Abhiwaqti Gupta

Business Analyst

Bengaluru, Karnataka, India9 yrs 9 mos experience
AI Enabled

Key Highlights

  • Expert in GDPR compliance and data protection strategies.
  • Proven track record in developing privacy policies and training programs.
  • Strong understanding of global data privacy laws and regulations.
Stackforce AI infers this person is a Data Privacy and Compliance Specialist with expertise in GDPR and global data protection regulations.

Contact

Skills

Core Skills

Data PrivacyPrivacy LawGdpr

Other Skills

Privacy ActDPDPPersonal Data ProtectionData Privacy Best PracticesData Protection ActGeneral Data Protection Regulation (GDPR)Privacy Accountability FrameworkPrivacy Policies and ProceduresGovernanceResponsible AIEmployee Data Privacy RiskRoPAData Processing Agreements (DPAs)Supplier Assessment and Contractual ReviewIncident & Breach Management

About

I am a Legal and Data Privacy professional presently working as Data Protection Officer with Odessa Have experience of working on regulatory requirement such as GDPR compliance framework, Privacy Impact Assessment (PIA), PIPL Assessments in China and Record of Processing Activity (RoPA). HR business policies and operations to align with privacy requirements and regulations for the protection of worker personal data. Responsible not only for analysis but also for assisting with developing strategies for improvement. Comprehensive understanding and working experience of global data privacy laws and regulations, including GDPR, PIPLs, CCPA and preparedness for upcoming regulations such as Vietnam, India etc. by conducting data mapping activity, assessing high risk processes and incorporating the Privacy by design requirements into organizations workflow. Skills: Critical Thinking · Privacy Accountability Framework · Privacy Policies and Procedures · Governance · Responsible AI · Employee Data Privacy Risk · RoPA · Data Processing Agreements (DPAs) · Supplier Assessment and Contractual Review · Incident & Breach Management · Data Subject Requests and Training & Awareness programs.

Experience

9 yrs 9 mos
Total Experience
2 yrs 5 mos
Average Tenure
0 mo
Current Experience

Quess corp limited

Deputy Data Protection & Privacy Officer

Apr 2026Present · 0 mo · Bengaluru · On-site

  • Supporting the privacy program for Quess & its group companies in the APAC region, Middle East, Singapore, Malaysia, Vietnam and Sri Lanka, including processes, procedures and initiatives, and collaborate with other departments and practices in support of the privacy program. Promote a culture of data protection and compliance across all units of the organization.
  • Responsibilities
  • Serves as primary point of contact for Data Privacy related program, queries, coordinating with internal stakeholders & regulatory authorities
  • Research and legal monitoring of new and revised data privacy regulations in India, APAC , Middle East and NA region
  • Respond to requests for data privacy advice from the business, including assisting in responding to prospect and customer data protection questionnaires
  • Drafting of relevant data privacy & ISMS policies and with identifying any gaps in policies/procedures based on regulations and recommend prioritization of addressing gaps
  • Privacy trainings and awareness programs
  • Implementation of the Vendor Risk Management Program, Data Protection Impact Assessments (where required) & Privacy-by-Design
  • Maintain organisation’s Records of Processing Activities, where required
  • Negotiate local and international data sharing agreements and assisting with local and international contract analysis to ensure that data privacy and protection objectives are adequately addressed
  • Manage and centralizing Data Subject Access Requests (DSARs) and other requests from data subjects residing in the respective region
  • Advise on the response to data privacy incidents, including corrective and preventative actions
  • Monitor implementation of data privacy recommendations made under Data Protection Impact Assessments
Data PrivacyPrivacy LawPrivacy ActDPDPPersonal Data Protection

Women data protection foundation

Vice Chair Mason - Chapters

Jan 2026Present · 3 mos

Odessa

Data Protection Officer

Oct 2023Apr 2026 · 2 yrs 6 mos · Bangalore Urban · Hybrid

  • Develop and implement the company's data protection and privacy policies in line with applicable laws and regulations, such as GDPR, CCPA, or other regional data protection laws.
  • Monitor and assess the company's data processing activities, ensuring compliance with data protection policies and procedures.
  • Conduct data protection impact assessments (DPIAs) for new projects, initiatives, or changes to existing processes.
  • Collaborate with cross-functional teams, including IT, legal, HR, marketing, and product development, to embed data protection into various business processes.
  • Conduct regular audits and compliance checks to identify potential risks and areas for improvement in data protection practices.
  • Develop and deliver data protection training and awareness programs for employees to foster a privacy-conscious culture.
  • Stay up-to-date with changes in data protection regulations and best practices and ensure the company's policies and procedures.
  • Act as the point of contact for supervisory authorities and data protection regulators regarding data protection compliance matters.
  • Oversee data breach response and incident management processes, ensuring timely reporting and resolution.
  • Prepare and submit data protection reports to executive management and relevant stakeholders.
  • Collaborate with third-party vendors and service providers to ensure they meet the company's data protection standards.
  • Facilitate training sessions and workshops for staff members.
Data PrivacyData Privacy Best PracticesData Protection ActPrivacy LawPersonal Data ProtectionGeneral Data Protection Regulation (GDPR)+1

Intel corporation

Privacy Specialist

Nov 2018Nov 2023 · 5 yrs · Bengaluru Area, India · Hybrid

  • As a Privacy Specialist, responsible for evaluating privacy impacts and driving mitigation strategies to ensure Intel is compliant with global data protection laws. Responsibilities include:
  • Partners with peers to articulate and drive privacy requirements in data inventory and mapping initiates
  • Conduct privacy assessments of business processes, practices, products and services.
  • Analyze and interpret privacy-related legislation and regulatory requirements and driving updates/decisions for internal policies and/or guidelines.
  • Contribute to the definition, development, implementation and maintenance of corporate privacy compliance requirements.
  • Provide subject matter expertise in the area of privacy and security, keeping abreast of new developments and best practices
  • Act as a primary point of contact for engaging privacy office and respond to policy questions, privacy consultations, etc
  • Support the Privacy Incident Management and Response process. Ensure reliable and prompt initiation of Privacy Incident Response when an incident or event is reported to the privacy office that are determined to be highly likely to involve Personal Information.
  • As part of DSR requirement, responding to inquiries, individual data subject requests (including GDPR requests) and complaints, from initial receipt, through to response completion and recording of the engagement.
General Data Protection Regulation (GDPR)GDPR

Sterling talent solutions

Privacy Manager

Feb 2018Oct 2018 · 8 mos · Mumbai, Maharashtra, India

  • Manager, Privacy (APAC) overseeing all ongoing activities related to the development, implementation, maintenance of, and adherence to the organization’s privacy policies and procedures.
  • Supporting global regions to standardize privacy strategies in APAC.
  • Engaging with key stakeholders to proactively address privacy matters, as well as effectively respond to privacy issues that are relevant.
  • Participating in conducting risk assessments with key internal stakeholders.
  • Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration or destruction of customer information or customer information systems.
  • Assess the likelihood and potential damage of these threats, taking into consideration the sensitivity of the personal data.
  • Responding to, investigating and resolving privacy-related inquiries and complaints from data subjects, clients, employees, etc.
General Data Protection Regulation (GDPR)GDPR

Vodafone

2 roles

Privacy Consultant

Jan 2017Jan 2018 · 1 yr

  • Supported the GDPR roll out by Initiating kick-off meetings, aligning local Privacy policy to the group Privacy Management Policy, supporting training of GDPR SPOCs and assisting in getting the Data Processing Registers filled by each vertical to identify the High Risk Process and to conduct a Privacy Impact Assessment for them.
  • Supported and assisted the Group Legal and Privacy Managers in reviewing and revising the existing Inter-Company Agreements. As a part of GDPR conducting gap analysis of the existing INCA DPAs.
  • Lead assessor for VSSI for conducting PIA - activities included analysis of the compliance report, review of business case and transaction documents (e.g. service specification, project plans, applications, agreements).
  • Provided support in conducting BS 10012: 2009 Re-Certification Audit for all VISPL locations (Pune & Ahmedabad) and ensuring 100% compliance with the existing BS Standards.
  • Conducted Joint Privacy & Legal Contractual Review for all the vendors of the company, across different locations in India.
  • Reviewed and analyzed the Data Protection and Privacy Policy and Data Management and Retention Policy of the company and revised it to align it with the Vodafone Group’s and VSS standards.
  • Conducted Refresher Training for Data Protection & Privacy for different Business & Corporate verticals including presentation preparation of induction material. Also conducted Training Sessions for all the SPOC in accordance with the specification for Personal Information Management System.
  • Reviewed and drafted commercial and transaction documents, namely - Master Services Agreements, Contractor Services agreements, Services Agreements, Inter-Company Agreements, Memorandum of Understanding and Non–Disclosure Agreements.
General Data Protection Regulation (GDPR)GDPR

Management Trainee

May 2016Jan 2018 · 1 yr 8 mos

  • Data Protection and Privacy
  •  Worked on Global Data Protection laws such as The UK Data Protection Act 1998, European Union Directives and Safe Harbour Principles.
  •  Assisted in Researches under the Information Technology Act, 2000
  •  Part of Data Protection and Information Security Projects
  •  General legal advisory on Data Protection related issues.
  • Contracts / Agreements and Policies
  •   Negotiating terms of Contracts with various vendors
  •  Instituting Data Protection and Privacy clauses in Standard templates and Contracts
  •  Reviewed/ Revised /standardised Confidentiality Agreement.
  •  Assisted in drafting / reviewing Contracts and Agreements customized to vendor needs
General Data Protection Regulation (GDPR)GDPR

Chir amrit law chambers

Intern

Oct 2015Nov 2015 · 1 mo · Jaipur Area, India

  • Worked on Due diligence transactions and on company documents such as Memorandum of Association, Articles of Association. Prepared Legal summaries related to the companies activities. Drafted Notes and Legal opinion and Delivered a presentation on “An Analysis of Indian Mining”
  • Further assisted on research issued under the following Acts:
  • 1. Partnership Act
  • 2. Companies Act
  • 3. FSSAI Act
  • 4. Micro, Small and Medium Enterprises Act

J. sagar associates

Intern

Oct 2013Nov 2013 · 1 mo · Mumbai Area, India

  • Worked on due diligence transactions and on company documents such as, Memorandum of Association, Articles of Association, Board Resolutions, General Meeting Resolutions and Prepared Summaries of many different agreement related to a company transaction in different due diligence.
  • Further assisted on research issues under:
  • 1. Companies Act, 2013
  • 2. Property Law
  • 3. Indian Contract Act

Education

Christ University, Bangalore

Bachelor's degree

Jan 2011Jan 2016

St. Patricks, Jodhpur, Rajasthan

Jan 1996Jan 2011

Stackforce found 100+ more professionals with Data Privacy & Privacy Law

Explore similar profiles based on matching skills and experience