We use cookies to offer you the best possible website experience. Your cookie preferences will be stored in your browser’s local storage. This includes cookies necessary for the website's operation. Additionally, you can freely decide and change any time whether you accept cookies or choose to opt out of cookies to improve the website's performance, as well as cookies used to display content tailored to your interests. Your experience of the site and the services we are able to offer may be impacted if you do not accept all cookies.
Job Title: Data Protection Officer (DPO) Experience: 6 to 8 Years Job Location: Hyderabad Experience ▪ 6 - 8 years of experience in: ▪ Data privacy ▪ Risk management ▪ Governance / audits (Experience can be mixed across these domains; direct privacy experience is preferred but not mandatory.) Skills ▪ Strong understanding of privacy principles, the DPDP Act, the GDPR and general compliance frameworks. ▪ Ability to interpret policies, draft documents, and manage structured workflows. ▪ Good coordination skills across IT, HR, Legal, Delivery, and Operations. ▪ Strong written & verbal communication. ▪ Ability to handle sensitive incidents confidentially and professionally. Key Responsibilities A. DPDP Compliance Operations ▪ Support the DPO in implementing and maintaining compliance with the Digital Personal Data Protection Act, 2023 and GDPR requirements ▪ Maintain and update the Record of Processing Activities (ROPA) and enterprise-wide data inventory across HR, IT, Sales, Delivery, Marketing, and Vendor functions. ▪ Assist in preparing privacy notices, consent language, internal guidelines, and data-handling SOPs. B. DSAR & Rights Handling ▪ Manage the end-to-end workflow for Data Principal Rights: Access, Correction, Erasure, Consent Withdrawal, and Grievances. ▪ Maintain DPDP-compliant logs, turnaround times, and reporting dashboards. C. Privacy Governance & Documentation ▪ Draft, update, and operationalise policies, including: ▪ Data Retention & Disposal ▪ Information Handling & Access ▪ Vendor Data Protection Guidelines ▪ Breach Response SOP • Maintain structured documentation aligned with ESG, ISO 27001/27701, SOC2 and client contract requirements. D. Vendor & Third-Party Compliance ▪ Conduct privacy/security assessments for new vendors and tools. ▪ Review vendor DPAs, NDAs, and data-handling terms under supervision of the Head LRC and DPO. ▪ Track and escalate high-risk vendor issues. E. Awareness & Training ▪ Assist in rolling out privacy awareness programs, toolkits, intranet content, and mandatory training modules. ▪ Support delivery teams/HR/IT with compliance clarifications. F. Incident & Breach Support ▪ Maintain the Breach Register and assist the DPO in triage, documentation, evidence collection, and root-cause analysis. ▪ Coordinate with InfoSec, IT, HR, and Legal during investigations. G. Audit & Reporting ▪ Support internal audits, client audits, vendor audits, and certification assessments (ISO 27701, SOC2). ▪ Prepare monthly compliance reports for MD/CEO and governance decks for the Board, as required by the DPO
Get empowered by NTT DATA Business Solutions!
We transform. SAP® solutions into Value
NTT DATA Business Solutions is a fast-growing international IT company and one of the world’s leading SAP partners. We are a full service provider delivering everything from business consulting to implementation of SAP solutions, including hosting services and support.
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy, you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Required Cookies
These cookies are required to use this website and can't be turned off.
Required Cookies
Provider
Description
Enabled
SAP as service provider
We use the following session cookies, which are all required to enable the website to function:
"route" is used for session stickiness
"careerSiteCompanyId" is used to send the request to the correct data centre
"JSESSIONID" is placed on the visitor's device during the session so the server can identify the visitor
"Load balancer cookie" (actual cookie name may vary) prevents a visitor from bouncing from one instance to another
Advertising Cookies
These cookies serve ads that are relevant to your interests. You may freely choose to accept or decline these cookies at any time. Note that certain functionality that these third parties make available may be impacted if you do not accept these cookies.
Advertising Cookies
Provider
Description
Enabled
LinkedIn
LinkedIn is an employment-oriented social networking service. We use the Apply with LinkedIn feature to allow you to apply for jobs using your LinkedIn profile. Opting out of LinkedIn cookies will disable your ability to use Apply with LinkedIn. Cookie Policy Cookie Table Privacy Policy Terms and Conditions