Contributions

When someone shares their personal data with us, they place their dignity, reputation, and sometimes their very life in our hands. Protecting that trust is not just our responsibility—it is our duty.

Programs delivered

Dec 2023 – Present

Data Privacy & AI Governance Specialist (Techno-Legal)

Ministry of Education & Higher Education, Qatar (via Diyar Middle East)

Designed, implemented and led the national Data Privacy and AI Governance Program for approximately 250,000 users, meeting Qatar PDPPL, GDPR, ISO 27001, ISO 27701 and National Information Assurance requirements. Translated legislation into governance frameworks, policies and technical controls; ran PIAs/DPIAs, TIAs and AI impact assessments; established ROPAs, DSAR operations, data inventories and flow mapping; and acted as single point of contact for the National Data Privacy Office on breaches, inquiries and evidence packages. Embedded Privacy by Design through the SDLC, vendor lifecycle and cross-border transfers, implemented AI governance to the EU AI Act and ISO/IEC 42001, and championed PETs including Purview DLP, encryption, masking, synthetic data and consent management.

Sep 2019 – Dec 2023

Senior Consultant — Data Privacy & GRC

ResultsCX / Shore Infotech, India

Led data privacy gap assessments, DPIAs and risk remediation programs supporting GDPR compliance across business and technology functions. Developed the governance documentation set — processing activities, lawful basis assessments, procedures and DSAR workflows — implemented ISO/IEC 27701 PIMS controls across multi-jurisdictional contact centre operations alongside the existing ISMS, and reviewed and negotiated client, vendor and third-party DPAs with Legal, Procurement and Security.

Sep 2017 – Aug 2019

Senior Engineer

ResultsCX / Shore Infotech, India

Designed and maintained on-prem and cloud telephony infrastructure for contact centres of 30,000+ agents across Avaya, NICE inContact and Genesys. Programmed IVR call flows, CRM integrations and call recording, led the on-prem to cloud migration, drafted SOPs, runbooks and architecture documents as single point of contact for internal and external audits, and owned disaster recovery and business continuity testing, licence management and the Linux patch lifecycle.

Feb 2015 – Aug 2017

Senior Engineer

Invesco, India

Led technical compliance for TRAI and the Department of Telecommunications, delivering multiple regulatory audits with zero observations. Established a Network Operations Centre and integrated it into Invesco's enterprise NOC after the Religare–Invesco merger, led incident command for critical production outages — earning consecutive Best Performer awards — and managed vendors, managed service providers, monitoring platforms and alert governance.

Oct 2013 – Jan 2015

Tier-3 Backbone Engineer — Global Network Operations Centre

Avaya (via MIntergraph), India

Resolved more than 50 Priority-1 production incidents for Fortune 100 customers, providing Tier-3 support across global deployments, and managed incidents from diagnosis to permanent resolution in collaboration with R&D on defects, enhancements and root-cause investigations.

May 2008 – May 2010

Software Engineer

Avaya, India

Performed data classification, trend analysis and problem management, reducing reactive support demand by 3%, and authored technical articles, troubleshooting guides and reusable solutions that accelerated issue resolution.

Organisations
Ministry of Education & Higher Education, Qatar
Diyar Middle East
ResultsCX
Invesco
Avaya

Memberships

Bar Council of India
Enrolled Advocate — Telangana High Court Bar Association / Bar Council of India
2000 – Ongoing
ISACA
ISACA (Information Systems Audit and Control Association) Education & Programs Working Group member, Doha
2026 – Ongoing
IAPP
IAPP (International Association of Privacy Professionals) Hyderabad Chapter Chair
2022 to 2024

Case studies

Anonymised. Detail available on request under NDA.

Public sector · Qatar
A national data privacy program for 250,000 users

A national education body needed PDPPL, GDPR, ISO 27001/27701 and NIA compliance across hundreds of systems and a distributed user base. I built the governance framework, policy set, ROPA and DSAR operations, and the regulator interface with the NDPO and NCSA.

Result: a standing data privacy office, an evidenced control set and a defensible position in front of national regulators.
AI governance
AI governance under the EU AI Act and ISO 42001

Generative AI was entering the estate faster than governance could follow. I established the AI inventory, model classification and risk tiering, defined human oversight requirements, and wrote the AI privacy impact assessment used for every new deployment.

Result: AI adoption continued, with a documented risk decision behind each system.
Enterprise services
GDPR gap assessment and DPIA program

A multi-jurisdictional contact centre operator needed GDPR assurance for enterprise clients. I ran the gap assessment, established a repeatable DPIA process, rebuilt the governance documentation and integrated ISO 27701 PIMS controls into the existing ISMS.

Result: data privacy moved from a client questionnaire exercise to an operating process.

Bring this to your program

Tell me the jurisdiction, the systems in scope and the deadline. I will tell you what is realistic.