Data Privacy & Security Specialist
BT Group · Haryāna, Haryana, India
Free to search · AI fit score against your CV · tailor your résumé in one click
BT Group · Haryāna, Haryana, India
Req ID: 62151 Job Function: Risk, Compliance and Assurance Posting Start Date: 01/09/2026 Posting End Date: 03/09/2026 Division: Digital Job Location: IND-Gurugram-IQ Advertised Salary: Competitive Job Req ID: 62151 Posting Date: 1-Sep-26 Function: Risk, Compliance and Assurance Location: Gurugram Salary: Competitive About the role Specific business area: • Acts as a senior privacy specialist for designated Corporate Units Digital portfolios. The role performs a substantial proportion of the operational and advisory activities undertaken by the Data Privacy and Security Architect, independently owning complex privacy matters, setting the expected quality of reviews and representing the privacy function in agreed business and governance discussions. The Architect retains ownership of privacy strategy, the overall CU Digital privacy posture, final accountability for the operating model, precedent-setting decisions and material legal or regulatory escalations. Impact of the role: • Provides authoritative, risk-based privacy advice that business and technology leaders can rely on when making decisions. The role leads complex assessments and investigations, determines required privacy outcomes within delegated authority, challenges unacceptable processing, and drives remediation to closure. It protects colleagues, strengthens audit and regulatory readiness, and enables responsible use of data, including AI and digital solutions. Link to strategy: • Directly strengthens BT’s trusted and responsible use of data by embedding privacy-by-design, influencing standards and controls, and ensuring material privacy risks are visible to the right decision-makers. The role converts themes from PIAs, investigations and assurance into improvements across Corporate Units Digital and supports innovation at pace without compromising legal, regulatory or policy requirements. What you’ll be doing • Lead and determine the outcome of complex Privacy Impact Assessments and DPIAs, including high-risk data uses, colleague monitoring, profiling, AI, analytics and cross-border processing. • Decide whether identified privacy risks can be accepted within delegated authority, require further mitigation, or must be escalated to the Data Privacy and Security Architect, Legal, Global Privacy Leads, Data Council or another accountable governance body. • Lead complex privacy investigations involving incidents, complaints, suspected misuse, inappropriate access, retention failures or control weaknesses; establish facts, assess impact, determine root cause and issue defensible findings. • Provide robust challenge to Directors, Product Owners, Delivery Leads, Architects and other senior stakeholders where proposed processing does not meet legal, policy or privacy-by-design expectations. • Represent the Data Privacy function in governance forums, design reviews, risk discussions, audit activity and programme boards, ensuring privacy considerations influence decisions at the appropriate stage. • Provide quality assurance and peer review for work completed by Data Privacy and Security Professionals, set expectations for evidence and documentation, and coach colleagues on complex or sensitive cases. • Own the privacy position for complex supplier and contractual arrangements, identifying required data protection terms and controls and engaging Legal and Procurement within their respective remits. • Direct the assessment of data landscapes, access controls, minimisation, retention, deletion, classification, labelling and international transfers, requiring corrective action where arrangements are insufficient. • Own material privacy risks and remediation actions for assigned portfolios, agree proportionate treatment plans with accountable business owners, challenge slippage and escalate where exposure remains outside tolerance. • Produce authoritative, concise and audit-ready privacy opinions, investigation reports, risk statements and senior management information, clearly recording decisions, rationale, dependencies and residual risk. • Lead privacy input into audits, assurance reviews and regulatory enquiries, coordinating evidence and responses and ensuring identified weaknesses are addressed sustainably. • Identify systemic and emerging risks across PIAs, investigations, incidents and assurance outcomes; translate themes into changes to standards, controls, guidance, training and operating processes. • Support delivery of the privacy strategy, governance framework and team operating model defined by the Data Privacy and Security Architect, and deputise in specifically agreed forums or portfolio discussions when required; the role does not own overall strategy or function accountability. • Build effective senior relationships across Legal, Security, HR, Procurement, Architecture, Audit and global privacy teams, ensuring accountability remains clear and specialist decisions are taken by the correct function. • Manage a complex portfolio independently, prioritising according to risk and business impact while maintaining confidentiality, procedural fairness and a complete decision trail. • Retain clear escalation boundaries: the Data Privacy and Security Architect remains accountable for CU Digital privacy strategy, final precedent-setting decisions, material legal or regulatory positions, senior Legal leadership engagement and the overall privacy function roadmap and posture. Essential Skills / Experience • Strong working knowledge of data protection principles and how they apply in a large, complex business environment, including GDPR and relevant Indian data protection requirements. • Significant practical experience leading and determining complex PIAs/DPIAs and providing authoritative, risk-based privacy advice. • Experience investigating privacy, compliance, data handling or control issues and producing clear, evidence-based findings and actions. • Ability to analyse complex processin