# Data Protection Consultant

> Weekday AI · Mumbai, India · Full-time · Posted 2026-09-10

**Workplace:** on_site

**Department:** Weekday's Client via platform

## Description

**This role is for one of Weekday’s clients**

  
Min Experience: 2+ years  
Location: Mumbai, Maharashtra, India  
JobType: full-time

We are looking for a **Data Protection Consultant** with a minimum of **2 years of hands-on experience in Data Privacy and Data Protection**, with strong practical exposure to **Records of Processing Activities (ROPA)** and **Data Protection Impact Assessments (DPIA)**.

The ideal candidate should have experience working on privacy compliance programs, risk and gap assessments, privacy documentation, and regulatory requirements such as **GDPR, India’s DPDPA, and CCPA**.

## Requirements

**Key Responsibilities**

Design, implement, and support **Privacy and Data Protection Programs** for clients.

Independently prepare, review, and maintain **Records of Processing Activities (ROPA)**.

Conduct **Data Protection Impact Assessments (DPIA)** and identify privacy risks and appropriate mitigation measures.

Conduct privacy **risk assessments, gap assessments, audits, and compliance reviews**.

Perform data privacy assessments across business processes, systems, applications, and third-party relationships.

Work with information security and privacy frameworks including **ISO 27001, ISO 27701, NIST, and HITRUST**.

Advise internal teams and clients on privacy regulations including **GDPR, DPDPA, and CCPA/CPRA**.

Draft and review privacy policies, procedures, assessment reports, compliance documentation, and implementation roadmaps.

Assist organizations with establishing and improving privacy governance frameworks.

Support **cybersecurity governance and ISMS documentation**.

Identify privacy and security compliance gaps and recommend remediation measures.

Work with stakeholders across Legal, IT, Information Security, Compliance, HR, and business functions.

Support client meetings, workshops, assessments, and privacy-related consulting engagements.

**Mandatory Requirements**

Minimum **2 years of relevant experience** in Data Privacy, Data Protection, Information Security, GRC, or related domains.

**Hands-on experience in ROPA is mandatory.**

**Hands-on experience in conducting DPIAs is mandatory.**

Good working knowledge of **GDPR**.

Working knowledge of **India's DPDPA and CCPA/CPRA**.

Understanding of privacy risk assessments, gap assessments, and compliance audits.

Knowledge of privacy principles, data lifecycle, data processing activities, and privacy risk management.

Familiarity with **ISO 27001 and ISO 27701**.

Strong documentation, analytical, communication, and stakeholder-management skills.

Ability to prepare professional reports, policies, assessment documents, and compliance roadmaps.

**Preferred Skills**

Exposure to **NIST and HITRUST** frameworks.

Experience working in a consulting or client-facing environment.

Understanding of cybersecurity governance and ISMS.

Experience with privacy management or GRC tools will be an added advantage.

Experience conducting privacy workshops and stakeholder interviews.

**Preferred Certifications**

Candidates holding one or more of the following certifications will be preferred:

**CIPM – Certified Information Privacy Manager**

**CIPP/E – Certified Information Privacy Professional/Europe**

**CIPT – Certified Information Privacy Technologist**

ISO 27001 / ISO 27701 certifications will be an added advantage.

**Ideal Candidate**

We are particularly interested in candidates who have **actually prepared ROPAs and conducted DPIAs as part of their current or previous roles**, rather than candidates with only theoretical knowledge of these activities.

The candidate should be comfortable explaining:

How a ROPA is created and maintained.

What information is collected from business/process owners for a ROPA.

When a DPIA is required.

How privacy risks are identified and assessed during a DPIA.

How remediation and risk mitigation actions are documented and tracked.

How GDPR/DPDPA requirements are translated into practical organizational controls.

Must-have skills

data protection, GDPR, Data Protection Impact Assessment

Good-to-have skills

Data Privacy, Records of Processing Activities

## Apply

[Apply at Weekday AI](https://apply.workable.com/weekday-1/j/8A6256B605/apply)

---
Powered by [Workable](https://www.workable.com)
