Data Privacy Manager

  • Gurugram
  • Max Life Insurance Company Limited
Job Summary The role involves strategizing, implementing & overseeing comprehensive data privacy initiatives to safeguard sensitive data and promote culture of privacy within organization. This will require candidate to work closely with stakeholders in different teams such as legal, compliance, security, digital technology, operations, HR, Distribution and other functional owners responsible for data processing for effective implementation of privacy initiatives. Key Responsibilities Support DPO in developing, implementing, and maintaining robust data privacy & protection framework Review the organization posture on masking critical & sensitive data Advising the organization on data protection impact assessments (DPIAs), Privacy Notices, Data Discovery, and other measures to ensure readiness with the data protection laws and regulations Experience in handling data governance and data classification tools Develop Data Inventory and create/ review DFDs Develop Consent Management by designing consent architecture framework and reviewing data flow diagrams Assessment of As-is vendor contracts and based on assessment results, identify gaps between current contracts and to-be contracts Prepare a Remediation Plan/Implementation Roadmap post gap assessment Understanding of existing DLP and perform gap assessment Conduct regular security audits and risk assessments to identify and address any potential issues or breaches Develop and maintain an effective incident response plan for data breaches or privacy incidents or privacy incidents Develop policies and procedures for Data Privacy Impact Assessment, Privacy Incidents, third party privacy framework, Breach management procedures & data privacy governance structure Work closely with cross-functional teams to identify and address potential privacy risks, ensuring compliance with regulations Collaborate with external partners to ensure adherence to compliance, regulation and standards Drive privacy related training to employees at all levels to enhance awareness and understanding. Training staff who are involved in data processing and handling personal data of data subjects’/ data principals and foster a privacy- aware culture Conduct regular privacy audits to assess compliance and identify areas for improvement. Implement monitoring mechanisms to track and report on privacy-related metrics.