Overview

Data Protection Officer Jobs in Chennai, Tamil Nadu, India at Cholamandalam MS General Insurance Co. Ltd.

Title: Data Protection Officer

Company: Cholamandalam MS General Insurance Co. Ltd.

Location: Chennai, Tamil Nadu, India

Job Purpose

The Data Protection Officer (DPO) will be responsible for ensuring the organization’s compliance with applicable data protection and privacy laws, regulations, and internal policies. The role involves overseeing data protection strategy, advising senior management, monitoring compliance, handling data principal requests, and acting as the primary point of contact with regulators and data principals.

Key Responsibilities

Governance & Compliance

  • Ensure compliance with applicable data protection laws and regulations including:
  • Digital Personal Data Protection Act (DPDP Act), 2023 and Rules
  • IRDAI regulations and guidelines
  • Other applicable privacy and sectoral regulations
  • Define, implement, and maintain the organization’s data protection and privacy governance framework.
  • Develop and periodically review privacy policies, standards, procedures, and guidelines.
  • Monitor regulatory developments and assess their impact on the organization.
  • Maintaining personal data inventory/records with accountability for accuracy and periodic review
  • Third party Privacy Risk Management to ensure compliance to contractual clauses, onboarding due diligence, and ongoing assurance/monitoring.

Advisory & Risk Management

  • Advise the Board, senior management, and business functions on data protection obligations and risks.
  • Conduct and oversee Data Protection Impact Assessments (DPIAs) for new and existing systems, products, and processes.
  • Identify, assess, and mitigate privacy risks across IT systems, vendors, and business operations.
  • Review contracts, agreements, and third‑party arrangements from a data protection perspective.

Data Principal Rights Management

  • Oversee mechanisms for handling Data Principal requests such as:
  • Access, correction, erasure and right to nominate
  • Grievances and complaints
  • Ensure timely and compliant response to data principal requests.
  • Managing consent /withdrawal mechanism and integrations in line with DPDP guidelines.
  • Ensure PII data is secured and accessible to only authorized users & systems.

Incident & Breach Management

  • Perform breach assessment, documentation/evidence trail requirements on:
  • Personal data breaches and incidents
  • Impact assessments and notification obligations
  • Act as the single point of contact for regulators in case of data protection incidents.

Awareness & Training

  • Design and deliver data protection awareness and training programs for employees and relevant stakeholders.
  • Promote a culture of privacy‑by‑design and privacy‑by‑default across the organization.

Regulatory & Stakeholder Engagement

  • Serve as the point of contact with:
  • Data Protection Board of India / Regulators
  • Auditors and external assessors
  • Support regulatory inspections, audits, and supervisory reviews.

Key Skills & Competencies

Technical & Domain Skills

Strong understanding of:

  • Data protection and privacy frameworks
  • Information security controls and risk management
  • Familiarity with data lifecycle management, data discovery, data classification, and consent management
  • Experience with DPIA, privacy risk assessments, and breach response

Behavioural & Leadership Skills

  • High level of integrity, independence, and judgment
  • Strong communication and stakeholder management skills
  • Ability to influence senior leadership and business teams
  • Analytical and problem‑solving mindset

Qualification & Experience

Educational Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Risk Management, or related field

Certifications (Preferred)

  • CIPP/E, CIPP/A, CIPM, or equivalent privacy certifications
  • ISO/IEC 27701 Lead Implementer
  • Any Information Security certifications (CISSP, CISM, etc.) will be an advantage

Experience

  • Minimum 12–15 years of experience in:
  • Data protection, privacy, information security, risk, or compliance
  • Minimum 3–5 years in a leadership role
  • Prior experience in banking, insurance, NBFC, or other regulated sectors preferred
Upload your CV/resume or any other relevant file. Max. file size: 800 MB.