Data Protection Officer (DPO)
India
Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region. SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network. We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.
With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.
|
Primary Responsibilities (These are the key work activities to achieve the position objective. Limit this section to essential responsibilities.) |
Percentage (%) of Time Spent
|
Secondary Responsibilities (List of duties that are marginal or infrequent.) |
|
15% |
Support governance forum materials and policy refresh activities. |
|
15% |
Track emerging guidance and prepare internal briefing notes where required. |
|
15% |
Support review of consent, data masking, anonymization or privacy tooling requirements. |
|
15% |
Support data quality, data ownership, data lifecycle, reporting usage and information governance initiatives. |
|
15% |
Maintain evidence and records of processing / assessment outcomes. |
|
10% |
Support issue tracking, ownership assignment and closure monitoring. |
|
5% |
Assist in privacy clauses / contract checks and targeted awareness campaigns. |
|
10% |
Coordinate inputs for management updates, audit reviews and governance packs. |
|
Total |
100% |
|
Section 6: Knowledge, Skills, Experience & Qualifications
- Knowledge Requirements: Strong understanding of privacy laws and data governance frameworks, including DPDP Act / Rules, RBI expectations, privacy governance, data governance management, privacy risk management, DPIA / PIA, data subject rights, grievance redressal, privacy incident management and third-party data protection obligations.
- Specialist / technical skills: Ability to design and implement privacy, data governance and data management frameworks, policies, controls and monitoring mechanisms; familiarity with data flow mapping, data inventory, data preparation, data quality, data analysis / utilization governance, consent management, data masking, anonymisation, security protocols, IT infrastructure and privacy management tools.
- Behavioural / management skills: Executive stakeholder management, regulatory interpretation, enterprise governance, strategic leadership, programme management, risk management, communication, cross-functional collaboration and ability to develop privacy and data governance capabilities.
- Relevant Experience: At least 15+ years of experience across data privacy & protection, information security and risk. Prior experience in implementing EU GDPR and / or leading and managing organisation-wide data privacy, data protection or data governance programme(s), such as DPDP. Experience in cross-functional stake-holder management including but not limited to IT/IS, operations, governance, risk & compliance.
- Education and Certifications: Relevant graduate / Post-graduate qualification. Preferred Data Privacy / Data Protection certifications include Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT), Certified Information Systems Security Professional (CISSP), ISO 27701 or equivalent.