to ensure reasonable security safeguards, access controls, logging, backup, vulnerability management, encryption and vendor controls appropriate to personal-data risk.
• Personal data breaches: Coordinate privacy aspects of breach triage, containment, evidence
preservation, impact assessment, communications and legally required notifications.
Presidency University | DPDP Governance Framework
• Vendor / processor governance: Review personal-data clauses in contracts; maintain
processor/vendor records; ensure processing on behalf of the University is governed by valid contracts and appropriate controls.
• Retention and deletion: Develop and monitor retention schedules and defensible
deletion/anonymisation processes, subject to statutory, academic, research, accreditation, employment and litigation requirements.
• DPIA / risk assessments: Establish DPIA and privacy-risk assessment procedures for high-risk or
material new processing, and perform/coordinate periodic DPIAs if the University becomes an SDF.
• Audit and assurance: Coordinate internal compliance reviews, remediation tracking and independent data audits where required; maintain auditable evidence.
• Privacy by design: Review new applications, digital platforms, AI tools, analytics, biometric systems,
research projects and major system changes before deployment where they materially process personal data.
• Training and awareness: Conduct role-based awareness for faculty, admissions, HR, finance,
examinations, IT, research, placements, security and student-facing teams.
• Regulatory interface: Coordinate responses to lawful regulatory requests and, if the University is an SDF, represent it under the DPDP Act as required.
• Committee secretariat: Serve as Member-Secretary / privacy secretariat for the Data Protection
Committee, prepare agendas, risk reports, action trackers and compliance dashboards.
3. Authority of the DPDP Officer
• Direct access to senior governance for material privacy and compliance risks.
• Access, on a need-to-know basis, to records, systems, contracts, process owners and information
necessary to perform the role.
• Authority to require business/process owners to complete data inventories, risk assessments and
remediation actions.
• Authority to recommend temporary suspension or restriction of a processing activity where an
imminent and material privacy or security risk exists, subject to emergency governance procedures.
• Authority to convene an urgent Data Protection Committee meeting following a material breach or high-risk event.
• Independence to record dissent or unresolved compliance risk in Committee minutes and escalate it to the competent governing authority.
4. Candidate Profile
The candidate should preferably possess:
• A Bachelor’s degree from a recognised university in Law, Information Technology, Computer
Science, Cybersecurity, Information Systems, Management, Public Administration, or a related
discipline; and
• Preferably, a postgraduate degree or professional qualification in Law, Data Protection, Privacy,
Cybersecurity, Information Security, Compliance, Risk Management, Technology Law, or a related
field.
For candidates with a predominantly technology or cybersecurity background, demonstrable experience in privacy governance, regulatory compliance and stakeholder management should be considered important.
Professional Certifications – Desirable
One or more recognised certifications in privacy, data protection, cybersecurity, information security, governance or compliance would be advantageous, including certifications relating to:
• Data Protection and Privacy;
• Information Privacy Management;
• Privacy Programme Management;
• Information Security;
• Cybersecurity;
• Information Security Management Systems;
• Risk Management;
• Governance, Risk and Compliance; or
• ISO/IEC 27001 and/or ISO/IEC 27701.
Relevant certifications from recognised professional bodies such as IAPP, ISACA, (ISC)², ISO-accredited training/certification organisations, or equivalent institutions may be considered favourably.
Professional certification should, however, ordinarily be treated as desirable rather than an absolute substitute for appropriate practical experience and understanding of Indian data protection law
Interested candidates Please share Resumes to Careers2026@presidencyuniversity.in
Click on Apply to know more.