About the Opportunity / Organizer
Sumitomo Mitsui Banking Corporation (SMBC), headquartered in Tokyo, is a core member of Sumitomo Mitsui Financial Group (SMBC Group). With an illustrious history dating back to 1876, SMBC is a global banking powerhouse offering personal, corporate, and investment banking services across an integrated worldwide network. SMBC is currently inviting applications for the post of AVP – Data Protection (Techno-Legal) in New Delhi to drive data protection compliance, privacy legal risk management, technology risk assessments, and regulatory governance under the guidance of the Data Protection Officer (DPO).
Key Responsibilities
- Regulatory Research & Compliance: Conduct privacy legal and regulatory research, track evolving data protection frameworks, and maintain implementation trackers and regulatory obligation registers for DPO review.
- Policy Drafting & Documentation: Draft, review, and maintain privacy policies, consent wording, privacy notices, internal guidelines, and regulatory evidence across system lifecycles.
- Contract Review: Evaluate contracts, data processing clauses, confidentiality terms, and vendor privacy requirements in coordination with Legal, Procurement, and Information Security teams.
- Impact Assessments & Privacy-by-Design: Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new technologies and products, integrating privacy-by-design concepts into system architectures.
- Data Mapping & Governance: Assist in data flow mapping, data inventories, records of processing, personal data retention/disposal, data subject grievance redressal, incident management, and periodic DPO reporting.
Eligibility & Qualifications
- Relevant graduate or postgraduate qualification (a combined background in Law and Technology is strongly preferred).
- In-depth working knowledge of data protection regulations, DPIA/PIA methodologies, privacy-by-design, data subject rights, and information security controls.
- Demonstrated expertise in legal research, contract clause review, data flow mapping, and technology risk evaluations.
- Familiarity with privacy management software/GRC tools and relevant privacy/security certifications is highly desirable.
- Exceptional analytical thinking, meticulous documentation discipline, and strong communication skills.
How to Apply
Eligible and interested candidates can apply directly through the official SMBC Asia Career portal.