Bachelor’s or Master’s degree in Law, Information Security, Computer Science, or related field. 2. 10–12+ years of experience in Privacy, Data Protection, Compliance, or consulting roles, with hands-on implementation experience (not just advisory). Must have progressed from individual contributor to a role involving team leadership, methodology development, or practice building. 3. Practitioner-level expertise in DPDP Act 2023 and Rules — must be able to advise Data Fiduciaries on their obligations: consent requirements, Data Principal rights, cross-border transfer rules, Significant Data Fiduciary obligations, and notice requirements including Schedule 8 language provisions. Working knowledge of GDPR and CCPA for international client context. 4. Demonstrated ability to independently prepare application-level privacy assessment deliverables: Data Flow Diagrams, processing activity registers, DPIA reports, notice requirements, and technical safeguard mapping. Must be comfortable producing structured implementation-ready documents, not just advisory presentations. 5. Working understanding of application architectures, APIs, databases, and data flows — sufficient to conduct technical gap assessments alongside engineering teams, identify consent collection points in application workflows, and map data flows from source to downstream systems 6. Understanding of privacy-enhancing technologies (PETs) at a conceptual level: encryption, masking, anonymisation, synthetic data, tokenisation. Must be able to recommend which safeguard applies to which data category without needing engineering guidance for every decision. 7. Ability to navigate sector-specific regulatory landscapes that intersect with DPDP — banking (RBI guidelines, PMLA/KYC, PCI-DSS, Account Aggregator), telecom (TRAI regulations, lawful interception), healthcare (health data protection rules), insurance (IRDAI), capital markets (SEBI), digital media (IT Act intermediary guidelines, ad-tech/cookie regulations). Must demonstrate the ability to quickly assess how a sector’s existing regulatory obligations interact with DPDP consent, notice, and data principal rights requirements. Deep expertise in at least one regulated sector; working familiarity across two or more. 8. Experience conducting DPIAs and privacy impact assessments in at least one of: banking/financial services, digital media/publishing, telecom, healthcare, or government sectors. 9. Proven ability to work in two modes: collaboratively with a customer’s privacy consultant partner (as a peer, not a subordinate), and independently where the customer has no privacy partner. 10. Excellent consulting, stakeholder management, and communication skills — ability to present to DPOs, CISOs, and board-level audiences as well as work daily with application teams and engineers. 11. Willingness to be hands-on and embedded in early client engagements (6–8 months per engagement) while contributing to broader practice development. 12. Experience hiring, mentoring, or leading a team of 2–5 privacy/compliance professionals — or demonstrated readiness to build a team from scratch (e.g., built a practice area, created a methodology, trained junior consultants at a previous employer). 13. Experience of working on other Privacy compliance tools. 14. Professional certifications such as DCPLA/ DCDPO/ Any other DPO Certification with CIPP/E, CIPM, CIPT, or ISO 27701 and PCDPO are highly preferred. Alternatively, demonstrated DPDP/ GDPR implementation experience at 2+ organisations as equivalent evidence