Data Protection Risk Advisor

1 semana atrás


Lisboa, Portugal BNP Paribas Tempo inteiro

**About the job**

The Data Protection Advisor will act as a trusted advisor for BNP Paribas Business and Functions and oversight BNP Paribas DPOs, to assist in the implementation, management and monitoring of the DPP strategy, by supporting the definition, implementation and operationalization of the Group’s DPP framework by Group Entities.

**Your Main Activities Are**
- Advising on the maintenance of the Group’s DPP (Data Protection and Privacy) Governance and framework, as well as the definition and creation of DPP policies, guidelines and procedures of Group BNP Paribas
- Independent review and challenge of the technical and operational DPP controls implemented and issue recommendations with regards to privacy, data protection and compliance with the Group BNP Paribas DPP framework and regulation (e.g. GDPR, CCPA, LGPD, PDPA, etc)
- Act as a trusted advisor of key internal stakeholders (e.g. CDOs, CISOs, DPOs, Business ) regarding manage DPP requirements, such as:

- Oversight and check & challenge complex and transversal DPP initiatives, design and rollout of the DPP strategy, and strategy implementation.
- Oversight and check & challenge transversal and complex Group wide data processing/ initiative impact assessments (DPIA), notable the adequacy of controls and measures, controllership, transfers, etc.
- Identify key DPP risks, inform BNP Paribas’ Management and key stakeholders such IT and Business among other, and oversight the decisions to manage those risks.
- Oversight key Group data breaches and other DPP incidents and work with key stakeholders (such CDO, CISO, DPO, IT, Legal, etc.) on the risk identification, ensure the consistency of potential incidents qualification, conduct post mortem analysis, and validate the adequacy and solutions implementation.
- Monitor and advice on the interactions with authorities and other external stakeholders, analyzing the requests, actions to be taken and producing lessons learned among the BNP Paribas worldwide DPP community.
- Monitor global regulatory changes and authority decisions, share and provide advice on DPP risk anticipation to the DPP community, providing lessons learned, best practices and guidelines, and leveraging on the BNP Paribas DPP knowledge basis.
- Attend regular/ ongoing data protection, information security, privacy training and continuous improvement.

**Profile and Skills to Success**

University degree and relevant professional certifications (e.g. CIPP/E, CIPT, CIPM, ISO27001, etc.) in fields relevant to DPP and cybersecurity

Desirable experience working for a multi-national company from a central position (e.g. Group/ Head office level), preferably in the Financial sector

Experience working as a consultant, advisor or auditor in initiatives related with data management, data protection, privacy and information security (notably Privacy by Design and Data Flow Mapping), preferably in a relevant audit/ consulting Firm

Has experience analysing potential privacy incidents to proactively mitigate risk, in determining reporting requirements and corrective action plans when needed

Desirable experience of promoting a data privacy culture and awareness

Experience in communicating and presenting effectively to senior management and decision-making individuals within the organization

Experience of working with and managing stakeholders from different disciplinary backgrounds (e.g. IT, Risk, CDO and Data management, Legal, Compliance, Security, HR, etc.), notably providing technical advice and producing technical deliverables

English Fluent mandatory

French is a plus

Technical Skills:
Understands information security controls and principles that ensure confidentiality, integrity, availability of sensitive information

Understanding of large-scale technology infrastructure and programmes where large quantities of data are used/managed

Has a hybrid understanding of cross over requirements (risk, IT, regulatory, data security)

Is able to evaluate DPP policies, regulations and decisions, and produce actionable insight

Familiarity with privacy and security risk assessment, best practices and gap analysis, privacy certifications/seals, information security and DPP certifications, and tools

Personal Skills and Behaviours

Good interpersonal skills and ability to collaborate across business lines and geographies

Ability to work in a multi-cultural, multi-lingual environment adapting ways of working as required

Good communication skills

Rigor and attention to details

Flexibility and customer orientation

**About the Team**

BNPP Group Personal Data Protection framework, defined to respond to applicable privacy regulations throughout BNPP territories, relies on the accountability of teams within BNPP entities in their processing of Personal Data (customer, employees, UBOs, representatives of corporate, vendors, etc.)

Data Protection Office (DPO) is part of the RISK Department within BNP Paribas, positioned in the 2nd Line of Defence



  • Lisboa, Portugal PPDP - Plus Privacy Data Protection Tempo inteiro

    Junior Data Protection Consultant @ Plus Privacy Full Time Lisbon, Portugal Quem somos: Na Plus Privacy, criamos programas de proteção de dados adaptados ao negócio de cada cliente, que permitem medir o nível de cumprimento dentro da organização. Uma vez implementado, este é o plano que a empresa necessita para rumar à conformidade com o RGPD. A...


  • Lisboa, Lisboa, Portugal PPDP - Plus Privacy Data Protection Tempo inteiro

    Junior Data Protection Consultant @ Plus PrivacyFull TimeLisbon, PortugalQuem somos:Na Plus Privacy, criamos programas de proteção de dados adaptados ao negócio de cada cliente, que permitem medir o nível de cumprimento dentro da organização. Uma vez implementado, este é o plano que a empresa necessita para rumar à conformidade com o RGPD.A missão...


  • Lisboa, Lisboa, Portugal BNP Paribas CIB Tempo inteiro

    About The JobBNPP Group Personal Data Protection framework, defined to respond to the new General Regulation on Data Protection - GDPR coming into effect on 25 May 2018, relies on the accountability of teams within BNPP entities and territories in their processing of Personal Data (customer, employees, UBOs, representatives of corporate, vendors, etc.)The...

  • Data Protection Officer

    1 semana atrás


    Lisboa, Portugal Triggerise Tempo inteiro

    Do you have practical experience within the data protection space? Would you be able to bring a fresh perspective to managing data privacy risks, while providing advice and oversight across all aspects of data privacy? Read more to find out about the role of Data Protection Officer. **The Company** We are a fast-growing non-profit social enterprise with...

  • Data Privacy

    1 dia atrás


    Lisboa, Portugal BNP Paribas Tempo inteiro

    **About the job** - As a Data Privacy and Protection Expert, the primary mission is to spearhead the development and implementation of robust data privacy and protection frameworks within P&P group function. This role is pivotal in ensuring the highest standards of compliance with internal and external data regulatory requirements, and the minimization of...


  • Lisboa, Portugal act digital Tempo inteiro

    We are looking for a Personal Data Protection Analyst to support day-to-day GDPR business-as-usual activities within the 1st Line of Defense (1LoD). This role focuses on ensuring Privacy by Design principles are embedded into projects and operations, while acting as a key point of contact for data protection matters in close collaboration with central data,...

  • Senior Manager Privacy

    1 dia atrás


    Lisboa, Portugal Atlas Technology Solutions Tempo inteiro

    We believe in a world where growth thrives across borders and cultures. As an EOR, Atlas employs people to work for companies anywhere in the world. Before we came along, the only businesses offering a similar solution were essentially brokers. They'd outsource your HR and payroll services to third-party providers in different countries. Today, we're the...


  • Lisboa, Lisboa, Portugal act digital Tempo inteiro

    We are looking for a Personal Data Protection Analyst to support day-to-day GDPR business-as-usual activities within the 1st Line of Defense (1LoD).This role focuses on ensuring Privacy by Design principles are embedded into projects and operations, while acting as a key point of contact for data protection matters in close collaboration with central data,...

  • Data Protection Analyst

    3 semanas atrás


    Lisboa, Portugal HN Services Portugal Tempo inteiro

    🚀 We’re looking for a Data Protection Analyst (Lisboa)Who We're Looking For:✅ Professional Experience & Main TasksEnsure project validation processes comply with Privacy by Design principles, and supporting Project Managers on their data protection activities Manage incoming external and internal requests in the outlook inbox, including Data Subject...

  • Data Protection Analyst

    3 semanas atrás


    Lisboa, Portugal HN Services Portugal Tempo inteiro

    🚀 We’re looking for a Data Protection Analyst (Lisboa)Who We're Looking For:✅ Professional Experience & Main TasksEnsure project validation processes comply with Privacy by Design principles, and supporting Project Managers on their data protection activities Manage incoming external and internal requests in the outlook inbox, including Data Subject...