Professional Summary
Overview
Work History
Education
Skills
Disclaimer
Timeline

DUDEKULA AHAMMAD BASHA

HCL Technologies
Hyderabad
7
years of professional experience

Experienced IT Governance, Risk, and Compliance professional with over 6+ years in Third-Party Risk Management, ISO 27001 implementation, and regulatory compliance. Expertise in GDPR and India's Digital Personal Data Protection Act, focusing on privacy impact assessments, data mapping, and consent management. Knowledgeable in PCI DSS, HIPAA, HITRUST, NIST CSF, and SOC audits, delivering effective risk mitigation and enhanced information security.

Work History

Security Analyst

2 Years 3 Months
HCL Technologies | 03.2024 - 06.2026

Data Privacy & Protection (GDPR / DPDP Act)

  • Led GDPR and DPDP Act, 2023 compliance initiatives — performed gap assessments, defined remediation roadmaps, and tracked closure of privacy findings.
  • Conducted Data Protection Impact Assessments (DPIAs) and Privacy Impact Assessments for new systems and vendors to identify privacy risks and ensure compliance.
  • Built and maintained Records of Processing Activities (RoPA) and data flow maps covering personal data collection, storage, transfer, and retention.
  • Implemented privacy-by-design controls, consent management practices, and processes for handling data subject / data principal rights requests (access, correction, erasure).
  • Reviewed Data Processing Agreements (DPAs) and evaluated cross-border data transfer safeguards with third parties.
  • Supported data breach response procedures, including assessment of notification obligations under GDPR and the DPDP Act. Information Security
  • Designed, implemented, and maintained the organization's information security framework to protect sensitive information, systems, and infrastructure from cyber threats.
  • Performed threat detection, risk assessments, and vulnerability assessments; coordinated remediation with IT teams.
  • Supported incident response activities — triage, containment, root-cause analysis, and post-incident reporting.
  • Delivered organization-wide security and privacy awareness training. Governance, Risk & Compliance (GRC)
  • Developed and implemented comprehensive IT governance frameworks aligned with organizational objectives and regulatory requirements.
  • Conducted risk assessments to identify, evaluate, and mitigate potential IT risks; maintained GRC tools to streamline risk and compliance management.
  • Drafted, updated, and enforced IT policies, procedures, and controls to meet industry standards and best practices.
  • Led ISO 27001 implementation projects — gap analyses, control selection, risk treatment plans, Statement of Applicability, and ISMS documentation.
  • Conducted internal audits for ISO 27001 compliance and prepared the organization for external certification audits. Third-Party Risk Management (TPRM)
  • Evaluated third-party compliance with security and privacy regulations, ensuring alignment with ISO 27001, PCI DSS, GDPR, and the DPDP Act.
  • Designed and executed vendor risk assessment frameworks for onboarding and continuous monitoring of third party relationships.
  • Monitored third-party risk postures through questionnaires, audits, and vulnerability assessments; developed remediation plans and ensured follow-through to resolution.

Data Privacy Analyst

2 Years 5 Months
Infosys Ltd. | 09.2021 - 02.2024
  • Drafted, reviewed, and updated Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs), ensuring alignment with GDPR, CCPA, and other global data privacy regulations.
  • Conducted Data Protection Impact Assessments (DPIAs) to identify and mitigate privacy risks in personal data processing. Implemented internal data privacy policies and training programs, enhancing employee awareness and ensuring legal compliance.
  • Acted as the primary point of contact for handling Data Subject Access Requests (DSARs) across APAC and EMEA regions in compliance with regulatory timelines. Liaised with cross-functional teams including Legal, IT, HR, and Procurement to ensure privacy-by-design principles were embedded in systems and processes.
  • Led privacy risk assessments and supported audit readiness by maintaining accurate data inventories and data flow mapping using governance tools. Supported incident response and breach handling with cybersecurity and legal teams, ensuring timely containment and compliance with regulatory reporting requirements.
  • Monitored global privacy regulations (GDPR, HIPAA, DPDPA, CCPA, CPRA) and advised stakeholders on policy updates, ensuring organizational alignment with evolving compliance standards.
  • Collaborated with product development teams to assess privacy Details basha16041997@gmail.co m kurnool, India, (+91) 7799135219 Skills GDPR Vendor Risk & Third-Party Assessments Data Protection Impact Assessments (DPIA) Privacy by Design Internal Auditing Risk Management IT Governance ISO 27001 Languages English Hindi requirements in new solutions, advising on controls related to user consent, retention, and lawful processing. Conducted internal audits and vendor privacy assessments to evaluate compliance posture, including sub processors and third-party data handling practices. Participated in the rollout of centralized privacy management systems to standardize practices across global operations.

Software Engineer

1 Year 7 Months
Capgemini | 03.2019 - 10.2020
  • Conducted Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) to identify and mitigate privacy risks across business processes and technologies.
  • Implemented global data protection frameworks (GDPR, CCPA, ISO 27701) by aligning policies, controls, and procedures with regulatory requirements. Reviewed and drafted Data Processing Agreements (DPAs), vendor contracts, and privacy notices to ensure compliance with data protection obligations. Managed Data Subject Access Requests (DSARs) to ensure timely and compliant responses under applicable regulations. Partnered with product, IT, and legal teams to embed Privacy by Design
  • principles in new projects, systems, and applications. Monitored and audited data lifecycle management practices, including collection, storage, retention, and deletion, to maintain compliance.
  • Supported privacy audits and regulatory assessments, preparing evidence and documentation for internal and external stakeholders.
  • Conducted privacy awareness training for employees to foster a culture of compliance and accountability across the organization.

Education

GED

KSRM College Of Engineering | Kadapa, India | 04-2018

Skills

Data privacy management
• Information security management • IT Governance
Risk
and Compliance (ITGRC)
Third-party risk management
ISO compliance management
SOX compliance testing
Incident response
ISMS development
Compliance certification processes
Cybersecurity framework audits
Risk assessment development
Security & Privacy Awareness Training

Disclaimer

I hereby declare that the above-mentioned information is correct up to my knowledge.                                                                (Basha)

Timeline

Security Analyst

HCL Technologies
03.2024 - 06.2026Read More

Data Privacy Analyst

Infosys Ltd.
09.2021 - 02.2024Read More

Software Engineer

Capgemini
03.2019 - 10.2020Read More

KSRM College Of Engineering

GED
Read More
DUDEKULA AHAMMAD BASHA