SMBC Group

Data Protection (Techno-Legal)

SMBC Group  •  Republic of India (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Headquartered in Tokyo, Sumitomo Mitsui Banking Corporation (SMBC) is a leading global financial institution and a core member of Sumitomo Mitsui Financial Group (SMBC Group). Built upon our rich Japanese heritage since 1876, we put our customers first and provide seamless access to, from and within the Asia Pacific region. SMBC is one of the largest Japanese banks by assets and maintain strong credit ratings across our global integrated network. We work closely as one SMBC Group to offer personal, corporate and investment banking services to meet the needs of our customers.

With sustainability embedded within our strategy and operations, we are committed to creating a society in which today’s generation can enjoy economic prosperity and well-being, and pass it on to future generations.

Primary Responsibilities

(These are the key work activities to achieve the position objective. Limit this section to essential responsibilities.)

Percentage (%) of

Time Spent

Secondary Responsibilities

(List of duties that are marginal or infrequent.)

  1. Support privacy legal and regulatory research, including review of applicable data protection requirements, regulatory developments and internal compliance obligations; prepare structured summaries and implementation trackers for DPO review.

20%

Maintain regulatory reference materials, obligation registers and supporting records.

  1. Assist in drafting and periodic review of privacy policies, procedures, consent wording, privacy notices, forms, internal guidance and other privacy-related legal documentation.

20%

Support version control, approvals, publication and evidence maintenance.

  1. Support review of contracts, data processing clauses, confidentiality terms and third-party privacy requirements in coordination with Legal, Procurement, Information Security and relevant business teams.

15%

Maintain review comments, issue logs and closure evidence.

  1. Conduct or support Privacy Impact Assessments / DPIAs for new or changed products, processes, systems and technologies, including identification and documentation of legal and technology-related privacy risks.

15%

Track mitigations, owners, target dates and residual risks for DPO oversight.

  1. Support data flow mapping, data inventory, records of processing and review of personal data collection, use, storage, sharing, retention and disposal across systems and processes.

15%

Coordinate information collection and maintain supporting documentation.

  1. Participate in privacy-by-design reviews for technology projects and change initiatives; assess whether privacy requirements are appropriately reflected in system and process design.

10%

Document observations and follow up action items with relevant stakeholders.

  1. Support privacy incident assessment, data subject request / grievance handling, awareness activities and periodic DPO reporting.

5%

Maintain case files, trackers, dashboards and governance meeting inputs.

Total

100%

  • Knowledge Requirements: Working knowledge of data protection and privacy requirements, legal research, contract and policy review, technology systems, data lifecycle concepts, privacy-by-design, DPIA / PIA, data subject rights, grievance handling and basic information security controls.
  • Specialist / technical skills: Legal and regulatory research; drafting and document review; contract clause review; data flow mapping; privacy assessment; technology risk understanding; issue tracking; Microsoft Office and structured record management. Familiarity with privacy management or GRC tools is desirable.
  • Behavioural / management skills: Analytical thinking, attention to detail, written and verbal communication, documentation discipline, stakeholder coordination, confidentiality, ownership and ability to work under the guidance of the DPO.
  • Education & Qualifications: Relevant graduate or post-graduate qualification. A combined legal and technology background is preferred. Relevant privacy, technology or security certification may be desirable.
SMBC Group

About SMBC Group

SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 150 offices and 120,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, one of the three largest banking groups in Japan. SMFG's shares trade on the Tokyo and Nagoya stock exchanges, and its ADRs trade on the New York Stock Exchange (NYSE: SMFG).

Americas: https://www.smbcgroup.com/

EMEA: https://www.smbcgroup.com/emea/

APAC: https://www.smbc.co.jp/asia/

Tokyo: https://www.smfg.co.jp/english/

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
Tokyo, JP
Year Founded
Unknown
Website
co.jp
Social Media