539 Data Privacy Analyst jobs in India

Data Privacy Analyst

Hyderabad, Andhra Pradesh Kofax

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Level

Mid Career


To manage a high-quality readiness to data protection & information governance, Subject Access Requests, third party risk management, and Data Protection enquiries from the council upholding our statutory obligations.

The data protection analyst will assist the compliance activities of the Data Protection Officer, supporting data privacy regulations and apply them in a practical manner.

This role reports to the Data Protection Officer and will support aspects of corporate Data Privacy Compliance programs including managing redlined addendum, contracts, and other activities required by the Data Protection Officer.

Key Responsibilities

  • Support the DPO/Manager, Data Privacy Programs as required in the delivery of the Data Protection Program
  • Identify, analyze, and document risks to individuals’ privacy arising from data processing activities
  • Handle and assist the data subject access right requests, ensuring compliance data subject access right.
  • Support to conduct Data Protection Impact Assessments (DPIAs) for projects, systems, and third-party vendors.
  • Lead or assist in investigating, documenting, and reporting data breaches to authorities and affected parties as required.
  • Assist to generate reports for management on the organization’s compliance status and areas for improvement.
  • Monitor third-party compliance with data protection requirements.
  • Review and evaluate data privacy agreements with vendors, partners, and service providers.
  • Review and support the customer infosec questionnaire in the data protection topics.
  • Support the creation as well as the implementation of the records regarding the processing activities
  • Support documentation and evaluation of data processing activities
  • Work closely with Sales, Product, and other teams to improve data privacy protections and ensure end-to-end data privacy compliance.
  • Maintain records to support the data protection and audits where necessary
  • Participate in the implementation and embedding the data governance organizational model
  • Manage the compliance tools and systems for data security and compliance
  • Support the educating team-members and other employees about data protection regulation

  • Required Skills

  • 1-3 years prior Project Management experience
  • Knowledge of EU the General Data Protection Regulation (GDPR),
  • Ability to handle multiple tasks and interact with various stakeholders
  • Experience performing third party compliance assurance assessments
  • Excellent client relationship and customer service skills
  • Understanding of common internet related technologies, ideally including SaaS (cloud, enterprise systems,) and on-premises business application
  • Affinity for IT topics especially in legal technology
  • Proactive, self-starter who requires minimal support
  • Exceptional interpersonal, written, and oral communication skills in English and French(preferred)

  • Required Experience

  • See Qualifications section
  • Experience with privacy and risk management tools (Skills in OneTrust beneficial)
  • Over 1 year of practical experience related to GDPR
  • Tungsten Automation is an Equal Opportunity Employer M/F/Disability/Vets

    While the job description describes what is anticipated as the requirements of the position, the job requirements are subject to change based upon any changing needs and requirements of the business.

    This advertiser has chosen not to accept applicants from your region.

    Data Privacy Analyst

    Hyderabad, Andhra Pradesh Kofax

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    To manage a high-quality readiness to data protection & information governance, Subject Access Requests, third party risk management, and Data Protection enquiries from the council upholding our statutory obligations.


    The data protection analyst will assist the compliance activities of the Data Protection Officer, supporting data privacy regulations and apply them in a practical manner.  


    This role reports to the Data Protection Officer and will support aspects of corporate Data Privacy Compliance programs including managing redlined addendum, contracts, and other activities required by the Data Protection Officer.


    Key Responsibilities    



    • Support the DPO/Manager, Data Privacy Programs as required in the delivery of the Data Protection Program

    • Identify, analyze, and document risks to individuals’ privacy arising from data processing activities

    • Handle and assist the data subject access right requests, ensuring compliance data subject access right.

    • Support to conduct Data Protection Impact Assessments (DPIAs) for projects, systems, and third-party vendors.

    • Lead or assist in investigating, documenting, and reporting data breaches to authorities and affected parties as required.

    • Assist to generate reports for management on the organization’s compliance status and areas for improvement.

    • Monitor third-party compliance with data protection requirements.

    • Review and evaluate data privacy agreements with vendors, partners, and service providers.

    • Review and support the customer infosec questionnaire in the data protection topics.

    • Support the creation as well as the implementation of the records regarding the processing activities

    • Support documentation and evaluation of data processing activities

    • Work closely with Sales, Product, and other teams to improve data privacy protections and ensure end-to-end data privacy compliance.

    • Maintain records to support the data protection and audits where necessary

    • Participate in the implementation and embedding the data governance organizational model

    • Manage the compliance tools and systems for data security and compliance

    • Support the educating team-members and other employees about data protection regulation



    Required Skills

    • 1-3 years prior Project Management experience

    •   Knowledge of EU the General Data Protection Regulation (GDPR),

    • Ability to handle multiple tasks and interact with various stakeholders

    • Experience performing third party compliance assurance assessments

    • Excellent client relationship and customer service skills

    • Understanding of common internet related technologies, ideally including SaaS (cloud, enterprise systems,) and on-premises business application

    • Affinity for IT topics especially in legal technology

    • Proactive, self-starter who requires minimal support

    • Exceptional interpersonal, written, and oral communication skills in English and French(preferred)



    Required Experience

    • See Qualifications section

    • Experience with privacy and risk management tools (Skills in OneTrust beneficial)

    • Over 1 year of practical experience related to GDPR



    Tungsten Automation is an Equal Opportunity Employer M/F/Disability/Vets



    While the job description describes what is anticipated as the requirements of the position, the job requirements are subject to change based upon any changing needs and requirements of the business.


    • 1-3 years prior Project Management experience

    •   Knowledge of EU the General Data Protection Regulation (GDPR),

    • Ability to handle multiple tasks and interact with various stakeholders

    • Experience performing third party compliance assurance assessments

    • Excellent client relationship and customer service skills

    • Understanding of common internet related technologies, ideally including SaaS (cloud, enterprise systems,) and on-premises business application

    • Affinity for IT topics especially in legal technology

    • Proactive, self-starter who requires minimal support

    • Exceptional interpersonal, written, and oral communication skills in English and French(preferred)

    This advertiser has chosen not to accept applicants from your region.

    Group Data Privacy (GDP) – Data Privacy Analyst - NCT

    Karnataka, Karnataka Deutsche Bank

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    Description

    Legal

  • Legal is responsible for managing the legal risk of Deutsche Bank Group. Our mission is to ensure that legal services are provided to the bank with the goals of protecting its integrity and reputation and managing legal risk to make transactions viable and safe.
  • We partner with Risk, Regulation, Compliance, Group Audit and others to provide a proactive integrated risk management approach. We work closely with managers to coordinate activities across business lines so we avoid violations of laws. We make sure the Bank has up-to-date information on regulatory and legal changes and continues to be seen as a trusted, respected market participant.
  • Group Data Privacy (GDP)

  • Group Data Privacy (GDP) is an independent 2nd Line of Defense risk type control function within Legal which defines the risk management framework for data protection and privacy risks. GDP is located in Frankfurt, New York, London, and Berlin and Bangalore organized in a matrix structure with regional Data Protection Officers (DPOs) and Business Partners providing guidance to Business Divisions and Infrastructure Functions.
  • Moreover, GDP manages a global network of local, internal data protection officers and rolled-out a controls framework in order to safeguard Deutsche Bank’s integrity and reputation and to ensure the correct processing of personal data entrusted to us.
  • As part of the TPRM process, as a 2LoD control function, GDP is mandated to review third party outsourcing activities adherence with data privacy requirements.
  • What we’ll offer you

    As part of our flexible scheme, here are just some of the benefits that you’ll enjoy,

  • Best in class leave policy.
  • Gender neutral parental leaves
  • 100% reimbursement under childcare assistance benefit (gender neutral)
  • Sponsorship for Industry relevant certifications and education
  • Employee Assistance Program for you and your family members
  • Comprehensive Hospitalization Insurance for you and your dependents
  • Accident and Term life Insurance
  • Complementary Health screening for 35 yrs. and above
  • Your key responsibilities

  • Advise Service Officers of divisions and infrastructure functions on Data Protection related controls, attestations and evidences required to pass TPRM process and the GDP Transfer Impact Assessment in order to meet the data protection requirements for vendor engagements including requirements.
  • Carry out reviews of TPRM transactions for new or existing service relationships ensuring that activities to be outsourced as well as existing service relationships are reviewed in line with the established controls in an effort to address and mitigate potential risks
  • Prepare submission to GDP Business Partners respectively local DPO for risk acceptance / approval in line with GDP Key Operating Documents (KOD), follow up and escalation, if required.
  • Maintain GDP related documentation of transactions, respective findings and documented risks in the TPRM tool.
  • Remain informed of regulatory developments in the data protection related outsourcing requirements including relevant GDP Policies and procedures as well as (assist if required in) maintenance of GDP Key Operating Documents
  • Collaborate closely with GDP Business Partner and local DPOs as well as other control functions units performing TPRM tasks.
  • Develop and maintain knowledge of the data privacy regulatory requirements applicable to DB incl. the EU General Data Protection Regulation (GDPR) and remain up-to-date with relevant regulatory requirements and industry trends.
  • Maintain close collaboration with other functions within GDP Berlin such as Controls Assurance, Law Monitoring, and Training & Awareness.
  • Provide support for Controls Assurance activities when required.
  • Your skills and experience

  • University degree, preferably in Business or Operations, law degree a plus
  • Knowledge of privacy regulations, financial industry, outsourcing or IT background a plus
  • Experience with managing deadlines and working to tight deadlines
  • Experience in making formal (written or oral) presentations and recommendations in a corporate setting
  • English proficiency (oral and written) a must. German a plus
  • Computer proficiency in Excel, Word, PowerPoint, Lotus Notes required
  • Experience in SharePoint or other database tools a plus
  • Competencies:

  • Excellent verbal and written communication skills
  • Ability to articulate issues in plain and clear language orally (as well as in writing) which enables the audience to follow easily
  • Strong relationship building skills
  • Ability to handle stress and high volumes
  • Ability to reach solutions proactively, quickly and diplomatically
  • Strategic and proactive approach to problem identification, analysis and resolution
  • Ability to work independently, with minimal to no oversight
  • Ability to work in an intercultural environment
  • How we’ll support you

  • Training and development to help you excel in your career.
  • Coaching and support from experts in your team.
  • A culture of continuous learning to aid progression.
  • A range of flexible benefits that you can tailor to suit your needs.
  • This advertiser has chosen not to accept applicants from your region.

    Data Privacy and Risk Analyst

    Hyderabad, Andhra Pradesh McDonald's

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About McDonald’s:

    One of the world’s largest employers with locations in more than 100 countries, McDonald’s Corporation has corporate opportunities in Hyderabad. Our global offices serve as dynamic innovation and operations hubs, designed to expand McDonald's global talent base and in-house expertise. Our new office in Hyderabad will bring together knowledge across business, technology, analytics, and AI, accelerating our ability to deliver impactful solutions for the business and our customers across the globe.


    Position Summary:

    Privacy, Security, & Risk Specialist: (Supervisor, Data Governance_G3_EDAA0104)

    As a Data Risk & Compliance Analyst within the Enterprise Data Governance (EDG) team, you will play a key role in supporting data risk management, privacy, and compliance efforts across the organization. You will operationalize and enhance processes that support secure data practices, regulatory alignment, and the protection of sensitive data assets. Working cross-functionally with business, legal, privacy, and cybersecurity teams, you will help ensure that data governance capabilities are implemented with integrity and transparency.

    This role combines technical acumen, risk assessment, and compliance management to support data discovery, access controls, data classification, and privacy risk assessments.


    Who we’re looking for:

    Primary Responsibilities:

    • Risk & Privacy Controls Execution : Maintain and support risk and privacy controls across key processes such as data retention, access monitoring, and records destruction.
    • Data Discovery & Classification Enablement : Help drive the implementation of data discovery, tagging, and classification activities by identifying structured data with privacy and regulatory implications.
    • Governance Platform Integration : Collaborate in testing and integrating data governance capabilities with risk and compliance systems (e.G., GRC tools, OneTrust, ServiceNow IRM).


    Key Responsibilities:

    • Partner with the privacy, legal, and security teams to operationalize privacy-by-design, records management, and access governance.
    • Support the creation, enhancement, and enforcement of data handling policies, including ROPA, data classification, and regulatory reporting.
    • Maintain and analyze Records of Processing Activities (ROPA) and ensure accuracy and traceability of critical data elements.
    • Assist with privacy and compliance risk assessments, tracking mitigation plans, and supporting enterprise audit requests.
    • Align with Identity and Access Management teams to manage privileged access appropriately, supporting the governance of access control and provisioning.
    • Assist in developing data quality metrics, health indices, and access provisioning dashboards.
    • Provide expert guidance to EDG councils and data stewards regarding privacy, data protection, and compliance requirements.
    • Support the organization in addressing questions about security classification, data-sharing agreements, and retention schedules.


    Skill:

    • Bachelor’s degree in information technology, Computer Science, or a related field.
    • 5+ years of experience in data governance, privacy, information risk, and compliance.
    • Familiarity with NIST CSF, NIST Privacy Framework, and ISO 27001.
    • Hands-on experience with GRC and privacy tools like OneTrust, RSA Archer, Collibra, or ServiceNow IRM.
    • Strong understanding of data discovery and classification technologies;
      ability to define policies and regex rules.
    • Knowledge of information governance, access control, and secure records lifecycle management.
    • Excellent analytical and communication skills with the ability to work across technical and business teams.
    • Cybersecurity certifications preferred (e.G., CISSP, CISA).


    Work location: Hyderabad, India

    Work pattern: Full time role.

    Work mode: Hybrid.

    This advertiser has chosen not to accept applicants from your region.

    Senior Privacy Analyst, Data Risk Office

    Hyderabad, Andhra Pradesh Bristol Myers Squibb

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    **Working with Us**
    Challenging. Meaningful. Life-changing. Those aren't words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You'll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible.
    Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us .
    **Position Summary**
    The Operations Lead - Data Risk Office (DRO) is responsible for the effective delivery of all privacy operations within the organization. This role provides oversight and has accountability for the DRO operations team, ensuring that privacy compliance processes are executed consistently and in alignment with global data protection regulations like GDPR, CCPA and others. The Operations Lead coordinates closely with cross-functional partners - including Privacy Legal, Cybersecurity, and business unit leaders - to manage privacy incidents, data subject requests, and regulatory inquiries. By monitoring operational metrics and driving continuous improvements, this role ensures the Data Risk Office meets its obligations and maintains a strong compliance posture. Ultimately, the Operations Lead serves as the central point of contact for privacy operations, accountable for the team's performance and the consistent, timely delivery of all DRO workstreams.
    **Key Responsibilities**
    **Operational Oversight & Delivery:**
    **Lead and coordinate the DRO operations team** , taking accountability for on-time and high-quality execution across all privacy operations workstreams (DSRs, DIN/DBN, DPQ, etc.). Ensure that standard operating procedures are followed and that the team meets regulatory deadlines and internal service level agreements for each request or incident. Provide guidance and mentorship to team members, and monitor daily workflows to quickly address any roadblocks or delays.
    **Data Incident & Breach Management (DIN/DBN):**
    **Manage the end-to-end process for data incidents and breaches** , from initial triage through regulatory notification. Work closely with the Cybersecurity incident response team to investigate privacy incidents and determine breach severity. If a breach is deemed reportable under laws like GDPR (within 72 hours) or CCPA, coordinate with Privacy Legal to draft notifications and ensure timely submission to Data Protection Authorities and communications to affected individuals. Maintain detailed incident records (what happened, actions taken) to demonstrate compliance. After resolution, lead post-incident reviews to implement preventive measures.
    **Data Subject Rights (DSR) Request Oversight:** **Oversee the intake and fulfillment of Data Subject Rights requests** (access, deletion, correction, etc.) across all relevant jurisdictions. Make sure requests are logged in the appropriate system (e.g., Privacy Hub or SharePoint) and assigned to the correct data owners. Track each DSR to closure, verifying that responses to data subjects meet legal requirements (for example, completed within **30 days for GDPR** .or **45 days under CCPA** ). Provide guidance on handling complex cases (like identity verification or legal holds) and ensure our standard templates and processes are used for consistency and compliance.
    **Regulatory Inquiries & Notifications:** Act as the **primary liaison with Data Protection Authorities (DPAs)** for any regulatory inquiries, audits, or breach notifications. This includes coordinating responses to official requests or investigations and preparing formal notification letters when required by law (e.g., drafting notification content for authorities in collaboration with Legal). Ensure all regulatory communications are handled professionally and within required timeframes. Maintain a log of all DPA interactions and outcomes, and escalate critical issues to senior leadership as needed.
    **Operational Metrics & Reporting:** **Develop and deliver privacy operations metrics and reports** to DRO leadership and other stakeholders. Aggregate data across all workstreams (e.g. number of DSRs received and closed, breach notification timelines, outstanding DPQs) and create weekly/monthly dashboards. Highlight key trends or risks - for instance, if DSR volumes spike or an incident took longer than expected to close. Use these insights to recommend process improvements or resource adjustments. The Operations Lead is expected to present these metrics in governance meetings, demonstrating where the DRO is on track and where attention is needed.
    **Cross-Functional Coordination & Compliance:** **Facilitate strong collaboration between the Data Risk Office and other teams** . Work with **Privacy Legal (Chief Privacy Officer's team)** to interpret new regulatory requirements and update operations accordingly. Partner with the **Cyber Risk/Security team** during incident investigations to ensure swift containment and remediation of data breaches.
    **Qualifications & Experience**
    **Educational Background:**
    Bachelor's degree in a relevant field such as Information Security, Law, Business Administration, or Computer Science. A master's degree or professional certification in data privacy/risk management (e.g., CIPP/E, CIPM) is highly valued but not required, demonstrating formal knowledge of privacy principles.
    **Experience:** Minimum **5-7 years** of experience in data privacy, compliance, or related risk management operations. The candidate should have **hands-on experience managing privacy processes** - for example, overseeing responses to data breaches and data subject requests in a multinational environment. Experience working with global privacy regulations (GDPR, CCPA, etc.) is essential.
    **Regulatory Knowledge:** Strong working knowledge of major data protection laws and regulatory requirements, including GDPR (Europe), CCPA/CPRA (California), and familiarity with other laws like LGPD (Brazil), PDPA (various countries). The candidate should understand obligations such as breach reporting timelines (e.g. 72-hour rule for GDPR), individual rights processes, and how these regulations apply operationally. They should also stay updated on emerging privacy laws and be able to quickly adapt processes to new legal requirements.
    **Operational Leadership & Communication:** Demonstrated ability to lead an operations team and coordinate complex processes. This includes excellent organizational skills to juggle multiple concurrent tasks (e.g., several DSRs and an incident investigation simultaneously) and ensure nothing falls through the cracks. Strong communication skills are required - the Operations Lead must communicate clearly with stakeholders at all levels, from analysts up to executives.
    If you come across a role that intrigues you but doesn't perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career.
    **Uniquely Interesting Work, Life-changing Careers**
    With a single vision as inspiring as Transforming patients' lives through science , every BMS employee plays an integral role in work that goes far beyond ordinary. Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting global participation in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues.
    **On-site Protocol**
    BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs. The occupancy type that you are assigned is determined by the nature and responsibilities of your role:
    Site-essential roles require 100% of shifts onsite at your assigned facility. Site-by-design roles may be eligible for a hybrid work model with at least 50% onsite at your assigned facility. For these roles, onsite presence is considered an essential job function and is critical to collaboration, innovation, productivity, and a positive Company culture. For field-based and remote-by-design roles the ability to physically travel to visit customers, patients or business partners and to attend meetings on behalf of BMS as directed is an essential job function.
    BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to . Visit careers.bms.com/ ( eeo-accessibility to access our complete Equal Employment Opportunity statement.
    BMS cares about your well-being and the well-being of our staff, customers, patients, and communities. As a result, the Company strongly recommends that all employees be fully vaccinated for Covid-19 and keep up to date with Covid-19 boosters.
    BMS will consider for employment qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.
    If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.
    **Company:** Bristol-Myers Squibb
    **Req Number:** R
    **Updated:** :05:53.693 UTC
    **Location:** Hyderabad-IN
    Bristol Myers Squibb is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, pregnancy, citizenship, marital status, gender expression, genetic information, political affiliation, or any other characteristic protected by law.
    This advertiser has chosen not to accept applicants from your region.

    Senior Privacy Analyst, Data Risk Office

    Hyderabad, Andhra Pradesh Bristol Myers Squibb

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    Working with Us
    Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible.

    Position Summary

    The Operations Lead – Data Risk Office (DRO) is responsible for the effective delivery of all privacy operations within the organization. This role provides oversight and has accountability for the DRO operations team, ensuring that privacy compliance processes are executed consistently and in alignment with global data protection regulations like GDPR, CCPA and others. The Operations Lead coordinates closely with cross-functional partners – including Privacy Legal, Cybersecurity, and business unit leaders – to manage privacy incidents, data subject requests, and regulatory inquiries. By monitoring operational metrics and driving continuous improvements, this role ensures the Data Risk Office meets its obligations and maintains a strong compliance posture. Ultimately, the Operations Lead serves as the central point of contact for privacy operations, accountable for the team’s performance and the consistent, timely delivery of all DRO workstreams.

    Key Responsibilities

    Operational Oversight & Delivery:

    Lead and coordinate the DRO operations team , taking accountability for on-time and high-quality execution across all privacy operations workstreams (DSRs, DIN/DBN, DPQ, etc.). Ensure that standard operating procedures are followed and that the team meets regulatory deadlines and internal service level agreements for each request or incident. Provide guidance and mentorship to team members, and monitor daily workflows to quickly address any roadblocks or delays.

    Data Incident & Breach Management (DIN/DBN):

    Manage the end-to-end process for data incidents and breaches , from initial triage through regulatory notification. Work closely with the Cybersecurity incident response team to investigate privacy incidents and determine breach severity. If a breach is deemed reportable under laws like GDPR (within 72 hours) or CCPA, coordinate with Privacy Legal to draft notifications and ensure timely submission to Data Protection Authorities and communications to affected individuals. Maintain detailed incident records (what happened, actions taken) to demonstrate compliance. After resolution, lead post-incident reviews to implement preventive measures.

    Data Subject Rights (DSR) Request Oversight: Oversee the intake and fulfillment of Data Subject Rights requests (access, deletion, correction, etc.) across all relevant jurisdictions. Make sure requests are logged in the appropriate system (e.g., Privacy Hub or SharePoint) and assigned to the correct data owners. Track each DSR to closure, verifying that responses to data subjects meet legal requirements (for example, completed within 30 days for GDPR .or 45 days under CCPA ). Provide guidance on handling complex cases (like identity verification or legal holds) and ensure our standard templates and processes are used for consistency and compliance.

    Regulatory Inquiries & Notifications: Act as the primary liaison with Data Protection Authorities (DPAs) for any regulatory inquiries, audits, or breach notifications. This includes coordinating responses to official requests or investigations and preparing formal notification letters when required by law (e.g., drafting notification content for authorities in collaboration with Legal). Ensure all regulatory communications are handled professionally and within required timeframes. Maintain a log of all DPA interactions and outcomes, and escalate critical issues to senior leadership as needed.

    Operational Metrics & Reporting: Develop and deliver privacy operations metrics and reports to DRO leadership and other stakeholders. Aggregate data across all workstreams (e.g. number of DSRs received and closed, breach notification timelines, outstanding DPQs) and create weekly/monthly dashboards. Highlight key trends or risks – for instance, if DSR volumes spike or an incident took longer than expected to close. Use these insights to recommend process improvements or resource adjustments. The Operations Lead is expected to present these metrics in governance meetings, demonstrating where the DRO is on track and where attention is needed.

    Cross-Functional Coordination & Compliance: Facilitate strong collaboration between the Data Risk Office and other teams . Work with Privacy Legal (Chief Privacy Officer’s team) to interpret new regulatory requirements and update operations accordingly. Partner with the Cyber Risk/Security team during incident investigations to ensure swift containment and remediation of data breaches.

    Qualifications & Experience

    Educational Background:

    Bachelor’s degree in a relevant field such as Information Security, Law, Business Administration, or Computer Science. A master’s degree or professional certification in data privacy/risk management (e.g., CIPP/E, CIPM) is highly valued but not required, demonstrating formal knowledge of privacy principles.

    Experience: Minimum 5–7 years of experience in data privacy, compliance, or related risk management operations. The candidate should have hands-on experience managing privacy processes – for example, overseeing responses to data breaches and data subject requests in a multinational environment. Experience working with global privacy regulations (GDPR, CCPA, etc.) is essential.

    Regulatory Knowledge: Strong working knowledge of major data protection laws and regulatory requirements, including GDPR (Europe), CCPA/CPRA (California), and familiarity with other laws like LGPD (Brazil), PDPA (various countries). The candidate should understand obligations such as breach reporting timelines (e.g. 72-hour rule for GDPR), individual rights processes, and how these regulations apply operationally. They should also stay updated on emerging privacy laws and be able to quickly adapt processes to new legal requirements.

    Operational Leadership & Communication: Demonstrated ability to lead an operations team and coordinate complex processes. This includes excellent organizational skills to juggle multiple concurrent tasks (e.g., several DSRs and an incident investigation simultaneously) and ensure nothing falls through the cracks. Strong communication skills are required – the Operations Lead must communicate clearly with stakeholders at all levels, from analysts up to executives.

    Uniquely Interesting Work, Life-changing Careers
    With a single vision as inspiring as “Transforming patients’ lives through science™ ”, every BMS employee plays an integral role in work that goes far beyond ordinary. Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting global participation in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues.

    On-site Protocol

    BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs. The occupancy type that you are assigned is determined by the nature and responsibilities of your role:

    Site-essential roles require 100% of shifts onsite at your assigned facility. Site-by-design roles may be eligible for a hybrid work model with at least 50% onsite at your assigned facility. For these roles, onsite presence is considered an essential job function and is critical to collaboration, innovation, productivity, and a positive Company culture. For field-based and remote-by-design roles the ability to physically travel to visit customers, patients or business partners and to attend meetings on behalf of BMS as directed is an essential job function.

    BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to . Visit to access our complete Equal Employment Opportunity statement.

    BMS cares about your well-being and the well-being of our staff, customers, patients, and communities. As a result, the Company strongly recommends that all employees be fully vaccinated for Covid-19 and keep up to date with Covid-19 boosters.

    BMS will consider for employment qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.

    Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.

    This advertiser has chosen not to accept applicants from your region.

    Digital Trust DRSG-S&G-Data Privacy and Ethics Analyst

    Chennai, Tamil Nadu KPMG India

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About KPMG in India

    KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

    KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.
    TempHtmlFile span { white-space: pre-wrap; } { line-height: ; margin-bottom: ; background: #FFF; font-family: Helvetica; font-size: ; margin-top: 0; margin-left: 0; margin-right: 0; } { color: #2E2E2F; font-family: Helvetica; font-size: ; letter-spacing: 0; font-style: normal; font-weight: bold; margin: 0; padding: 0; } { margin-top: 2pt; line-height: ; margin-bottom: 2pt; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-left: 0; margin-right: 0; } { color: # ; font-family: Univers for KPMG; font-size: 10pt; font-style: normal; font-weight: bold; margin: 0; padding: 0; } { margin-top: 5pt; line-height: ; margin-bottom: 12pt; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-left: 0; margin-right: 0; } { margin-top: 5pt; line-height: ; margin-bottom: 12pt; text-align: justify; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-left: 0; margin-right: 0; } { color: # ; font-family: Univers for KPMG; font-size: 10pt; font-style: normal; font-weight: normal; margin: 0; padding: 0; } { margin-top: 5pt; line-height: ; margin-bottom: 0; margin-left: ; text-indent: ; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-right: 0; } { color: # ; font-family: Symbol; font-size: 10pt; font-style: normal; font-weight: normal; margin: 0; padding: 0; display: inline-block; text-indent: 0; width: ; } { margin-top: 5pt; line-height: ; margin-bottom: 12pt; margin-left: ; text-indent: ; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-right: 0; } { margin-top: 5pt; line-height: ; margin-bottom: 0; margin-left: ; text-indent: ; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-right: 0; } { margin-top: 5pt; line-height: ; margin-bottom: 12pt; margin-left: ; text-indent: ; background: #FFF; font-family: Univers for KPMG; font-size: 10pt; margin-right: 0; }

    Data Privacy

    Job Title:

    Function: IT Advisory in Risk Consulting

    Location:

    Position Summary

    The position will require candidates to assist organizations in establishing enterprise privacy governance framework and driving privacy initiatives. It is a techno functional role in Data Privacy and Data Protection. Candidates will be required to develop creative solutions in privacy space for key stakeholders. The position requires candidates to be aware of global privacy regulatory landscape, understand and interpret regulatory clauses into privacy requirements and provide tailor made recommendations to organizations. The role requires understanding of latest technology and tools available in the market.

    The position will involve leading and executing engagements, create quality deliverables for various Data Privacy and Data Protection activities for stakeholders. The position interacts with Senior Management across organizations.

    Roles and Responsibilities

    ? Assist key stakeholder consultations regarding operational impact of data protection related laws, regulations, client contractual requirements, broad data industry practices and consider the resulting changes in organizations policies, procedures, systems, training, awareness, and monitoring activities

    ? Design / re-design processes and privacy controls to ensure compliance with laws, regulations, and internal standards in the most efficient, streamlined and customer centric way

    ? Recommend creative solutions and participate in discussions regarding the recommendations with various stakeholders

    ? Execute and provide a sustainable privacy framework based on different regulations / standards / industries / client requirements, and assess privacy risks

    ? Draft / update policies, guidelines, procedures, and documentation as required based on external or internal changes for our clients based on different regulations / standards / industries

    ? Define privacy metrics and corresponding dashboards for monitoring and reporting purposes

    ? Assist in the coordinating and reporting of various Data Protection activities to stakeholders in clients. In that regard, the position interacts with executive level personnel and client account teams or functional groups

    ? Assist in developing various awareness communications, training, and workshop materials

    ? Assist in research, Point of Views (PoVs) and Thought Leaderships on Data Privacy and Data Protection

    ? Develop Data Flow Diagrams (DFDs) and Data Inventory for organizations

    ? Conducts Data Protection / Privacy Impact Assessments (PIAs)

    ? Propose solutions for improvement and/or develop new approaches and / or policies / guidance by leveraging their knowledge of existing processes and business experience by considering Privacy as a design

    ? Maintain and expand current knowledge of field of expertise and communicates new developments and resulting impact to clients and team members

    ? Develop relationships and builds a network of people within the team and across the firm

    ? Conduct assessments / surveys ( on privacy impact / risk & controls) / data gathering and analysis on applications, products, processes, documentation and third parties to evaluate compliance with laws, regulations, and internal standards

    Knowledge and Skills Requirements

    ? Ability to learn and understand the firm and data protection polices as well as familiarity with other risk management initiatives

    ? Ability to manage tasks and activities in a timely manner and be responsible for specific outcomes

    ? Strong knowledge of data privacy and protection regulation (Example: GDPR, PDPB, PDPA, APP, CCPA to name a few)

    ? Demonstrate knowledge on data protection solutions such as DLP, DRM, Cloud Security, Encryption, MDM to name a few

    ? Demonstrate knowledge on data privacy solutions such as One Trust, to name a few

    ? Requires a solid understanding of firm's business and area wide privacy issues and concerns

    ? Requires an understanding the high-level technology issues surrounding information security as well as the firm's application architecture for those applications which process personal or client confidential data

    ? Basic knowledge of privacy tools, project management tools and methodologies

    ? Problem solving, flexibility and initiative

    ? Ability to keep confidential sensitive information

    ? Strong research and communications skills

    ? Expected to interface with executive leaders and must be able to demonstrate expanded knowledge of one or more functional areas while communicating processes, identifying, and providing solutions for mitigating risk factors associated with quality & risk management initiatives

    ? May take responsibility for a discreet component(s) of a project and work independently with periodic feedback

    ? Assist in the training of Associates and/or Intern to familiarize these individuals with firm processes and policies and enable these members to handle more complex issues

    Other Requirements

    Job Requirements

    Education:

    ? Bachelor's degree or equivalent work experience

    ? Legal degree

    Certification Requirements:

    ? DSCI Certified Privacy Professional

    ? DSCI Certified Privacy Lead Assessor

    ? Certified Information Privacy Manager

    ? Certified information Privacy Professional/ Asia

    ? Certified information Privacy Professional/ Canada

    ? Certified information Privacy Professional/ Europe

    ? Certified information Privacy Professional/ US

    ? Certified Information Privacy Technologist


    Equal employment opportunity information

    KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
    TempHtmlFile span { white-space: pre-wrap; } { margin-bottom: 0; font-family: Calibri; font-size: 11pt; line-height: 108%; margin-top: 0; margin-left: 0; margin-right: 0; } { color: #1F3864; font-family: 'Calibri Light', 'sans-serif'; font-size: 11pt; text-transform: uppercase; font-style: normal; font-weight: bold; margin: 0; padding: 0; } { color: #1F3864; font-family: Calibri; font-size: 11pt; font-style: normal; font-weight: bold; margin: 0; padding: 0; } { margin-bottom: 0; margin-left: ; text-indent: ; font-family: Calibri; font-size: 11pt; line-height: 108%; margin-top: 0; margin-right: 0; } { color: #1F3864; font-family: Calibri; font-size: 11pt; font-style: normal; font-weight: normal; margin: 0; padding: 0; display: inline-block; text-indent: 0; width: ; } { color: #1F3864; font-family: Calibri; font-size: 11pt; font-style: normal; font-weight: normal; margin: 0; padding: 0; } { color: #1F3864; font-size: 11pt; font-style: normal; font-weight: bold; margin: 0; padding: 0; } { font-size: 11pt; font-style: normal; font-weight: normal; margin: 0; padding: 0; }

    Data Privacy and Protection - BE, LLB or LLM

    Certifications - IAPP Privacy
    This advertiser has chosen not to accept applicants from your region.
    Be The First To Know

    About the latest Data privacy analyst Jobs in India !

     

    Nearby Locations

    Other Jobs Near Me

    Industry

    1. request_quote Accounting
    2. work Administrative
    3. eco Agriculture Forestry
    4. smart_toy AI & Emerging Technologies
    5. school Apprenticeships & Trainee
    6. apartment Architecture
    7. palette Arts & Entertainment
    8. directions_car Automotive
    9. flight_takeoff Aviation
    10. account_balance Banking & Finance
    11. local_florist Beauty & Wellness
    12. restaurant Catering
    13. volunteer_activism Charity & Voluntary
    14. science Chemical Engineering
    15. child_friendly Childcare
    16. foundation Civil Engineering
    17. clean_hands Cleaning & Sanitation
    18. diversity_3 Community & Social Care
    19. construction Construction
    20. brush Creative & Digital
    21. currency_bitcoin Crypto & Blockchain
    22. support_agent Customer Service & Helpdesk
    23. medical_services Dental
    24. medical_services Driving & Transport
    25. medical_services E Commerce & Social Media
    26. school Education & Teaching
    27. electrical_services Electrical Engineering
    28. bolt Energy
    29. local_mall Fmcg
    30. gavel Government & Non Profit
    31. emoji_events Graduate
    32. health_and_safety Healthcare
    33. beach_access Hospitality & Tourism
    34. groups Human Resources
    35. precision_manufacturing Industrial Engineering
    36. security Information Security
    37. handyman Installation & Maintenance
    38. policy Insurance
    39. code IT & Software
    40. gavel Legal
    41. sports_soccer Leisure & Sports
    42. inventory_2 Logistics & Warehousing
    43. supervisor_account Management
    44. supervisor_account Management Consultancy
    45. supervisor_account Manufacturing & Production
    46. campaign Marketing
    47. build Mechanical Engineering
    48. perm_media Media & PR
    49. local_hospital Medical
    50. local_hospital Military & Public Safety
    51. local_hospital Mining
    52. medical_services Nursing
    53. local_gas_station Oil & Gas
    54. biotech Pharmaceutical
    55. checklist_rtl Project Management
    56. shopping_bag Purchasing
    57. home_work Real Estate
    58. person_search Recruitment Consultancy
    59. store Retail
    60. point_of_sale Sales
    61. science Scientific Research & Development
    62. wifi Telecoms
    63. psychology Therapy
    64. pets Veterinary
    View All Data Privacy Analyst Jobs