hirly

QUINTESSENTIAL INNOVATIONS

Data Protection & Compliance Manager

Hyderabad, India

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at QUINTESSENTIAL INNOVATIONS first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
IN
Work mode
On-site / unstated
First seen by hirly
23 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Data Protection & Compliance Manager (DPO · CIPP/E · GDPR/DPDP)

About Quin

Quin is a safety-technology company. We embed sensor tech — crash detection, motion sensing, connectivity — into helmets and protective gear as an ingredient brand, shipping inside products from partners across motorcycling, cycling, sports, Industrial PPE and more. Quin products are designed to scale to millions of users, adopted by leading, global brands. Our engineering and product operations centre is in Hyderabad, where we are building our team and product with world-class excellence.

Why this role exists

This role is responsible for ensuring enterprise security assurance, global data protection, and AI/algorithmic governance are not just managed, but a sales enabler and point of pride for the company. You'll stand up our governance, risk and compliance function, and own the data-protection role for the company.

What you'll own

Security compliance & certifications

Own the control framework, evidence collection, and continuous-monitoring cadence (partnering with the InfoSec Engineer on the technical controls).

Data protection & DPO

  • Act as the company's Data Protection Officer across GDPR (UK/EU) and India's DPDP Act, including registration obligations.
  • Own RoPA, DPIAs, data-subject-request handling, breach response and notification, retention schedules, and cross-border transfer mechanisms.
  • Lead and embed privacy by design..

Policy authorship & document governance

  • Author and own the full internal governance stack: information security, acceptable use, data classification & handling, incident response, business continuity / disaster recovery, access control, change management, vendor/third-party risk, and an AI/ML-use governance policy for our motion-data work.
  • Draft and maintain all privacy-facing documents: the app and portal privacy notice s , cookie/consent notices, the DPA template and sub-processor register, and internal data-handling SOPs.
  • Be the single accountable owner and custodian of the entire policy & document estate — versioning, review cadence, approvals, and the internal knowledge base. This includes keeping the customer- and product-facing agreements that external counsel drafts current in the repository.
  • Stand up a lightweight, real risk register the business actually uses.

Third-party & vendor risk

Own vendor due diligence, DPAs, and the sub-processor register..

Enterprise trust & customer assurance

Own security questionnaires, RFP compliance sections, and a customer-facing trust posture.

Product & AI governance

Build a proportionate governance approach for our motion-sensing/ML work, in line with EU AI Act and algorithmic transparency in a pragmatic and practical manner.

Must-haves

  • 4–8 years in data protection, privacy, GRC, or technology/compliance law — ideally in SaaS or a product company handling personal data at scale .
  • Deep, working command of GDPR ; familiarity with India's DPDP Act .
  • Demonstrable ownership of either a security-certification program (SOC 2 and/or ISO 27001) or a data-protection/DPO program end to end — and the credibility to learn the other fast.
  • The ability to work directly with engineers and translate regulation into concrete product/technical requirements.
  • Genuinely autonomous: you scope, drive and close things without being managed.

Strong pluses

  • CIPP/E, CIPM, CISSP, or ISO 27001 Lead Implementer/Auditor.
  • Exposure to the EU AI Act or AI/algorithmic governance.
  • Experience with a global SaaS/enterprise buyer base and their procurement/security reviews.
  • Comfort operating across geographies (UK/EU, India, China supply chain).

How we work

Small team of doers. We hire people who move fast and go deep, not people who manage other people to do the work. You'll have real ownership and very little bureaucracy.

Original posting on QUINTESSENTIAL INNOVATIONS's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job
Data Protection & Compliance Manager · Hyderabad | hirly.me