Data Protection Officer

  • Thiruvananthapuram
  • Muthoot Fincorp Ltd.

ROLE SUMMARY

The Data Protection Officer (DPO) at Muthoot Fincorp Limited (MFL) will be responsible for overseeing the company's data protection strategy, ensuring compliance with applicable laws and data protection regulations (such as the Information Technology Act, 2000, DPDP act and other relevant guidelines). The DPO will develop and maintain data privacy policies, conduct risk assessments, and foster a culture of data privacy awareness across the organization.

.

KEY RESPONSIBILITIES

Data Privacy Strategy and Compliance

  1. Develop and implement a comprehensive data protection strategy that aligns with MFLs strategic objectives and regulatory requirements.
  2. Ensure compliance with all relevant data protection laws, including the IT Act, 2000, and RBI guidelines specific to NBFCs.
  3. Monitor and evaluate the effectiveness of data protection policies, procedures, and controls

Risk Assessment and Mitigation

  1. Conduct regular risk assessments and data protection impact assessments (DPIAs) to identify potential risks and vulnerabilities.
  2. Develop and implement mitigation strategies to address identified risks, ensuring minimal impact on business operations.
  3. Report data protection risks and incidents to the Chief Risk Officer and senior management.
  4. Lead the investigation and management of data breaches or incidents, ensuring timely reporting to relevant authorities and stakeholders.
  5. Develop and maintain an incident response plan, including communication protocols, investigation procedures, and remediation actions.
  6. Draft, review, and update data protection policies, procedures, and guidelines in line with evolving regulations and industry standards.

Stakeholder Management

  1. Design and deliver data protection training programs for employees to enhance awareness and compliance across all departments.
  2. Promote a culture of data privacy through regular communication, workshops, and awareness campaigns.
  3. Act as the primary point of contact for regulatory authorities, customers, and internal stakeholders on data protection matters.
  4. Collaborate with internal and external auditors to ensure compliance and address findings related to data protection.
  5. Coordinate with internal teams (e.G., IT, Legal, Compliance) to ensure data protection policies are integrated into all business processes.

Reporting, Governance and Monitoring

  1. Develop and monitor key data protection performance indicators (KPIs) to measure the effectiveness of the data protection program.
  2. Oversee data governance practices to ensure data accuracy, integrity, and security across the organization.
  3. Prepare and present regular reports to the Chief Risk Officer and the Board on data protection compliance, risks, and incidents.
  4. Maintain records of processing activities (ROPA) and ensure transparency in data handling practices.


KEY STAKEHOLDERS

Internal Stakeholders

External Stakeholders

  1. Board of Directors
  2. KMPs/SMPs
  3. Legal and Compliance
  4. Internal Audit and Quality Assurance
  5. Technology
  6. Information Security Team
  7. Operations and Customer Service
  8. Regulatory Authorities
  9. External Auditors/Consultants



KEY SKILLS & BEHAVIOURAL ATTRIBUTES

  1. Basic understanding of NBFC or financial services domain and applicability of data protection and privacy laws in India which includes Information Technology Act, 2000 and DPDP Act, 2023.
  2. Ability to manage complex data protection projects and initiatives.
  3. Proficiency in incident management and risk assessment techniques.
  4. Experience in developing and delivering training programs.
  5. Behavioral Attributes- Driven and in alignment with our Purpose “Transforming the life of the common man by improving their financial well-being” and anchored by our core value of integrity, collaboration, and excellence.


EDUCATION / EXPERIENCE

  1. Bachelor’s degree in law, information security, risk management or related field. Professional certification in data protection (e.G., CIPP, CIPM, CIPT, CCDPO) is preferred.
  2. At least 5-7 years of experience in data protection, privacy, information security, or risk management, preferably within the financial services sector.

Insert your email to proceed to Muthoot Fincorp Ltd.'s job offer

or