JOB DESCRIPTION
The AVP – Data Privacy by Design role will lead privacy team operations and processes and work closely with the Legal, Product, Global Technology, Cyber Security, Policy and Commercial functions.
- Monitor compliance and data practices to ensure the business and its products comply with applicable contractual obligations and privacy regulations, including GDPR, CCPA, CPRA, COPPA, and emerging AI privacy laws.
- 2.Enable innovation by advising the Product team on privacy and data use to enable EXL to continue as the standard for the most secure, privacy-compliant, and independently evaluated media authentication company globally.
- 3. Drive AI Governance and adoption through frameworks for safe and responsible AI use that balance risk and business goals to drive the organization’s AI strategy
JOB RESPONSIBILITIES
- Lead EXL’s global privacy program, including Privacy by Design (PbD), Privacy Enhancing Technologies (PETs), and enterprise privacy governance initiatives.
- Partner with the AI Governance Committee to establish and maintain privacy frameworks, policies, and controls that support responsible AI adoption and regulatory compliance.
- Develop, implement, and maintain privacy governance standards aligned with global regulations, including GDPR, CCPA, CPRA, COPPA, and emerging AI and data protection requirements.
- Serve as the primary privacy advisor to business, product, technology, legal, and operational stakeholders on data use, privacy risk, and compliance matters.
- Drive Privacy by Design and Privacy by Default practices across products, applications, and data-driven business processes.
- Conduct and oversee Data Protection Impact Assessments (DPIAs), Privacy Impact Assessments (PIAs), and privacy reviews for new products, technologies, and processing activities.
- Maintain global privacy policies, procedures, and standards to address evolving regulatory and business requirements.
- Review and negotiate privacy-related provisions in customer, partner, and vendor agreements in partnership with Legal and Information Security teams.
- Lead privacy risk assessments, vendor reviews, and third-party data protection evaluations to ensure appropriate controls are implemented.
- Monitor and interpret global privacy regulations and emerging legislative developments, assessing business impact and recommending remediation strategies.
- Maintain and expand privacy certifications and accreditation programs, including ISO 27701, APEC CBPR, APEC PRP, and Data Privacy Framework requirements.
- Partner with Cyber Security teams to maintain records of processing activities, data inventories, data mapping, data flows, and third-party processing activities.
- Support enterprise data governance efforts by ensuring appropriate controls for data retention, destruction, minimization, and lawful processing.
JOB QUALIFICATIONS
- Hold at least one Data Protection and/or Privacy certification such as CIPP/US, CIPP/E, CIPM, CIPT, or equivalent (preferred)
- 10-15 years of progressive experience in data privacy and protection, with at least 3-5 years in a leadership role
- Experience with U.S. and EU data privacy laws (GDPR, CCPA, CPRA, COPPA) and emerging AI privacy regulations
- Multiple years' experience within a compliance, legal, audit and/or risk function, with substantial experience in privacy compliance
- Experience in developing policy and compliance training programs
- Experience serving as Data Protection Officer or in similar senior privacy capacity preferred
- Background in technology companies, particularly in digital advertising, adtech, martech, or fraud detection industries strongly preferred
- Travel: Willingness to travel as needed for business purposes, including regulatory meetings, audits, industry conferences, and team collaboration