Data Protection Officer
Spandana Sphoorty Financial · Hyderabad
- Experience8–10 yrs
- SalaryDisclosed
- Work modeonsite
- Posted23 Sept 2026
About Spandana Sphoorty Financial
Spandana Sphoorty Financial is hiring in Hyderabad in financial services. This role looks for around 8+ years of experience.
Skills
- DPDP Act compliance
- privacy governance
- data protection
- Privacy Impact Assessments
- data protection risk management
- privacy incident management
- regulatory compliance
- information security frameworks
- audit
- incident management
The role
A data protection officer at a financial services company develops privacy governance frameworks, applies DPDP Act compliance and conducts Privacy Impact Assessments, while managing data protection risks and privacy incidents. The role also uses ISO/IEC 27701 and regulatory compliance to maintain accountable information practices.
Full job description
Position Name: Data Protection Officer (DPO)
Designation: Manager / Sr. Manager
Reporting To: AVP
Location: Corporate Office, Hyderabad
JOB PURPOSE:
To oversee and ensure compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and other applicable privacy regulations, establish privacy governance frameworks, safeguard personal data, manage data protection risks, and serve as the primary point of contact for regulators, data principals, and internal stakeholders on all privacy-related matters.
DUTIES AND RESPONSIBILITIES:
Develop, implement, and monitor the organization's data privacy and data protection framework.
Ensure compliance with the DPDP Act, 2023, related rules, and other applicable privacy regulations.
Advise management on privacy risks, regulatory obligations, and data protection controls.
Monitor lawful processing of personal data, consent management, data retention, and data lifecycle practices.
Conduct Privacy Impact Assessments (PIA/DPIA) and recommend risk mitigation measures.
Coordinate and manage privacy incidents, investigations, and breach notification processes.
Facilitate internal and external audits, regulatory inspections, and compliance reviews.
Collaborate with Legal, Compliance, IT, Information Security, HR, and Business Teams to ensure privacy compliance.
Develop and conduct privacy awareness programs and employee training initiatives.
Maintain privacy-related policies, procedures, records, reports, and regulatory submissions.
Act as the designated point of contact for Data Principals and regulatory authorities on privacy-related matters.
QUALIFICATIONS & EXPERIENCE:
Bachelor's Degree or higher from a recognized university in Information Security, Computer Science, Information Technology, Law, Business Administration, or related discipline.
8+ years of overall professional experience, including at least 5 years of specialized experience in the privacy domain, with expertise in Data Protection, Privacy, Compliance, Information Security, Risk Management, Internal Audit, or Legal functions.
Preferred Certifications
Certified Information Privacy Professional (CIPP)
Certified Information Privacy Manager (CIPM)
ISO/IEC 27701 Lead Implementer / Lead Auditor
ISO/IEC 27001 Lead Auditor
DPDP Practitioner / DPDP Lead Auditor
CISSP (Preferred)
CISM (Preferred)
ISO 31000 Risk Management Certification (Preferred)
KEY COMPETENCIES:
Strong knowledge of the DPDP Act, 2023, privacy regulations, and data protection governance.
Ability to identify, assess, and mitigate privacy and data protection risks, including conducting DPIA/PIA assessments.
Sound understanding of information security frameworks, regulatory compliance, audit, and incident management.
Excellent communication, stakeholder management, and training capabilities to drive privacy awareness across the organization.
High standards of integrity, professional ethics, analytical thinking, and independent decision-making.