Role Summary:
As the Data Protection Counsel (m/w/d), you will help minimize data protection risks and ensure compliant personal data processing across Europe, with a focus on operational privacy matters such as data subject requests, data processing agreements, data mapping, and risk assessments, while contributing to broader governance initiatives.
We want you to:
- Provide day-to-day legal support on data protection matters across business projects, ensuring compliance with GDPR and related regulations
- Draft, review, and negotiate Data Processing Agreements (DPAs) and related contractual clauses
- Handle and coordinate Data Subject Rights (DSR) requests, ensuring timely and compliant responses
- Conduct data protection risk assessments and support mitigation of identified risks
- Contribute and gather information for data mapping and support AI use case inventories and AI risk assessments
- Participate in decision-making process for adopting templates & policies, aligning on legal interpretation and risk classification of processing activities, including identification of potential high-risk scenarios
- Maintain and update records of processing activities and data mapping documentation
- Responsible for the maintenance and accuracy of data protection documentation, including templates, registers, and internal guidance materials
- Oversee the approval of standardized DSR responses and contractual templates, in line with defined escalation processes
- Support compliance monitoring and internal audits in cooperation with relevant functions
- Contribute to the development and implementation of data protection policies, procedures, and standards
- Support the implementation of automated solutions (e.g. DSR workflows, data mapping tools)
About you:
- Degree in Law; professional legal qualification preferred
- Minimum five years of relevant experience
- Legal background, ideally with experience in data protection and privacy matters
- Hands-on experience in Data Subject Rights (DSR) handling, Data Processing Agreement (DPA) drafting and negotiation, and data mapping, including Records of Processing Activities (RoPA).
- Solid understanding of GDPR and EU data protection frameworks
- Ability to draft and review legal documents, including contracts, assessments, and responses
- Basic understanding of AI governance, algorithmic risk, or automated decision-making frameworks is an advantage
- Familiarity with cybersecurity principles and their intersection with data protection, including security of processing under GDPR
- Experience supporting risk assessments related to personal data processing
- Familiarity with compliance monitoring and audit support
- Fluent English
- Proactive, accountable, and able to work effectively with appropriate supervision
- Sound risk awareness and judgement in day-to-day activities
- Strong analytical and problem-solving skills
- Ability to prioritise and manage multiple tasks in a structured manner
- High attention to detail and accuracy
- Ability to translate legal requirements into practical business guidance
- Strong stakeholder collaboration and cross-functional communication skills
We offer:
- A competitive salary and benefits package
- Flexible working hours and a hybrid working policy
- Continued learning and professional development
- Car sharing and lease mobility program
- Complimentary daily lunch at our canteen and subsidized breakfast options
- Complimentary fitness facility and the opportunity to join various sporting clubs
- Highly international working environment