Job Title: Data Privacy Officer /Global Data Privacy Officer

Company : Bajaj Auto Limited

Location : Pune

Reporting to : General Counsel/Chief Digital Information Officer

The Data Privacy Officer (DPO) is responsible for developing, implementing, and overseeing the Bajaj Auto’s global privacy and data protection program . The role will ensure compliance with applicable privacy laws and regulations across India and all jurisdictions where the company and its subsidiaries operate. The DPO will have the primary responsibility to advice on privacy matters, manage privacy risks balancing the support to  business growth initiatives and act as a key liaison with regulators, customers, employees, and internal /external stakeholders world wide

Responsibilities :

  1. Privacy Governance Strategy
  • Develop and maintain organization’s global privacy framework, policies, standards, and procedures.
  • Establish privacy governance structures including consent management system in India and international subsidiaries
  • Lead the design and implementation of privacy-by-design and privacy -by-default principles.
  • Monitor emerging privacy laws and regulatory developments in India and globally.
  • Advice the Data Privacy Steering Committee of Bajaj Auto on privacy risks and periodically update compliance status.

 

  1. Regulatory Compliance
  • Ensure compliance with (a) Digital Personal Data Protection Act, 2023 (India) (b) General Data Protection Regulation (EU/EEA) (c) Privacy regulations in applicable jurisdictions where Bajaj Auto or its subsidiaries operate.
  • Maintain records of processing activities.
  • Manage data subject rights processes and regulatory reporting obligations.
  • Coordinate response to regulatory inquires and investigations.

 

  1. Oversight on Global Subsidiaries
  • Lead the Privacy activities as the central SPOC for all global subsidiaries
  • Implement privacy framework and requirements by partnering with local legal, compliance, HR, Digitech and business teams.
  • Establish privacy champions within the overseas entities.
  • Conduct periodic compliance reviews and maturity assessments.

 

 

  1. Data Protection Impact Assessments
  • Lead Privacy Impact Assessment (PIAs) and Data Protection Impact Assessments (DPIAs)
  • Review new products, technologies and business initiatives for privacy implications.

 

  1. Cross – Border Data Transfers
  • Develop frameworks for international data transfers.
  • Review and approve transfer mechanisms and contractual safeguards.
  • Assess Vendor and subsidiary data sharing arrangements.
  • Monitor localization and transfer requirements across jurisdictions

 

  1. Vendor & Third-Party Risk Management
  • Review privacy provisions in customer, supplier and partner contracts.
  • Conduct privacy due diligence for vendors and service providers.
  • Support procurement processes involving personal data.
  • Monitor ongoing compliance of critical third parties.

 

  1. Incident Response & Breach management
  • Serve as a core member of the incident response team.
  • Assess privacy incidents and determine notification obligations.
  • Coordinate breach investigations and remediation activities.
  • Maintain incident records an lessons-learned processes.

 

  1. Training & Awareness
  • Develop and delivery privacy training program in India and globally .
  • Conduct targeted training and promote a cultre of privacy awareness and accountability

 

  1. Audit & Monitoring
  • Conduct privacy audits and compliance assessments.
  • Define privacy KPIs and reporting metrics.
  • Prepare management and Board reports on privacy program effectiveness

Qualifications

Education

  • Bachelor’s degree in law, Information Technology, Cyber security, Business Administration or related filed
  • Master’s degree preferred

Experience

  • 7-10 years of experience in privacy, data protection, compliance, legal, information security or risk management.
  • Experience managing multi-jurisdiction privacy programs and supporting global operations and international subsidiaries.
  • Demonstrated experience interacting with regulators and senior executives

Preferred Certifications

  • Certified Information Privacy Professional (CIPP/E, CIPP/US. CIPP/A)
  • Certified Information Privacy manager
  • Relevant compliance or risk certifications.

Key Competencies

  • Deep understanding of global privacy laws and regulations
  • Strong legal and regulatory interpretation skills.
  • Excellent stakeholder management and influencing abilities.
  • Experience managing cross-border data transfer issues.
  • Strong analytical and risk assessment capabilities
  • Ability to operate effectively in a multinational environment
  • Excellent communication and presentation skills
  • Program management and leadership experience.