Privacy and Data Protection
About YellowIpe Our mission is to inspire the connection of technology with people; we foster the best in our professionals through our expertise in finding and attracting the best talent for the best projects. Focus on People, Collaboration, and Commitment are the pillars that guide us on this journey. Join the yellow team as our new Privacy and Data Protection! Responsibilities: Provide practical legal advice on the General Data Protection Regulation (GDPR) and national privacy legislations in various European jurisdictions, aligning with the needs of each region.
Assist in maintaining the privacy compliance framework, as well as offering proactive consultancy to business and technology teams regarding privacy risks associated with projects, vendors, data transfers, artificial intelligence, and personal data-related incidents.
Draft and review clear and well-founded legal opinions on privacy matters, ensuring they are easily understandable for various stakeholders.
Establish, maintain, and update Records of Processing Activities, as stipulated by Article 30 of the GDPR, ensuring continuous compliance with regulations.
Draft and evaluate privacy policies, internal norms, and procedures, as well as privacy notices, ensuring they are comprehensive and duly updated.
Conduct and supervise Data Protection Impact Assessments (DPIAs) and legitimate interest assessments to identify and proactively mitigate risks.
Detect privacy risks and recommend proportionate mitigation measures, promoting a culture of "privacy by design" and "privacy by default" in products, services, and systems.
Review artificial intelligence projects, automated decision-making, digital marketing, and data transformation initiatives, ensuring they respect privacy guidelines.
Draft, review, and negotiate Data Processing Agreements, data sharing agreements, and arrangements between controllers and processors, binding all parties to clear and fair obligations.
Provide advice on international and intra-group data transfers, including the application of Standard Contractual Clauses and Transfer Impact Assessments.
Evaluate the privacy posture of vendors and third parties during procurement processes and risk analyses, ensuring compliance throughout the supply chain.
Coordinate responses to data subject rights requests within legal deadlines, ensuring respectful and effective handling.
Manage personal data breach incidents, including triage, risk assessment, remediation, documentation, and regulatory notifications whenever necessary.
Act as the primary point of contact for communications with supervisory authorities, maintaining transparency and alignment.
Design and conduct privacy training and awareness sessions for the team, promoting a culture of awareness throughout the organization.
Prepare privacy metrics, dashboards, and updates for senior stakeholders and governance committees, continuously evaluating the effectiveness of privacy practices.
Collaborate with Legal, Information Security, IT, Human Resources, Procurement, Marketing, and business sectors in different jurisdictions to ensure the integration of privacy practices throughout the organization.
Requirements: Bachelor's degree in Law.
Qualification or admission in an EU jurisdiction is strongly preferred.
4 to 7 years of experience in relevant areas of data protection or privacy law.
Experience gained in-house, in a law firm, or in legal or privacy consultancy.
Solid practical knowledge of GDPR and national privacy legislation in at least one European jurisdiction.
Practical experience with DPIAs, Records of Processing Activities (RoPA), privacy policies, Data Subject Access Requests (DSARs), personal data breaches, Data Processing Agreements (DPAs), and international data transfers.
Familiarity in advising on privacy risks linked to technology, artificial intelligence, or digital projects.
Experience in financial services, market infrastructure, or another regulated sector is valued.
Professional fluency in English, both written and spoken.
Knowledge of French, Dutch, Italian, or Portuguese is considered a relevant differentiator.
Differentiators: Previous experience dealing with privacy audit processes and regulatory compliance.
Knowledge of privacy technology tools and information security solutions.
Skills in the design and implementation of confidentiality policies and consent management.
Effective communication skills with stakeholders at all levels, with a strong mediation and conflict resolution profile.
Application: View the vacancy and apply at YellowIpe