Assoc. Director - Head Of Enterprise Data Privacy
CurrentAs the leader of the enterprise data privacy program, responsible for developing, implementing, and overseeing a comprehensive privacy framework aligned with regulatory requirements and best practices.Led the creation and expansion of the bank's data privacy program from the ground up, ensuring protection of customer and employee data across all business units.Built the enterprise data privacy program from scratch, aligning the bank’s privacy posture with relevant data protection laws and internal risk management standards.Designed and implemented privacy processes and procedures across data collection, processing, retention, and disposal, improving operational efficiency and compliance.Developed and deployed a robust Data Subject Access Request (DSAR) program, ensuring prompt and compliant responses to customer data access, deletion, and rectification requests.Established a Data Protection Impact Assessment (DPIA) program, including guidelines, templates, and workflows for assessing privacy risks in new projects, systems, and third-party vendor engagements.Led a comprehensive overhaul of the bank’s records management program, implementing data retention schedules, data classification schemes, and secure storage solutions to reduce exposure to regulatory fines and improve operational efficiency. Partnered with legal, IT, risk, compliance, and business units to embed privacy-by-design principles in product development, marketing, and other core business activities.aSpearheaded organization-wide privacy training and awareness programs, increasing employee engagement and compliance with data protection policies.Conducted regular privacy audits and risk assessments, identifying gaps in compliance and recommending corrective actions to ensure ongoing adherence to privacy laws and internal policies.