Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Languages
Timeline
Generic

Gitanjali Bose

Pune

Summary

Proactive Data Privacy Professional with 7 years of experience specializing in Privacy and Data Protection, Third-Party Risk Management (TPRM), Data Governance and Strategic Management. Skilled in developing and implementing privacy frameworks, enhancing security posture, and mitigating compliance risks. Committed to delivering strategic solutions that foster privacy maturity, regulatory alignment, and operational efficiency in dynamic environments.

Overview

7
7
years of professional experience
1
1
Certification

Work History

Data Privacy Professional

Open Insights
Pune
09.2024 - Current
  • Assisted clients in privacy compliance governance setup, ensuring alignment with regional regulations.
  • Developed privacy maturity assessments and roadmaps to help organizations achieve compliance objectives.
  • Provided strategic guidance on operationalizing data protection frameworks and embedding privacy controls within business processes.
  • Drafted privacy policies, frameworks, and procedural documents tailored to local compliance requirements.
  • Conducted Records of Processing Activities (ROPA) to maintain transparency in data processing, ensuring adherence to legal requirements.
  • Conducted privacy impact assessments to identify regulatory gaps, and recommended remediation plans.
  • Implemented vendor risk management strategies, ensuring third-party compliance with applicable privacy laws.
  • Developed training and awareness programs to strengthen the privacy culture within client organizations.
  • Assisted in setting up privacy metrics and KPIs for governance and operational tracking.
  • Developed DSR handling procedures, streamlining workflows for efficient and compliant request fulfillment.

Assistant Manager

BDO RISE
Bengaluru
08.2022 - 08.2024
  • Guided client in formulating GDPR/CPRA compliance roadmap while delivering project implementation and privacy support throughout GDPR/CPRA compliance journey.
  • Facilitated workshops with clients to establish compliance roadmap and outline high-level program design, implementation assumptions, and roles and responsibilities.
  • Established a data inventory encompassing business processes, systems, applications, and vendors, with risk ranking and categorization.
  • Optimized configuration of data inventory templates and assessments in privacy management software.
  • Conducted Privacy Impact Assessments of existing systems, applications, and networks to identify potential vulnerabilities, or areas for improvement in data protection.
  • Assisted in developing training programs to educate staff on handling sensitive information securely.
  • Maintained up-to-date knowledge of industry trends in privacy regulations, technology, and tools.
  • Drafted internal communications regarding changes in applicable laws, or new initiatives designed to improve security posture.
  • Handled and fulfilled data subject rights of individuals.

Senior Associate

Grant Thornton
Bengaluru
04.2018 - 08.2022
  • Assisted client in developing CCPA compliance roadmap along with providing project implementation and privacy support in its journey to achieve the CCPA compliance.
  • Assisted client in developing Individual right management procedure documents, along with process flow and matrix to streamline the IRM process.
  • Performed GDPR readiness assessment.
  • Assisted client to enhance client’s Vendor Risk Management governance and operating model based on the applicable governance structures for information security and enterprise risk management, along with defining a corresponding roadmap.
  • Conducted vendor risk assessments for various clients.
  • Assisted clients in conducting Cyber maturity assessments.

Education

MBA - Information Security

Symbiosis Centre For Information Security (SCIT)
Pune
04-2018

BCA - Computer And Information Systems Security

Birla Institute of Technology
Muscat, Oman
06-2016

12th Std. - Commerce

Indian School Al Ghubra
Muscat, Oman
06-2013

Skills

  • CPRA and GDPR Assessments
  • Third Party Risk Assessments and program setup
  • ISO 27001:2013 LA
  • OneTrust, Centrl and Nymity (TrustArc), DataGrail tool implementation
  • PowerBI Dashboards and Reports
  • Individual Rights Management
  • Risk Assessments
  • Privacy Gap Assessments
  • Coaching
  • Task Delegation
  • Employee Performance Evaluations
  • Employee Scheduling and Budgeting
  • Privacy Laws
  • Project Management
  • Teamwork and collaboration

Accomplishments

  • Received multiple Client Appreciations at BDO RISE
  • Honored with BDO Core Values in Core Board at BDO RISE
  • Rewarded Bonus for outstanding performance of 2023 at BDO RISE
  • Honored with Applause Award for outstanding performance of 2021 at Grant Thornton
  • Honored with Kudos Award for outstanding performance of 2019 at Grant Thornton
  • Honored with Star Intern of the Year 2017 during my Internship at Harsh Technologies Pvt. Ltd.
  • Honored with Best Project Award during Bachelor of Computer Application (BCA) project at Waljat College of Applied Sciences Muscat, Sultanate of Oman in academic partnership with Birla Institute of Technology, India in 2016
  • Served an NGO – Anchal Charitable Trust for the year of 2017-2018

Certification

  • Lead Auditor (BS ISO/IEC 27001:2013) by BSI Training Academy
  • OneTrust Professional Certified
  • OneTrust Data mapping expert

Languages

Bengali
First Language
English
Advanced (C1)
C1
Hindi
Advanced (C1)
C1

Timeline

Data Privacy Professional

Open Insights
09.2024 - Current

Assistant Manager

BDO RISE
08.2022 - 08.2024

Senior Associate

Grant Thornton
04.2018 - 08.2022

MBA - Information Security

Symbiosis Centre For Information Security (SCIT)

BCA - Computer And Information Systems Security

Birla Institute of Technology

12th Std. - Commerce

Indian School Al Ghubra
Gitanjali Bose