Mona Roy

CEO

India8 yrs 11 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 10 years of experience in data privacy and compliance.
  • Expertise in GDPR and various privacy regulations.
  • Strong background in risk management and information security.
Stackforce AI infers this person is a Data Privacy and Compliance Specialist with a strong focus on Risk Management.

Contact

Skills

Core Skills

Data Privacy ComplianceRisk ManagementResearch ManagementBusiness Development

Other Skills

Business StrategyCC++CCPACRM toolsClient CommunicationData Privacy impact AssessmentsGDPRHITRUSTHTMLISO 27001IT Security OperationsInformation SecurityInformation Security ManagementJava

About

I have over 10+ years of experience. I have been trained in the field of Data privacy Implementation, ISMS (ISO 27000: 2013) Implementation, Internal Audit, Cybersecurity, Governance and Risk Compliance, Risk Management. Good understanding of the Data Privacy domain, General Data Privacy Regulation, ITGC, HITRUST Validated Assessments, Security Compliance, etc. I have worked for major clients across various sectors such as Telecom, IT/ITES, Government, Manufacturing, Power, Oil and Gas, and Human Resources. She worked with clients from India, USA, UK, Middle East, and Southeast Asia

Experience

Ramboll

2 roles

Global Regulatory Partner

Promoted

May 2025Present · 10 mos · Gurugram, Haryana, India

Data Privacy Lead - India, Asia Pacific and Middle East

Oct 2022May 2025 · 2 yrs 7 mos · Gurugram, Haryana, India

Pwc

2 roles

Assistant Manager

Feb 2022Oct 2022 · 8 mos

Consultant

Apr 2019Feb 2022 · 2 yrs 10 mos

  • Data privacy compliance engagement for a leading global organizations wherein her role
  • involves designing data privacy compliance requirements for complex ERP transformation
  • looking into~ 20 privacy regulations like GDPR, CCPA, draft PDP bill, etc.
  • As a data privacy expert, delivered data privacy design recommendations across domains like
  • Access Management, Logging and Monitoring, Data Subject Rights, Data Minimization,
  • Consent, Cross Border Requirements, Data validation, etc.
  • Performed Data Privacy impact Assessments, prepared Data Privacy Consents and Data
  • Privacy Notices and gave consultation for the Cross Border Requirements.
  • Responsible for understanding of security and privacy environment for a leading
  • manufacturing organization and creating a data privacy policy and manual as per multiple
  • privacy regulatory requirements and provide project management services to the
  • organization to implement the same. Performed privacy gap assessment for GDPR
  • compliance.
  • Strong understanding of information security standards & frameworks (ISO27001) and IS
  • policy implementation and interpretation such as ISO 27001/2. Strong understanding of IT
  • Risks and IT General Controls for various organizations
  • Performed HITRUST validated assessment for a client on various domains like Access
  • management, Change Management, Asset Management, Physical Security and many more
  • Created Risk Compliance Matrix (RCM) by working on Risk Identification, Risk Impact
  • Assessment and controls to be implemented for the Telecom Clients. Drafted the Process
  • Flows Charts and Process narratives for the Clients
  • Drafted Risk assessment framework and conducted risk assessment and gap analysis for
  • various clients. Conducted vendor assessment for a number of banks and performed
  • checking and testing of general IT controls.
  • Established policies and procedures for Information Security for mid and large-scale
  • organizations incorporating the applicable frameworks and industry best practices.
Data privacy complianceGDPRCCPAData Privacy impact AssessmentsRisk ManagementISO 27001+2

Deloitte

Summer Intern

Apr 2018Jun 2018 · 2 mos · Mumbai, Maharashtra, India

  • Currently, I am working in the profile of Regulatory and Operational Risk of Risk Advisory department of Deloitte.

Egon zehnder

Research Analyst and Allocation Lead

Jul 2016Jun 2017 · 11 mos · Gurgaon, India

  • Developed a comprehensive knowledge base of companies and candidates across various industries, enhancing research capabilities.
  • Managed resource allocation and strategic assignment of projects for a team of 25 direct and 30 indirect researchers.
  • Delivered timely and accurate project outcomes through effective client communication and workflow management.
ResearchProject ManagementClient CommunicationResearch Management

Aspiring minds

Business Development Executive

Jul 2015Jul 2016 · 1 yr · Gurugram

  • Identified and engaged key decision-makers, fostering strong relationships with CHROs and VPs in various sectors.
  • Successfully drove sales and marketing campaigns, resulting in increased client acquisition and retention.
  • Demonstrated expertise in CRM tools like Hubspot, enhancing sales tracking and reporting efficiency.
  • Collaborated with top management to develop sales strategies, contributing to significant revenue growth.
SalesMarketingCRM toolsBusiness Development

Nec corporation

Summer Intern

Jun 2014Jul 2014 · 1 mo · New Delhi Area, India

  • I did my 4 weeks Internship on Microwave Transmission in Telecom Industry and Network Planning in various Circles.

Education

Symbiosis Institute of Digital & Telecom Management (SIDTM), Pune

Master of Business Administration - MBA Co-ordinator | Placements and Corporate Interface Team — Marketing and Finance

Jan 2017Jan 2019

KEC, Dwarahat

Bachelor’s Degree

Jan 2011Jan 2015

St. George's College, Mussoorie

High School

Jan 2006Jan 2010

Stackforce found 100+ more professionals with Data Privacy Compliance & Risk Management

Explore similar profiles based on matching skills and experience