Website:
dutient.ai
Job details:
Location: Mumbai (Onsite)
Experience: 2–4 Years
Employment Type: Full-Time
- Immediate Joiners or candidates serving a notice period of up to 15 days will be preferred.
About the Role
We are looking for a highly motivated Senior Data Privacy Consultant to join our growing Privacy Consulting practice. The ideal candidate will have hands-on experience in implementing privacy programs, conducting privacy assessments, advising clients on global privacy regulations, and driving enterprise-wide data protection initiatives.
This role offers the opportunity to work with leading organizations across BFSI, Healthcare, Retail, Manufacturing, Technology, E-commerce, and other industries, delivering strategic privacy consulting engagements while helping organizations establish mature privacy governance frameworks.
Key Responsibilities
Privacy Advisory & Regulatory Compliance
- Lead end-to-end privacy consulting engagements across multiple industry verticals.
- Advise clients on global privacy regulations including DPDPA, GDPR, CCPA/CPRA, HIPAA, UAE PDPL, Singapore PDPA, and other applicable privacy frameworks.
- Conduct privacy maturity assessments, gap assessments, compliance reviews, and privacy health checks.
- Develop practical remediation roadmaps to address regulatory and operational privacy risks.
Privacy Governance & Implementation
- Design and implement enterprise privacy governance frameworks, policies, standards, procedures, and operational controls.
- Conduct data discovery, data mapping, and data flow assessments to identify personal data processing activities.
- Prepare and maintain Records of Processing Activities (RoPA), Data Protection Impact Assessments (DPIAs), Privacy Impact Assessments (PIAs), Legitimate Interest Assessments (LIAs), and Transfer Impact Assessments (TIAs).
- Support clients in implementing Privacy by Design and Privacy by Default principles across business processes and technology platforms.
- Assist organizations in developing privacy notices, consent management frameworks, data retention policies, breach response procedures, and data subject rights processes.
Contractual & Third-Party Privacy
- Draft, review, and negotiate privacy-related contractual documents, including Data Processing Agreements (DPAs), Data Sharing Agreements (DSAs), Standard Contractual Clauses (SCCs), Non-Disclosure Agreements (NDAs), and vendor contracts.
- Conduct vendor privacy assessments and third-party risk reviews to evaluate processor compliance.
- Advise clients on cross-border data transfers and international privacy obligations.
Risk Management & Incident Response
- Identify privacy and compliance risks across business operations and recommend practical mitigation strategies.
- Support privacy incident investigations, breach assessments, regulatory notifications, and remediation planning.
- Assist clients during regulatory inspections, privacy audits, certification exercises, and compliance reviews.
Client Management
- Engage with Legal, Compliance, Information Security, Risk, HR, Product, Procurement, and Business teams to embed privacy controls across the organization.
- Conduct stakeholder workshops, executive presentations, and privacy awareness sessions.
- Support proposal preparation, RFP responses, solution design, and pre-sales activities.
- Mentor junior consultants and contribute to internal knowledge management initiatives.
Required Skills & Experience
- 2-4 years of experience in Data Privacy, Data Protection, Privacy Consulting, Information Security Compliance, or Regulatory Compliance.
- Strong working knowledge of DPDPA, GDPR, and one or more global privacy regulations.
- Hands-on experience in conducting RoPA, DPIA, PIA, TIA, LIA, data mapping, and privacy assessments.
- Experience in drafting and reviewing DPAs, SCCs, NDAs, MSAs, SOWs, and other commercial agreements.
- Strong understanding of privacy governance, consent management, data lifecycle management, and third-party risk management.
- Familiarity with ISO 27001, ISO 27701, NIST Privacy Framework, or similar security and privacy standards.
- Experience working with privacy management platforms such as OneTrust, Securiti.ai, BigID, TrustArc, or similar solutions is preferred.
- Excellent analytical, communication, stakeholder management, and presentation skills.
Preferred Certifications
Candidates with one or more of the following certifications will have an added advantage:
- CIPP/E, CIPP/A, CIPP/US
- CIPM
- CIPT
- FIP
- ISO 27701 Lead Implementer / Lead Auditor
- ISO 27001 Lead Implementer / Lead Auditor
- OneTrust Professional Certifications
- DSCI Certified Data Protection Officer (DCDPO)
Click on Apply to know more.