The Corporate Compliance function acts as a second line of defence, providing independent oversight, advice and challenge on regulatory and conduct risks. Within this function, the Data Protection Office is responsible for ensuring that the Group meets its obligations under the GDPR and local privacy regulation.
A leading European market infrastructure group is seeking an experienced Privacy Counsel o to reinforce the Data Protection Office and support the Group DPO. The successful candidate will provide day-to-day privacy legal advice, help operate and mature the Group privacy compliance framework, and ensure that GDPR and local privacy requirements are consistently embedded across the Group's activities, projects and jurisdictions.
Advisory & regulatory guidance
GDPR & local law advice — act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across markets (France, the Netherlands, Italy, Belgium, Portugal, Norway and Ireland), including local implementing legislation and sector-specific rules.
Regulatory monitoring — track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes (ePrivacy, the EU AI Act, data governance and financial-services data rules), assess their impact and translate them into practical guidance and updated policies.
Legal opinions — provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite.
Privacy governance & documentation
Records of Processing (RoPA) — establish, maintain and update the Article 30 records of processing activities across entities and functions.
Policies & procedures — draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices; ensure they remain aligned with regulatory change.
DPIAs & risk assessments — conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures.
Privacy by design, projects & new technology
Privacy by design & by default — embed privacy requirements into new products, services, systems and business initiatives from the outset.
AI & new technology — review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with legal, technology and risk teams and considering the interplay with the EU AI Act.
Project support — provide privacy input to transformation, digital, marketing and data initiatives across the Group.
Vendors, contracts & data transfers
Data Processing Agreements — draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.
International transfers — advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments.
Third-party due diligence — assess the privacy posture of vendors and third parties as part of procurement and third-party risk management.
Data subject rights & incident response
Data subject requests (DSARs) — manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.
Breach & incident response — manage the personal data breach process end to end: triage, risk assessment, remediation, record-keeping and notifications to supervisory authorities and data subjects where required.
Regulator liaison — support engagement with supervisory authorities (e.g. CNIL, Autoriteit Persoonsgegevens, Garante) on notifications, queries and investigations.
Awareness, cooperation & reporting
Training & awareness — design and deliver privacy training and awareness sessions and promote a strong data protection culture across the Group.
Stakeholder cooperation — work closely with Legal, Information Security, IT, HR, Procurement, Marketing and the business, and coordinate with local privacy contacts across jurisdictions.
Reporting — prepare privacy metrics, dashboards and updates for compliance management, senior stakeholders and relevant governance committees.
Un plan personnalisé pour postuler intelligemment à cette offre.
Cliquez sur "Postuler" pour accéder à l'offre.