20d ago
New

Data Protection Consultant

IndiaIndia·MumbaiFull-timemid
OtherConsultant
0 views0 saves0 applied

Quick Summary

Overview

This role is for one of Weekday’s clients Min Experience: 2+ yearsLocation: Mumbai, Maharashtra,

Technical Tools
OtherConsultant

Requirements

~1 min read

Minimum 2 years of relevant experience in Data Privacy, Data Protection, Information Security, GRC, or related domains.

Responsibilities

~1 min read

Design, implement, and support Privacy and Data Protection Programs for clients.

Independently prepare, review, and maintain Records of Processing Activities (ROPA).

Conduct Data Protection Impact Assessments (DPIA) and identify privacy risks and appropriate mitigation measures.

Conduct privacy risk assessments, gap assessments, audits, and compliance reviews.

Perform data privacy assessments across business processes, systems, applications, and third-party relationships.

Work with information security and privacy frameworks including ISO 27001, ISO 27701, NIST, and HITRUST.

Advise internal teams and clients on privacy regulations including GDPR, DPDPA, and CCPA/CPRA.

Draft and review privacy policies, procedures, assessment reports, compliance documentation, and implementation roadmaps.

Assist organizations with establishing and improving privacy governance frameworks.

Support cybersecurity governance and ISMS documentation.

Identify privacy and security compliance gaps and recommend remediation measures.

Work with stakeholders across Legal, IT, Information Security, Compliance, HR, and business functions.

Support client meetings, workshops, assessments, and privacy-related consulting engagements.

Good working knowledge of GDPR.

Working knowledge of India's DPDPA and CCPA/CPRA.

Understanding of privacy risk assessments, gap assessments, and compliance audits.

Knowledge of privacy principles, data lifecycle, data processing activities, and privacy risk management.

Familiarity with ISO 27001 and ISO 27701.

Strong documentation, analytical, communication, and stakeholder-management skills.

Ability to prepare professional reports, policies, assessment documents, and compliance roadmaps.

Nice to Have

~1 min read

Exposure to NIST and HITRUST frameworks.

Experience working in a consulting or client-facing environment.

Understanding of cybersecurity governance and ISMS.

Experience with privacy management or GRC tools will be an added advantage.

Experience conducting privacy workshops and stakeholder interviews.

Candidates holding one or more of the following certifications will be preferred:

ISO 27001 / ISO 27701 certifications will be an added advantage.

We are particularly interested in candidates who have actually prepared ROPAs and conducted DPIAs as part of their current or previous roles, rather than candidates with only theoretical knowledge of these activities.

The candidate should be comfortable explaining:

How a ROPA is created and maintained.

What information is collected from business/process owners for a ROPA.

When a DPIA is required.

How privacy risks are identified and assessed during a DPIA.

How remediation and risk mitigation actions are documented and tracked.

How GDPR/DPDPA requirements are translated into practical organizational controls.

Must-have skills

data protection, GDPR, Data Protection Impact Assessment

Good-to-have skills

Data Privacy, Records of Processing Activities

Location & Eligibility

Where is the job
Mumbai, India
On-site at the office

Listing Details

Posted
September 10, 2026
First seen
September 29, 2026
Last seen
September 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
21%
Scored at
September 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Data Protection Consultant