National Payments Corporation of India (NPCI) logo

Associate Data Protection & Privacy

National Payments Corporation of India (NPCI)
3 hours ago
Full-time
On-site
Mumbai Suburban District, Maharashtra, India
Associate
About NPCI-
National Payments Corporation of India (NPCI), an umbrella organization for retail payments in India, is an initiative of Reserve Bank of India (RBI) and Indian Banks’ Association (IBA) and is authorized under the provisions of the Payment and Settlement Systems Act, 2007 for providing payment and settlement systems in India. Considering the utility nature of NPCI, it has been incorporated as a “Not for Profit” Company under the provisions of Section 25 of Companies Act 1956 (now Section 8 of Companies Act 2013), with an intention to provide best in class digital payment infrastructure by creation of efficient and innovative retail payment platforms.
NPCI is an Equal Opportunity Employer. At NPCI, we are committed to fostering an inclusive workplace and have zero tolerance for any form of discrimination based on race, ethnicity, disability, gender identity, and the LGBTQ+ Community.
To learn more about our company please click on below link https://www.npci.org.in/

The opportunity-
We are seeking a dedicated and knowledgeable Data Privacy professional to join our team at the Goregaon office. The ideal candidate will have a strong understanding of data privacy laws and standards, particularly ISO 27701:2019, the Digital Personal Data Protection Act (DPDPA), and the General Data Protection Regulation (GDPR). This role is crucial in ensuring our organization's compliance with data protection regulations and maintaining the highest standards of data privacy

Job details
Job Title: Data Privacy
Division: Marketing Information Security
Years of Experience : Minimum 1 – 3 years
Education : Bachelor’s degree in Information Technology, Computer Science, Law or a related field.
Full-time
Location : Mumbai
Permanent Role

Key responsibilities-
1. Data Privacy Compliance:
• Ensure compliance with ISO 27701:2019, DPDPA, GDPR, and other relevant data privacy laws and
regulations.
• Assist in the development, implementation, and maintenance of data privacy policies and procedures.
• Conduct regular audits and assessments to identify areas of non-compliance and recommend corrective
actions.
2. Technical Expertise:
• Implement and manage encryption and data masking techniques to protect sensitive information.
• Conduct technical privacy risk assessments to identify and address potential vulnerabilities.
• Write Business Requirement Documents (BRDs) for the development and enhancement of privacy tools
and technologies.
• Collaborate with IT and development teams to ensure privacy-by-design principles are integrated into
systems and applications.
• Conduct privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new
projects and initiatives.
• Govern privacy settings for cloud environments and third-party applications.
• Develop and maintain data inventories and data flow diagrams to map the movement of personal data
within the organization.
• Utilize anonymization and pseudonymization techniques to protect personal data while enabling data
utility.
• Ensure secure data transfer protocols are in place for data sharing and processing activities.
3. Risk Management:
• Identify and evaluate data privacy risks and provide recommendations to mitigate them.
• Monitor data processing activities to ensure they comply with data protection requirements.
4. Data Subject Rights:
• Manage and respond to data subject requests (DSRs) and other rights requests under GDPR and DPDPA.
• Ensure timely and accurate responses in compliance with legal requirements.
5. Training and Awareness:
• Develop and deliver training programs to raise awareness of data privacy requirements across the
organization.
• Provide guidance and support to employees on data privacy best practices.
6. Incident Management:
• Assist in the investigation and management of data breaches and incidents.
• Prepare incident reports and implement measures to prevent future occurrences.
7. PII inventory and scanning
• Lead in maintaining the PII inventory across the organization for all products
• Perform database and endpoint scanning on periodic basis to identify PII/ sensitive data and take appropriate action as per defined procedure.
8. Documentation and Reporting:
• Maintain comprehensive records of data processing activities.
• Prepare reports and documentation required for internal and external audits.
9. Collaboration:
• Work closely with all team members to ensure alignment with organizational goals and objectives.
• Collaborate with cross-functional teams to integrate data privacy considerations into business processes

Requirements

Key skills and experience required-
• Excellent knowledge of data protection principles and practices
• Strong analytical and problem-solving skills • Effective communication and interpersonal skills
• Ability to work independently and as part of a team
• Proficiency in using data privacy management tools and software