AVP - Data Protection (Techno-Legal)
India
Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region. SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network. We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.
With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.
|
Primary Responsibilities (These are the key work activities to achieve the position objective. Limit this section to essential responsibilities.) |
Percentage (%) of Time Spent
|
Secondary Responsibilities (List of duties that are marginal or infrequent.) |
|
20% |
Maintain regulatory reference materials, obligation registers and supporting records. |
|
20% |
Support version control, approvals, publication and evidence maintenance. |
|
15% |
Maintain review comments, issue logs and closure evidence. |
|
15% |
Track mitigations, owners, target dates and residual risks for DPO oversight. |
|
15% |
Coordinate information collection and maintain supporting documentation. |
|
10% |
Document observations and follow up action items with relevant stakeholders. |
|
5% |
Maintain case files, trackers, dashboards and governance meeting inputs. |
|
Total |
100% |
|
- Knowledge Requirements: Working knowledge of data protection and privacy requirements, legal research, contract and policy review, technology systems, data lifecycle concepts, privacy-by-design, DPIA / PIA, data subject rights, grievance handling and basic information security controls.
- Specialist / technical skills: Legal and regulatory research; drafting and document review; contract clause review; data flow mapping; privacy assessment; technology risk understanding; issue tracking; Microsoft Office and structured record management. Familiarity with privacy management or GRC tools is desirable.
- Behavioural / management skills: Analytical thinking, attention to detail, written and verbal communication, documentation discipline, stakeholder coordination, confidentiality, ownership and ability to work under the guidance of the DPO.
- Education & Qualifications: Relevant graduate or post-graduate qualification. A combined legal and technology background is preferred. Relevant privacy, technology or security certification may be desirable.