Job Title: Director – Data Office & Privacy
Department: Data Office
About Business line/Function
Data Privacy function of ISPL helps the business comply with data privacy & protection regulations and instills trust in staff & clients while processing personal data. This is achieved through Data Privacy program governance, Local policy & procedure governance, and alignment to DPDPA & BNP Group led control requirements .
The next stage for this unit is to build Global services in Data Office at ISPL to provide critical high-value service delivery to CIB IT and Operations Data Office across various regions (EMEA, AMER & APAC) for activities including but not limited to : Transaction Reporting, Records and Data Management, Voice and EComs Record keeping and Data Quality.
Position Purpose
The role is the functional lead for ISPL Data Privacy & Data Office team.
For Data Privacy, the individual is accountable and the central point of accountability for design, implementation, and continuous improvement of ISPL’s privacy governance framework.
Key Focus Areas:
- Strategy alignment: Ensure Data Privacy Program strategic alignment with Group requirements.
- End-to-end privacy lifecycle: Risk-based assessment & mapping, control implementation & ongoing monitoring.
- Cross-functional leadership: Steer privacy initiatives & ensure execution of privacy-by-design principles.
- Team Leadership: Lead a team of privacy analysts and act as escalation point for privacy incidents, audit findings, and regulator enquiries.
For Data Office, the individual is responsible for building and leading a team of ~24 professionals (including Analysts, Control Officers, Project Coordinators, and Sr. Technologists) who act as a seamless extension of the onshore teams, with a strong business angle (leaning towards Global Markets activities).
Key Focus Areas:
- Operational Excellence: Driving "Run the Bank" activities (Incident Management, Control Execution, Reporting).
- Data Integrity: Managing the "Data Lifecycle" (Data Quality, Transactional Accuracy).
- Service Scaling: Building a high-performing, scalable team from the ground up in India.
- Compliance Support: Ensuring adherence to Transaction Reporting and Record-keeping regulations.
Responsibilities
I. On Data Privacy and Protection for ISPL
A. Governance
- Policy Management: Continuously monitor and update privacy policies, manuals, and procedures to reflect regulatory changes and best practices.
- Subject Matter Expertise: Ensure ISPL alignment with Group, CIB, and Regulator requirements.
- Impact Assessments: Provide expert opinions on GDPR data protection sections; lead privacy assessments such as PDPQ, DPIA, and TIAQ.
- Regulatory Compliance: Review and ensure strict compliance with the India DPDP Act.
- Privacy by Design: Proactively identify improvements to the current framework and support stakeholders as an SME.
- Stakeholder Management: Drive and participate in Data Privacy & Protection committees; maintain an efficient network across 1LoD and 2LoD.
- Regulatory Watch: Maintain a continuous watch on data protection trends and disseminate a culture of protection within ISPL.
B. Privacy Risk Management
- Risk Assessment: Complete annual risk assessments for the privacy compliance program.
- Project Integration: Lead Privacy Impact Assessments for new technologies, products, and projects to embed mitigations before launch.
- Audit & Inspection: Liaise with Controls teams to support internal audits and regulator inspections, delivering required artefacts and corrective action plans.
- Risk Mitigation: Identify and monitor data-management, privacy, and record-management risks across the enterprise.
C. Privacy Program Effectiveness
- Operational Calendar: Develop an annual calendar for activities (e.g., RoPA recertification, policy reviews).
- Reporting: Support the Program Lead in preparing data-driven management reports for senior leadership and board committees.
- KPI Management: Establish and report privacy KPIs via a scorecard to measure program maturity.
D. Contributing Responsibilities
- Strategic Advice: Advise on privacy and data-ethics considerations for new business initiatives.
- Awareness: Drive Data Privacy & Protection Awareness programs tailored for both technical and non-technical audiences.
- Emerging Risks: Proactively identify risks related to new technologies (AI/ML, cloud services).
II. On Data Office Services (team responsibilities)
A. Operational Oversight & Incident Management (VERK, RMO, Reporting)
- Control Execution & Reporting: Oversee the execution and reporting of core controls for Transaction Reporting (MiFID, EMIR, etc.), RMO, and VERK. Ensure all results are accurately logged in relevant tools such as ServiceNow or ORUS.
- Incident & Problem Control: Drive adherence to robust incident management frameworks. Perform materiality assessments, escalate breaches, and manage the end-to-end resolution process.
- Root Cause Analysis (RCA): Perform deep-dive investigations into recurring issues, implementing corrective actions to address root causes through a strong data-handling approach.
- Knowledge Management: Own and improve the team’s knowledge base for past incidents, root causes, and remedial actions to foster a culture of continuous improvement.
B. Data Quality & Technical Oversight
- Data Integrity: Implement and monitor data quality metrics to identify trends, anomalies, or systemic issues in regulatory reporting and record-keeping workflows.
- Process Automation: Identify opportunities for process improvements and drive automation (e.g., via SQL, Python, or scripting) to increase efficiency and reduce manual tasks.
C. Project Coordination & Change Delivery
- Project Management: Coordinate the planning, execution, and delivery of key initiatives (Change the Bank) and control framework enhancements.
- Governance Support: Prepare, maintain, and enhance project documentation, governance materials, status reporting, RAID logs, action trackers, meeting materials, & decision records to ensure traceability for onshore
Specific Qualifications:
Technical Competencies
- Experience: 18 – 25 years of experience in Data Privacy, Data Governance, Regulatory Operations, Compliance Control, Finance roles (Global Markets preferred). Proven track record of building and scaling large, multi-disciplinary teams (~20+ FTEs).
- Legal and Regulatory Knowledge: Strong understanding of privacy laws (GDPR, India DPDP Act). Knowledge of the Philippines Data Protection Act is an advantage. Familiarity with financial regulations (MiFID, EMIR, etc.) and record-keeping requirements is a strong advantage.
- Certifications: Professional qualification preferred (e.g., CIPP / CIPM, Data Protection Practitioner).
- Background: Information Security and Technology, and Data Management. Business role experience (Global Markets preferred). Ability to manage and challenge technical teams specialized in SQL, Python, Data Analytics.
Behavioral & Transversal Skills
- Communication: Excellent interpersonal and verbal communication skills; ability to simplify complex technical concepts and regulatory issues for diverse stakeholders.
- Analytical Skills: High attention to detail & rigor and a strong problem-solving mindset for Root Cause Analysis.
- Leadership: Ability to manage projects, facilitate meetings/committees, and lead a large, multi-disciplinary team in a matrixed environment.
- Mindset: Self-starter, independent, results-driven, creative problem solver and capable of driving continuous process automation and efficiency.
Education Level: BSc. / B.E. / B.Tech is ideal. MSc. is a strong advantage.
Location: Mumbai
About BNP Paribas Group:
BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporate and institutional clients) to realize their projects through solutions spanning financing, investment, savings and insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.
About BNP Paribas India Solutions:
Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.
Commitment to Diversity and Inclusion
At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.