Educational Qualification: Bachelor’s or Master’s degree in Law, Information Security, Computer Science, or related field. Candidates with law degrees must demonstrate working understanding of application architectures and data flows. Candidates with technology degrees must demonstrate regulatory interpretation capability through certifications or consulting experience. About the Job: The Senior Privacy Consultant is a founding leadership role responsible for building and leading the privacy consulting practice from the ground up. This individual serves as the privacy domain expert embedded in customer engagements, bridging the gap between regulatory requirements and Privacy technology platform. The role involves two distinct operating modes: working collaboratively alongside the customer’s privacy consultant partner (where one exists) to jointly prepare privacy assessments and compliance deliverables; and working independently on engagements where the customer does not have a dedicated privacy partner, taking full ownership of assessment and compliance advisory. In both modes, the Privacy Consultant is responsible for producing structured, implementation ready deliverables. The outputs of this role directly determine what technical team configures: which applications need consent integration, where Data Flow Diagrams show personal data processing, what notice content must be displayed to Data Principals, which technical safeguards (encryption, masking, anonymisation) apply to which data flows, and whether the deployment meets DPDP Act requirements. As the leading privacy consulting hire, this individual will be both a leader and a practitioner — personally delivering assessments for early clients while simultaneously building the team, methodology, templates, and quality standards that will scale the practice. Once the team grows, this person transitions into a practice leadership role: hiring and mentoring junior privacy consultants, reviewing their deliverables, and handling complex or sensitive assessments that require senior judgment. The individual must be credible as a peer to the customer’s privacy consultant or DPO — someone who can challenge assumptions, identify gaps the customer’s own team may have missed, and connect regulatory requirements to Privacy product capabilities. Responsibilities: Assessment & Gap Analysis (Core Deliverables): 1. Conduct application-level DPDP gap assessments — review each application’s data collection, processing, storage, and sharing against DPDP Act requirements and identify compliance gaps. 2. Prepare Data Flow Diagrams (DFDs) per application showing personal data flows from upstream to downstream, including points of consent collection, processing purposes, and third-party data sharing. 3. Define notice page structure and content requirements per DPDP Act and DPDP Rules — what information must be communicated to Data Principals, in what format, including multi-language requirements. 4. Document purpose of processing per application, mapping each processing activity to its legal basis under DPDP, and validate with the customer’s DPO. 5. Prepare the Compliance Readiness Report that serves as the input for the Solution Architect to design the technical integration approach and for Integration Engineers to integrate the products. Working with Customer’s Privacy Consultant Partner: 1. Collaborate with the customer’s privacy consultant partner to jointly review and validate Application Assessment Reports — ensuring reports cover Point of Consent Collection, Consent Form and Notice elements, DFDs, and exact business purposes. 2. Validate the customer’s privacy consultant’s assessment findings against tool capabilities — identify where tool workflows align with the customer’s existing processes and where gaps or FRDs exist. 3. Challenge and supplement the customer’s assessment where gaps are found — the Privacy Consultant must be able to identify what the customer’s own consultant may have missed (incomplete DFDs, undocumented processing purposes, unidentified consent collection points). 4. Co-prepare DPIA assessments with the customer’s privacy team and DPO, using Prescription DPIA tool. Independent Assessment (Where Customer Has No Privacy Partner): 1. Take full ownership of privacy assessment and compliance advisory for the engagement — acting as the de facto privacy consultant for the customer. 2. Independently prepare all assessment deliverables: application gap assessment, DFDs, notice requirements, purpose-of-processing register, safeguard mapping, and DPDP compliance gap report. 3. Conduct DPIA assessments independently, coordinating with the customer’s DPO or compliance officer for sign-off. 4. Advise the customer on Consent Collection and Withdrawal SOP design, Data Principal Rights workflows, and breach notification requirements under DPDP. Technical Safeguard Mapping (Bridge to Products): 1. Map technical safeguards to applications — for each data flow and data category, recommend which PET tool (encryption, masking, anonymisation, synthetic data) applies and why, connecting DPDP “reasonable security safeguards” requirement to Event-Horizon capabilities. 2. Review customer’s existing Consent Collection and Withdrawal SOPs against Consentium tool capabilities — identify process-product alignment gaps and recommend workflow adjustments or FRDs. 3. Map Data Principal Rights (DPR) requirements to Consentium’s DPR workflow — access, correction, erasure, nomination and identify where customer processes need adjustment. 4. Provide regulatory context to Solution Architect and Integration Engineers — explain why specific configurations are required, not just what to configure. Sector-Specific Regulatory Navigation (Cross-Industry): 1. Navigate the intersection between DPDP Act and sector-specific regulations across client industries — every regulated sector (banking, telecom, healthcare, insurance, digital media, government) has pre-existing data handling obligations that interact with, and sometimes override, DPDP consent requirements. The Privacy Consultant must identify which processing is legally mandated under sector regulations (exempt from consent) versus discretionary (requiring DPDP consent). 2. Understand and advise on data localisation requirements across sectors (RBI for payments, proposed health data rules, government data policies) and their impact on privacy platform deployment, consent record storage, and cross-border data transfers. 3. Classify sector-specific personal data categories during application assessments — each industry has distinct data types (financial records, health records, subscriber data, employment data, behavioural data) with different sensitivity levels, retention obligations, and regulatory controls. The consultant must recognise these categories and map them to appropriate privacy safeguards. 4. Assess how existing compliance frameworks (PCI-DSS, ISO 27001, SOC 2, SEBI, IRDAI, TRAI, IT Act intermediary guidelines) interact with DPDP — where existing controls satisfy DPDP's “reasonable security safeguards” requirement and where gaps remain. 5. Advise on consent complexities unique to each sector: mandatory processing without consent (KYC/AML in banking, lawful interception in telecom, public health reporting in healthcare), multi party consent (joint accounts, family plans, group policies), consent for change of purpose (cross sell, analytics, research), and third-party data sharing classification by legal basis (legally mandated vs contractual vs discretionary). Regulatory Advisory & Stakeholder Engagement: 1. Advise clients on DPDP Act 2023 and Rules, with working knowledge of GDPR/CCPA, and emerging regulatory frameworks for international client context. 2. Provide executive-level guidance on privacy risk management, regulatory compliance, and strategic decision-making. 3. Lead regulatory readiness assessments, audit preparation, and mock audit exercises. 4. Build trusted relationships with customer DPOs, CISOs, legal teams, and privacy teams. 5. Contribute to thought leadership, practice growth, and capability development. Practice Building & Team Leadership (Founding Role): 1. Build privacy consulting practice from the ground up — define the methodology, create reusable assessment templates, establish quality standards, and document the consulting playbook that future hires will follow. 2. Hire, onboard, and mentor junior privacy consultants (3–7 years’ experience) as the practice scales — evaluate candidates, design interview assessments, and set performance expectations. 3. Review and quality-assure deliverables produced by junior consultants before they are shared with clients. No assessment report, DFD, or DPIA leaves the team without this person’s sign-off during the practice’s first few months/years. 4. Be prepared for hands-on delivery before transitioning to practice leadership as the team grows. Be prepared to personally handle complex, sensitive, or strategically important assessments — wave-by-wave application assessments, routine DFDs, standard DPIAs. 5. Establish the privacy consulting practice’s relationship with the Product and Engineering teams — ensure field learnings feed into product roadmap, and product capabilities feed into consulting methodology. 6. Define training curriculum for junior privacy consultants — what they must know about DPDP, Privacy tools, client engagement protocols, and deliverable standards before they are deployed on client engagements. Knowledge Feedback: Submit structured field feedback: DPDP compliance observations, customer unmet needs, competitive intelligence, and regulatory interpretation issues encountered in the field. Contribute to Knowledge Base — document reusable assessment templates, industry-specific compliance patterns, and regulatory interpretation guidance from client engagements. Requirements: 1. Bachelor’s or Master’s degree in Law, Information Security, Computer Science, or related field. 2. 10–12+ years of experience in Privacy, Data Protection, Compliance, or consulting roles, with hands-on implementation experience (not just advisory). Must have progressed from individual contributor to a role involving team leadership, methodology development, or practice building. 3. Practitioner-level expertise in DPDP Act 2023 and Rules — must be able to advise Data Fiduciaries on their obligations: consent requirements, Data Principal rights, cross-border transfer rules, Significant Data Fiduciary obligations, and notice requirements including Schedule 8 language provisions. Working knowledge of GDPR and CCPA for international client context. 4. Demonstrated ability to independently prepare application-level privacy assessment deliverables: Data Flow Diagrams, processing activity registers, DPIA reports, notice requirements, and technical safeguard mapping. Must be comfortable producing structured implementation-ready documents, not just advisory presentations. 5. Working understanding of application architectures, APIs, databases, and data flows — sufficient to conduct technical gap assessments alongside engineering teams, identify consent collection points in application workflows, and map data flows from source to downstream systems 6. Understanding of privacy-enhancing technologies (PETs) at a conceptual level: encryption, masking, anonymisation, synthetic data, tokenisation. Must be able to recommend which safeguard applies to which data category without needing engineering guidance for every decision. 7. Ability to navigate sector-specific regulatory landscapes that intersect with DPDP — banking (RBI guidelines, PMLA/KYC, PCI-DSS, Account Aggregator), telecom (TRAI regulations, lawful interception), healthcare (health data protection rules), insurance (IRDAI), capital markets (SEBI), digital media (IT Act intermediary guidelines, ad-tech/cookie regulations). Must demonstrate the ability to quickly assess how a sector’s existing regulatory obligations interact with DPDP consent, notice, and data principal rights requirements. Deep expertise in at least one regulated sector; working familiarity across two or more. 8. Experience conducting DPIAs and privacy impact assessments in at least one of: banking/financial services, digital media/publishing, telecom, healthcare, or government sectors. 9. Proven ability to work in two modes: collaboratively with a customer’s privacy consultant partner (as a peer, not a subordinate), and independently where the customer has no privacy partner. 10. Excellent consulting, stakeholder management, and communication skills — ability to present to DPOs, CISOs, and board-level audiences as well as work daily with application teams and engineers. 11. Willingness to be hands-on and embedded in early client engagements (6–8 months per engagement) while contributing to broader practice development. 12. Experience hiring, mentoring, or leading a team of 2–5 privacy/compliance professionals — or demonstrated readiness to build a team from scratch (e.g., built a practice area, created a methodology, trained junior consultants at a previous employer). 13. Experience of working on other Privacy compliance tools. 14. Professional certifications such as DCPLA/ DCDPO/ Any other DPO Certification with CIPP/E, CIPM, CIPT, or ISO 27701 and PCDPO are highly preferred. Alternatively, demonstrated DPDP/GDPR implementation experience at 2+ organisations as equivalent evidence