Manager - Data Privacy

Mumbai, Maharashtra8-12 yrsPermanentOn-siteINR 28 - 30 LPA

Hiring for: One of India’s leading non-banking financial companies (NBFCs), focused on driving financial inclusion across rural and semi-urban markets.

Role: Manager - Data Privacy

Experience: 8 to 12 years

Location(s): Kurla, Mumbai

Salary: Up to INR 30 LPA (Including 10% variable)


Job Descriiption


Role Purpose

The Data Privacy Manager will support the Data Protection Officer (DPO) in the day-to-day execution and coordination of data privacy activities across the organisation. The role will assist with operational privacy activities, coordination with business units, maintenance of privacy records, assessments and tracking of agreed privacy actions. The role is intended to provide additional bandwidth to the DPO and does not replace or independently perform the DPO accountability.


Key Responsibilities


DPO Office – Day-to-Day Support

• Assist the DPO in day-to-day operational activities of the Data Privacy Office.

• Coordinate with business units and relevant stakeholders for execution and closure of privacy-related activities.

• Maintain privacy-related trackers, records, documentation and status reports as directed by the DPO.

• Support follow-up and tracking of privacy actions, observations and agreed remediation items.


Review of Data Extraction Requests

• Review and coordinate data extraction requests received from business units from a data privacy perspective.

• Validate the purpose, data elements and business requirement of requested data in accordance with defined privacy requirements.

• Coordinate with relevant stakeholders for clarification, supporting information and closure of data extraction requests.

• Escalate exceptions or privacy concerns to the DPO for appropriate decision.


Privacy Rollout Across Business Verticals

• Assist the DPO in rolling out privacy requirements across all business verticals and their relevant sub-processes.

• Coordinate with process owners to understand privacy requirements and implementation status.

• Track implementation activities and highlight gaps or pending actions to the DPO.


Customer Privacy Tickets

• Coordinate and support processing of customer privacy-related tickets and requests.

• Work with relevant business and support teams to obtain information required for resolution.

• Maintain appropriate records and status of privacy tickets and escalate matters requiring DPO intervention.


RoPA – Records of Processing Activities

• Assist in periodic review and updating of RoPA (Records of Processing Activities).

• Coordinate with business/process owners to validate changes in processing activities and associated information.

• Track pending updates and maintain supporting documentation for RoPA reviews.


DPIA – Data Protection Impact Analysis

• Assist the DPO in conducting DPIA for applicable business flows.

• Coordinate with business and technology stakeholders to collect required information for DPIA.

• Document identified privacy risks, observations and agreed actions and track them to closure.

• Escalate significant privacy risks or unresolved matters to the DPO.


DSPM & PII Identification

• Support DSPM (Data Security Posture Management) activities for identification of PII.

• Assist with identification and review of PII in structured databases.

• Assist with identification and review of PII in unstructured data storage.

• Coordinate with relevant technology/data owners on findings and required follow-up actions.

• Assist in tracking controls and activities related to masking and encryption of data.


Education & Experience

• Bachelor’s degree in Computer Science, Information Technology, Cyber Security, Law, Risk, Compliance, Business Administration or a related discipline.

• Typically 6–10 years of relevant experience in data privacy, privacy operations, information security, risk, compliance or a related field.

• Practical understanding of data privacy concepts, PII, RoPA, DPIA and data protection controls.

• Experience coordinating with business and technology stakeholders for privacy-related activities is preferred.

• Privacy/data protection certification such as CIPP, CIPM, CDPO or equivalent is an advantage.

Skills

Data PrivacyData Protection ControlsDPIAInformation SecurityInformation Security, Risk, and CompliancePersonally Identifiable Information (PII)Privacy OperationsROPA

Posted September 29, 2026