Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector
Full-time Mid-Senior LevelJob Overview
Advisory & Regulatory Guidance
GDPR & local law advice — Act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across the Group's European markets, including local implementing legislation and sector-specific rules.
Regulatory monitoring — Track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes, including ePrivacy, the EU AI Act, data governance and financial-services data rules. Assess their impact and translate them into practical guidance and updated policies.
Legal opinions — Provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite.
Privacy Governance & Documentation
Records of Processing (RoPA) — Establish, maintain and update the Article 30 records of processing activities across entities and functions.
Policies & procedures — Draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices, ensuring they remain aligned with regulatory developments.
DPIAs & risk assessments — Conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures.
Privacy by Design, Projects & New Technology
Privacy by design & by default — Embed privacy requirements into new products, services, systems and business initiatives from the outset.
AI & new technology — Review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with Legal, Technology and Risk teams and considering the interplay with the EU AI Act.
Project support — Provide privacy input to transformation, digital, marketing and data initiatives across the Group.
Vendors, Contracts & Data Transfers
Data Processing Agreements — Draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.
International transfers — Advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments.
Third-party due diligence — Assess the privacy posture of vendors and third parties as part of procurement and third-party risk management.
Data Subject Rights & Incident Response
Data subject requests (DSARs) — Manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.
Breach & incident response — Manage the personal data breach process end to end, including triage, risk assessment, remediation, record-keeping and notifications to supervisory authorities and data subjects where required.
Regulator liaison — Support engagement with supervisory authorities on notifications, queries and investigations.
Awareness, Cooperation & Reporting
Training & awareness — Design and deliver privacy training and awareness sessions and promote a strong data protection culture across the Group.
Stakeholder cooperation — Work closely with Legal, Information Security, IT, HR, Procurement, Marketing and the business, and coordinate with local privacy contacts across jurisdictions.
Reporting — Prepare privacy metrics, dashboards and updates for compliance management, senior stakeholders and relevant governance committees.
Make Your Resume Now