EU remote
Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector
About this role
Advisory & Regulatory Guidance GDPR & local law advice — Act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across the Group's European markets, including local implementing legislation and sector-specific rules. Regulatory monitoring — Track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes, including ePrivacy, the EU AI Act, data governance and financial-services data rules.
Assess their impact and translate them into practical guidance and updated policies. Legal opinions — Provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite. Privacy Governance & Documentation Records of Processing (RoPA) — Establish, maintain and update the Article 30 records of processing activities across entities and functions.
Policies & procedures — Draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices, ensuring they remain aligned with regulatory developments. DPIAs & risk assessments — Conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures. Privacy by Design, Projects & New Technology Privacy by design & by default — Embed privacy requirements into new products, services, systems and business initiatives from the outset.
AI & new technology — Review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with Legal, Technology and Risk teams and considering the interplay with the EU AI Act. Project support — Provide privacy input to transformation, digital, marketing and data initiatives across the Group. Vendors, Contracts & Data Transfers Data Processing Agreements — Draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.
International transfers — Advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments. Third-party due diligence — Assess the privacy posture of vendors and third parties as part of procurement and third-party risk management. Data Subject Rights & Incident Response Data subject requests (DSARs) — Manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.