Manager - Corporate Compliance and Data Privacy
CRISIL LtdJob Description
Manager – Corporate Compliance (Data Privacy)
Department
None
Job Description
Role: Manager – Corporate Compliance (Data Privacy)
Location: Mumbai
Job Description
Role Overview
We are seeking an experienced and driven manager to strengthen our enterprise-wide privacy program. The successful candidate will serve as a subject-matter expert and trusted advisor, helping the organization to operate data protection obligations, manage privacy risk, and embed a culture of privacy-by-design across all business functions. This is a high-visibility role with direct impact on regulatory standing, customer trust, and strategic risk management.
Key Responsibilities:
Privacy Program Management
- Design, implement, and continuously improve the enterprise data privacy programme in alignment with applicable regulations (GDPR, CCPA, PDPA, and other relevant frameworks).
- Maintain and evolve the organization’s privacy governance framework, including policies, standards, procedures, and guidelines.
- Conduct the Records of Processing Activities (RoPA) and ensure regular review and accuracy of all data processing inventories.
Regulatory Compliance & Advisory
- Monitor and interpret global data privacy laws and regulations; provide timely guidance to legal, technology, and business stakeholders on compliance obligations.
- Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new projects, products, and third-party engagements.
- Manage data subject rights requests (DSARs) processes, ensuring timely and compliant responses across jurisdictions.
Privacy Technology & Tools
- Administer and optimize privacy management platforms, with hands-on experience in OneTrust or equivalent privacy tools.
- Leverage tooling to automate consent management, data mapping, incident workflows, and vendor assessment processes.
- Partner with IT and cybersecurity teams to implement technical and organisational measures supporting privacy compliance.
Data Incident & Breach Management
- Assist in the data breach response process: triage, contain, notify regulators and affected individuals in accordance with statutory timelines.
- Maintain the data incident register and produce post-incident reports with remediation actions.
Third-Party & Vendor Privacy
- Conduct due diligence on vendors and partners who process personal data; negotiate and review Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs).
- Manage the privacy risk assessment lifecycle for third-party relationships end-to-end.
Training & Culture
- Develop and deliver targeted privacy training and awareness campaigns across business units.
- Champion privacy-by-design principles in product development and business change initiatives.
Reporting & Stakeholder Engagement
- Prepare regular reports and dashboards on privacy program metrics for senior leadership, the DPO, and board-level committees.
- Engage with regulators, external counsel, and industry bodies as required.
Qualifications & Experience:
Essential
- 6–9 years of progressive, hands-on experience in data privacy, data protection, or information governance roles.
- Demonstrable experience managing end-to-end privacy programmes within complex, multi-jurisdictional organizations.
- Strong knowledge of GDPR, UK GDPR, CCPA/CPRA and other major privacy frameworks; familiarity with sector-specific regulations (e.g. HIPAA, PSD2) is a plus.
- Proven expertise with OneTrust or comparable privacy management platforms.
- Experience conducting DPIAs, PIAs, RoPA maintenance, and DSAR management.
- Track record of advising C-suite, legal, and technology stakeholders on privacy risk.
- Excellent written and verbal communication skills; ability to translate complex regulatory requirements into actionable business guidance.
- One or more recognised privacy certifications: CIPP/E, CIPP/US, CIPM, CIPT (IAPP) or equivalent.
Desirable
- LLB or equivalent law degree, providing a strong foundation in legal interpretation and regulatory engagement.
- Experience with Binding Corporate Rules (BCRs), cross-border data transfer mechanisms, or international privacy programmes.
- Exposure to privacy engineering, data minimisation architecture, or AI/ML governance.
- Experience in a regulated industry (financial services, healthcare, or technology)
Open Positions
1
Mandatory Skills
Data Privacy,Data Protection,Corporate Compliance,Privacy Governance,Privacy Risk
Education Qualification
Legal or Compliance background preferable.
Experience
6 to 10 years
Job role
Job requirements
About company
Similar jobs you can apply for
Digital / Online MarketingDigital Marketing Specialist
Vritti Solutions Ltd.
Tally Operator
SK Global VenturesStaff Nurse
Zenith HospitalBusiness Advisor
Insta Transfer Biz Pvt Ltd
Floor Manager
Wandwave Technologies
Crew Member
McDYou can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 6 to 9 years are eligible to apply for this job. You can apply for more jobs in Mumbai/Bombay to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Mumbai/Bombay at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Mumbai/Bombay . Through apna, you can find jobs in 64 cities across India. Join NOW!