Data Privacy Officer
SBI General Insurance · Mumbai, Maharashtra, India - Navi Mumbai, Maharashtra, India - Thāne, Maharashtra, India
SBI General Insurance · Mumbai, Maharashtra, India - Navi Mumbai, Maharashtra, India - Thāne, Maharashtra, India
**Role Profile: Data Privacy Coordinator / Manager** **Broad objective of the role** The incumbent will be responsible for co-ordinating and performing privacy operations within the ambit of the Digital Personal Data Privacy Act (DPDP) and other relevant privacy laws. Provide updates to the DPO based on changes to existing processes or introduction of new process as well as related or peripheral activities or processes. Update privacy aspects in business SOPs based on changes in privacy obligations. Work closely with the internal data owners/users and vendors in optimizing the data environment for compliance. - Stay up to date with relevant data protection laws, regulations, and industry best practices. - Assist in interpreting data privacy regulations and assess their impact on the organization. - Collaborate with legal, compliance, and risk management teams to ensure data privacy compliance across all business processes. - Assist in developing and implementing data privacy policies, procedures, and guidelines in alignment with applicable laws and regulations. - Contribute to the development and execution of data privacy training programs for employees and stakeholders. - Coordinating with Head of Department, Data Governance Committee, Data Governance champions and Data Stakeholders - Implementation of data privacy acts/ regulatory compliance with respect to Indian Personal data protection authority (to be established). - Conduct Data Privacy Impact Assessments for new and existing projects, systems, and processes. - Collaborate with project teams to identify and mitigate potential privacy risks in data processing activities. - Coordinating with Information Security & other departments for effective movement of information/data throughout the life cycle - Network with various teams for control testing and support the implementation of Data Privacy, Information Security, and coordinate for review & Assessment activities. - Support the development and maintenance of an incident response plan for handling data privacy breaches and incidents. - Assist in investigating and documenting data privacy incidents, ensuring timely reporting to relevant authorities when required. - Co-ordinate annual vendor assessment process - Evaluate and assess the data privacy practices of third-party vendors and service providers. - Work with the Procurement team to ensure data privacy clauses are included in vendor contracts. - Analyse vendor related security breaches and follow-up for closure of the gaps leading to such breaches - Analysis of reported incidents and implementation of controls - Review, establish SOW/Contract/ NDA w.r.t. Confidentiality, Data privacy and Audit clause. Finalize and upload in Centralized SharePoint/ tool and track for its renewal with vendor - Ensure legal agreements with vendors/third parties contain applicable clauses to ensure privacy and assign accountability. - Coordinate for annual vendor assessment process - Coordination w.r.t. implementation of BCP (Business Continuity Planning) - Handle data subject access requests (DSARs) and other data privacy-related inquiries from individuals. - Coordinate with internal teams to respond to DSARs within the required timelines. - Monitor, review and standardize of internal and external data sharing Requirements (process improvement, customer grievances, complaint & escalation, data integrity) which ideally promote continuous service improvement at all levels - Periodic Risk Assessment and update the Management about any issues or gaps. - Analysis of incidence reported through risk registers and follow up and control plans - Coordinating with HODs, Data Governance Committee, data governance champions & data Stakeholders - Creation of Centralized data, coordinate for review with Business/ Data/ Information Owners - Point of contact for data related requests and external sources including Regulators/Government/Statutory Authorities/Data Protection Authority from government - Promote a culture of privacy awareness, training and compliance: - throughout the organization. - with data related vendors and maintain training records. - Act as a point of contact for privacy-related inquiries and provide guidance to employees on data protection matters. - Awareness Training, workshops, Seminars on Data Privacy, Cyber Security and related guidelines - Interacting with industries and associations on data protection / security / privacy matters - Facilitate Audits, liaise with audit teams and ensure the closure of assessment points/ gaps within given timeframe. - Analyze, review and report monthly service performance Report to verify SLA adherence which is subjected to penalty. **Education Qualifications** - Graduate / Post Graduate with minimum of 8-10 years of experience - Attending Seminars, Sessions and Industry Workshops related to Data Privacy, Security and Risk management - Lead Auditor ISO-27001; 27701(Privacy Information management Systems) would be added advantage **Core experience** - Data Privacy, Risk Management, Security, Process Improvement and Internal/ External Audits **Preferable Knowledge/Experience** - CISA Certification, ITIL Framework, DC-DPO/GDPR/DC-PLA certification; DISA would be an added advantage Kindly share resume at rashmika.manjrekar@sbigeneral.in/ Sanjana.borkar@sbigeneral.in