Data Protection Officer (DPO) / Privacy Compliance Manager
Appsierra
Experience
3-9 Yrs
Salary
Not disclosed
Job type
Full Time
Work mode
Remote
Skills
- gdpr
- dpdpa
- uk gdpr
- us privacy laws
- privacy governance
- data mapping
- records of processing activities (ropa)
- data protection impact assessment (dpia)
- privacy by design
- vendor due diligence
- data processing agreements (dpa)
- privacy incident management
- ai/ml privacy assessment
- privacy training and awareness
- stakeholder management
Job description
We are looking for an experienced Data Protection Officer (DPO) / Privacy Compliance Manager to support the organization in managing its privacy and data protection obligations. The DPO will act as the central point of contact for privacy governance, regulatory compliance, data protection advisory, privacy risk management and data subject/data principal rights, working closely with business and functional teams.
Key Responsibilities
Establish and maintain a privacy governance framework, policies, procedures and compliance documentation.
Maintain regulatory compliance trackers, action trackers and provide practical privacy advisory to business teams.
Identify and map personal data, review collection, processing, storage, sharing, retention and deletion practices.
Create and maintain Records of Processing Activities (RoPA) and identify privacy risks associated with data flows.
Set up and oversee processes for data subject rights requests (access, correction, deletion, consent withdrawal, grievance).
Conduct and coordinate Data Protection Impact Assessments (DPIAs) and recommend mitigation measures.
Review new products, services, processes and technologies for privacy by design considerations.
Conduct vendor due diligence, third‑party privacy assessments, review Data Processing Agreements and maintain a vendor privacy risk register.
Identify and assess privacy incidents, coordinate breach notifications and corrective actions with IT, Information Security, Legal and business teams.
Review privacy implications of AI‑enabled and automated processing, support privacy assessments for AI/ML solutions.
Deliver privacy awareness and role‑specific training, develop awareness material and support internal audits.
Maintain privacy registers (risk, DPIA, data rights requests, vendor assessments, incidents, training) and prepare periodic management reports.
Collaborate with Management, Legal & Compliance, Information Security, HR, Engineering, AI/Data/Analytics, Procurement and Business teams.
Requirements
In‑depth knowledge of DPDPA (India), GDPR (EU) and UK GDPR (UK). Working knowledge of applicable U.S. privacy laws and other data protection regulations.
Clear understanding of controllers/fiduciaries, processors, sub‑processors, consent, purpose limitation, data minimisation, retention and cross‑border transfers.
Ability to monitor regulatory developments and assess impact on the organization.
Hands‑on experience with data mapping, RoPA creation, DPIAs and privacy by design.
Experience conducting vendor due diligence, reviewing DPAs and maintaining a vendor privacy risk register.
Experience managing privacy incidents, breach notifications and coordinating corrective actions.
Ability to assess privacy implications of AI/ML solutions and technology vendor risk.
Strong communication skills, able to explain privacy requirements to technical and non‑technical audiences.
Strong analytical and risk‑assessment skills, independent judgment, high integrity and confidentiality.
Preferred Qualifications
Bachelor’s degree in Law, Information Technology, Risk, Compliance or a related field.
3+ years of hands‑on privacy compliance experience.
Certifications such as CIPP/E, CIPM, CDPO or ISO/IEC 27701 are an advantage.
About the company
Appsierra
appsierra.com