About this role
The AVP – Data Privacy by Design role will lead privacy team operations and processes and work closely with the Legal, Product, Global Technology, Cyber Security, Policy and Commercial functions.
• Monitor compliance and data practices to ensure the business and its products comply with applicable contractual obligations and privacy regulations, including GDPR, CCPA, CPRA, COPPA, and emerging AI privacy laws. • 2. Enable innovation by advising the Product team on privacy and data use to enable EXL to continue as the standard for the most secure, privacy-compliant, and independently evaluated media authentication company globally. • 3. Drive AI Governance and adoption through frameworks for safe and responsible AI use that balance risk and business goals to drive the organization’s AI strategy
• Lead EXL’s global privacy program, including Privacy by Design (PbD), Privacy Enhancing Technologies (PETs), and enterprise privacy governance initiatives. • Partner with the AI Governance Committee to establish and maintain privacy frameworks, policies, and controls that support responsible AI adoption and regulatory compliance. • Develop, implement, and maintain privacy governance standards aligned with global regulations, including GDPR, CCPA, CPRA, COPPA, and emerging AI and data protection requirements. • Serve as the primary privacy advisor to business, product, technology, legal, and operational stakeholders on data use, privacy risk, and compliance matters. • Drive Privacy by Design and Privacy by Default practices across products, applications, and data-driven business processes. • Conduct and oversee Data Protection Impact Assessments (DPIAs), Privacy Impact Assessments (PIAs), and privacy reviews for new products, technologies, and processing activities. • Maintain global privacy policies, procedures, and standards to address evolving regulatory and business requirements. • Review and negotiate privacy-related provisions in customer, partner, and vendor agreements in partnership with Legal and Information Security teams. • Lead privacy risk assessments, vendor reviews, and third-party data protection evaluations to ensure appropriate controls are implemented. • Monitor and interpret global privacy regulations and emerging legislative developments, assessing business impact and recommending remediation strategies. • Maintain and expand privacy certifications and accreditation programs, including ISO 27701, APEC CBPR, APEC PRP, and Data Privacy Framework requirements. • Partner with Cyber Security teams to maintain records of processing activities, data inventories, data mapping, data flows, and third-party processing activities. • Support enterprise data governance efforts by ensuring appropriate controls for data retention, destruction, minimization, and lawful processing.
• Hold at least one Data Protection and/or Privacy certification such as CIPP/US, CIPP/E, CIPM, CIPT, or equivalent (preferred) • 10-15 years of progressive experience in data privacy and protection, with at least 3-5 years in a leadership role • Experience with U.S. and EU data privacy laws (GDPR, CCPA, CPRA, COPPA) and emerging AI privacy regulations • Multiple years' experience within a compliance, legal, audit and/or risk function, with substantial experience in privacy compliance • Experience in developing policy and compliance training programs • Experience serving as Data Protection Officer or in similar senior privacy capacity preferred • Background in technology companies, particularly in digital advertising, adtech, martech, or fraud detection industries strongly preferred • Travel: Willingness to travel as needed for business purposes, including regulatory meetings, audits, industry conferences, and team collaboration