Data Protection Consultant
Weekday AI · Mumbai, Maharashtra, India
About The Role
# Data Protection Consultant
> Weekday AI · Mumbai, India · Full-time · Posted 2026-09-10
**Workplace:** on_site
**Department:** Weekday's Client via platform
## Description
**This role is for one of Weekday’s clients**
Min Experience: 2+ years
Location: Mumbai, Maharashtra, India
JobType: full-time
We are looking for a **Data Protection Consultant** with a minimum of **2 years of hands-on experience in Data Privacy and Data Protection**, with strong practical exposure to **Records of Processing Activities (ROPA)** and **Data Protection Impact Assessments (DPIA)**.
The ideal candidate should have experience working on privacy compliance programs, risk and gap assessments, privacy documentation, and regulatory requirements such as **GDPR, India’s DPDPA, and CCPA**.
## Requirements
**Key Responsibilities**
Design, implement, and support **Privacy and Data Protection Programs** for clients.
Independently prepare, review, and maintain **Records of Processing Activities (ROPA)**.
Conduct **Data Protection Impact Assessments (DPIA)** and identify privacy risks and appropriate mitigation measures.
Conduct privacy **risk assessments, gap assessments, audits, and compliance reviews**.
Perform data privacy assessments across business processes, systems, applications, and third-party relationships.
Work with information security and privacy frameworks including **ISO 27001, ISO 27701, NIST, and HITRUST**.
Advise internal teams and clients on privacy regulations including **GDPR, DPDPA, and CCPA/CPRA**.
Draft and review privacy policies, procedures, assessment reports, compliance documentation, and implementation roadmaps.
Assist organizations with establishing and improving privacy governance frameworks.
Support **cybersecurity governance and ISMS documentation**.
Identify privacy and security compliance gaps and recommend remediation measures.
Work with stakeholders across Legal, IT, Information Security, Compliance, HR, and business functions.
Support client meetings, workshops, assessments, and privacy-related consulting engagements.
**Mandatory Requirements**
Minimum **2 years of relevant experience** in Data Privacy, Data Protection, Information Security, GRC, or related domains.
**Hands-on experience in ROPA is mandatory.**
**Hands-on experience in conducting DPIAs is mandatory.**
Good working knowledge of **GDPR**.
Working knowledge of **India's DPDPA and CCPA/CPRA**.
Understanding of privacy risk assessments, gap assessments, and compliance audits.
Knowledge of privacy principles, data lifecycle, data processing activities, and privacy risk management.
Familiarity with **ISO 27001 and ISO 27701**.
Strong documentation, analytical, communication, and stakeholder-management skills.
Ability to prepare professional reports, policies, assessment documents, and compliance roadmaps.
**Preferred Skills**
Exposure to **NIST and HITRUST** frameworks.
Experience working in a consulting or client-facing environment.
Understanding of cybersecurity governance and ISMS.
Experience with privacy management or GRC tools will be an added advantage.
Experience conducting privacy workshops and stakeholder interviews.
**Preferred Certifications**
Candidates holding one or more of the following certifications will be preferred
**CIPM – Certified Information Privacy Manager**
**CIPP/E – Certified Information Privacy Professional/Europe**
**CIPT – Certified Information Privacy Technologist**
ISO 27001 / ISO 27701 certifications will be an added advantage.
**Ideal Candidate**
We are particularly interested in candidates who have **actually prepared ROPAs and conducted DPIAs as part of their current or previous roles**, rather than candidates with only theoretical knowledge of these activities.
The candidate should be comfortable explaining
- How a ROPA is created and maintained.
- What information is collected from business/process owners for a ROPA.
- When a DPIA is required.
- How privacy risks are identified and assessed during a DPIA.
- How remediation and risk mitigation actions are documented and tracked.
- How GDPR/DPDPA requirements are translated into practical organizational controls.
- Must-have skills
- data protection, GDPR, Data Protection Impact Assessment
- Good-to-have skills
Data Privacy, Records of Processing Activities
## Apply
[Apply at Weekday AI](https://apply.workable.com/weekday-1/j/8A6256B605/apply)
---
Powered by [Workable](https://www.workable.com)
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
