Devoteam Cyber Trust | Privacy Counsel

Há 2 dias

Porto, Portugal Devoteam | Cyber Trust Tempo integral 55 000 € - 85 000 € Contrato
Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries. Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients. The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS
- Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.

Job Description
Advisory & Regulatory Guidance
- GDPR & local law advice — Act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across the Group's European markets, including local implementing legislation and sector-specific rules.
- Regulatory monitoring — Track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes, including ePrivacy, the EU AI Act, data governance and financial-services data rules. Assess their impact and translate them into practical guidance and updated policies.
- Legal opinions — Provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite. Privacy Governance & Documentation
- Records of Processing (RoPA) — Establish, maintain and update the Article 30 records of processing activities across entities and functions.
- Policies & procedures — Draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices, ensuring they remain aligned with regulatory developments.
- DPIAs & risk assessments — Conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures. Privacy by Design, Projects & New Technology
- Privacy by design & by default — Embed privacy requirements into new products, services, systems and business initiatives from the outset.
- AI & new technology — Review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with Legal, Technology and Risk teams and considering the interplay with the EU AI Act.
- Project support — Provide privacy input to transformation, digital, marketing and data initiatives across the Group. Vendors, Contracts & Data Transfers
- Data Processing Agreements — Draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.
- International transfers — Advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments.
- Third‑party due diligence — Assess the privacy posture of vendors and third parties as part of procurement and third‑party risk management. Data Subject Rights & Incident Response
- Data subject requests (DSARs) — Manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.
- Breach & incident response — Manage the personal data breach process end to end, including triage, risk assessment, remediation, record‑keeping and notifications to supervisory authorities and data subjects where required.
- Regulator liaison — Support engagement with supervisory authorities on notifications, queries and investigations. Awareness, Cooperation & Reporting
- Training & awareness — Design and deliver privacy training and awareness sessions and promote a strong data protection culture across the Group.
- Stakeholder cooperation — Work closely with Legal, Information Security, IT, HR, Procurement, Marketing and the business, and coordinate with local privacy contacts across jurisdictions.
- Reporting — Prepare privacy metrics, dashboards and updates for compliance management, senior stakeholders and relevant governance committees. Qualifications
- Law degree; qualification/admission in an EU jurisdiction is strongly preferred.
- 4 to 7 years of relevant experience in data protection/privacy, gained in‑house and/or in a law firm or consultancy.
- Strong, demonstrable working knowledge of the GDPR and of national privacy laws in at least one relevant European jurisdiction.
- Experience in financial services, market infrastr