EU remote
DATA PROTECTION OFFICER (DEPUTY) (f/m/d)
About this role
The Deputy Data Protection Officer (Deputy DPO) supports and, where required, deputizes for the Data Protection Officer (DPO) of the 360T Group in carrying out the DPO’s advisory and monitoring responsibilities. The role acts as a staff function and supports the independent data protection assurance framework, providing advisory and monitoring support for the implementation of applicable data protection laws and helping to ensure that personal data is appropriately safeguarded.
When acting on behalf of the DPO, the Deputy DPO performs the relevant responsibilities within the DPO’s mandate and in accordance with applicable legal and regulatory requirements. Risk Management and Internal Control Support the DPO and Management in identifying, assessing, monitoring and reporting data protection and privacy risks. Monitor relevant legal, regulatory and organizational developments and support the implementation of proportionate measures.
Contribute to maintaining effective and compliant data protection structures and controls across the Group. Governance & Reporting Support the DPO in developing and maintaining the Group’s data protection strategy, policies and oversight framework. Support regular reporting to Management on key data protection risks, developments, incidents and remediation activities. Coordinate with relevant governance bodies and internal stakeholders on data protection matters.
Deputize for the DPO in governance and reporting activities where required. Monitoring & Assurance Support the independent monitoring of compliance with applicable data protection laws, internal policies and related controls. Monitor the effectiveness and adequacy of data protection processes and measures. Support the development and execution of a risk-based data protection monitoring plan. Deputize for the DPO in monitoring and assurance activities where required.
Advisory Advise the business on data protection and privacy requirements, including privacy by design and default, DPIAs and cross-border data transfers. Provide guidance on data subject rights, third-party and processor arrangements, privacy notices and records of processing activities. Advise on the assessment and handling of personal data breaches and related notification requirements. Support relevant projects and initiatives involving the processing of personal data.