Serve as the subject matter expert and primary point of contact for Data Privacy matters, with a focus on compliance with the India Digital Personal Data Protection Act, 2023 (DPDPA) and other Data Privacy compliance requirements as requested by clients, our vendors and PwC internal processes and systems. Ensure effective coordination with relevant stakeholders and timely reporting of the status to the Data Protection Officer (DPO), Risk Quality and business teams
As a Data Privacy Senior Associate, you would be responsible for,
- Support business for timely review of client contracts, conduct privacy gap assessments, Data Protection Risk Assessment (DPRAs), Data Protection Impact Assessments (DPIAs), and conduct internal audits across various sectors to identify gaps and build actionable remediation roadmaps.
- Support in Design and improve robust data privacy risk management programs, identifying risks, working with the business to devise mitigation strategies, and monitoring their effectiveness.
- Schedule and conduct data privacy and protection awareness programs for new and existing staff.
- Support incident response planning, breach notification processes, and handle/ensure timely responses to Data Principal rights requests (eg, access, correction, erasure).
- Maintain the personal data registers as required by legislation, eg the type of personal data that we hold, who processes it and who we share it with.
- Contribute to new initiatives and processes to implement DP compliances
Education and Experience
- Typically, 56+ years of experience in data privacy, compliance, or regulatory consulting roles.
- Indepth knowledge of the Digital Personal Data Protection (DPDP) Act, 2023, and strong working knowledge of other global privacy regulations such as GDPR, CCPA, etc
- Understanding of data goverce, security controls, privacy by design principles and application architecture, with the ability to provide technical remediation recommendations.
- Certifications Professional certifications such as CIPP/E, CIPP/A, CIPM, CIPT, or ISO 27701 Lead Implementer/Auditor are highly desirable.
- Soft Skills Excellent analytical, problemsolving, stakeholder management, and communication skills, with the ability to translate legal and technical requirements into actionable business practices
- Experience in handing client contract reviews, negotiations, problem solving will be big plus Experience of creating training awareness programmes
- Experience in Service Now or any other similar applications/tools
- Experience in One Trust modules for DSR, DPIA, Consent Management, Cookie Management is desirable.
Education Level bachelors degree or equivalent in Engineering or Law
Candidate Specifications (insert the relevant personal skills here)
Essential Skills
- Conceptual skills
- Influencing skills
- Conflict resolving skills
- Service orientation
- Managing ambiguity
- Diagnostics
- Change Management
- Managing multiple and time sensitive consultations efficiently
CV sifting criteria
- 5 to 6 years of experience in Data privacy, Data Protection, Information Protection, Privacy Counsel.
- Data Privacy Certifications (preferred) CIPP/E, CIPP/A, CIPM, CIPT, or ISO 27701 Lead Implementer/Auditor