Data Protection Risk Advisor

Há 7 dias


Lisboa, Portugal BNP Paribas Tempo inteiro

**About the job**
- The Data Protection Risk Advisory department (DPRA), under the Group Data Protection Officer (GDPO) who in turn reports to the Group Chief Risk Officer (CRO), is part of the Group Risk Functions within BNP Paribas acting as the Second Line of Defence (2LoD). The DPRA, with a multidisciplinary team of international specialists with different backgrounds (IT, data, S&O, legal, etc.), has the responsibility for Group wide approach of key data privacy and protection topics and for coordination of activities of the Data Protection activity at Group level.
- The department has responsibility for independently oversight the Group BNP Paribas activities alignment with the Data Protection and Privacy (DPP) BNP Paribas framework on a worldwide scope. This is achieved by framing DPP framework, policies and guidelines for Group BNP Paribas, disseminating of a privacy by design culture across the Group, assessing the adequacy of the DPP framework set-up, controlling the effectiveness of the Group Entities DPP environment, contributing to the detection, anticipation and response to risks, alerting BNP Paribas Management, Risk Function (RISK) and DPP stakeholders on any significant risk issue.
- As part of the 2LoD, the department has the responsibility to identify the key DPP risks of the Bank, to influence business, functions and technology partners to make sound risk management decisions, and advise on the implementation of the adequate DPP controls and measures. The DPRA is responsible for oversight the BNP Paribas Group wide DPP incentives in straight collaboration with the main BNP Paribas Business and Functions teams/stakeholders, such IT Operations, Legal, Cloud, Cybersecurity, Data, Compliance, etc.

**Your Main Activities Are**

The Data Protection Risk Advisor will act as a trusted advisor for BNP Paribas Business and Functions (1LoD - first line of defence) and BNP Paribas DPOs (2LoD - second line of defence) to assist in the implementation, management and monitoring of the DPP strategy, by supporting the definition, implementation and operationalization of the Group’s DPP framework by Group Entities.
- Advising on the maintenance of the Group’s DPP framework, as well as the definition and creation of DPP policies, guidelines and procedures in line with the Group’s DPP strategy
- Independent review and challenge of the technical and operational DPP controls implemented by the BNP Paribas 1LoD and issue recommendations with regards to privacy, data protection and compliance with BNP Paribas framework, policies and guidelines, and data protection regulation (e.g. GDPR, CCPA, LGPD, PDPA, etc)
- Act as a trusted advisor to 1LoD (controllers/ processors) and 2LoD stakeholders regarding DPP management requirements and policies, such as:

- Oversight and check & challenge the most complex DPP initiatives, the design and rollout of the DPP strategy aligned with the overall BNP Paribas DPP framework and regulatory requirements, and oversight, assess and verify the 1LoD implementation of the strategy.
- Oversight and check & challenge transversal and complex Group wide data processing/ initiative impact assessments (DPIA), notable the adequacy of the lawful basis, controllership, risk evaluation, measures and controls implemented and DPO advisory.
- Document 1LoD decisions taken consistent with and opposing DPO’s advice, identify the key DPP risks and inform BNP Paribas’ Management, RISK and other key Business/Function stakeholders.
- Oversight and promote the maintenance of the processing operations record under the responsibility of the controller as one of the tools enabling compliance monitoring, informing and advising the BNP Paribas Functions and Entities controllers/ processors, Business Line DPOs and Territory DPOs.
- Oversight key Group data breaches and other DPP incidents to check and verify on the 1LoD and BNP Paribas DPOs risk identification, ensure the consistency of potential incidents qualification, conduct DPP post mortem analysis, and validate the adequacy and the implementation of controls implemented by the 1LoD.
- Monitor global regulatory changes and authority decisions, share and provide advice on DPP risk anticipation to the DPP community, providing lessons learned, best practices and guidelines, and maintaining the BNP Paribas DPP knowledge basis.
- Attend regular/ ongoing data protection, information security, privacy training and continuous improvement.

**Profile and Skills to Success**
- University degree and professional certifications (e.g. CIPP/E, CIPT, CIPM) in fields relevant to Data Privacy and Protection
- Experience working for a multi-national company from a central position (e.g. Group/ Head office level), preferably in the Financial sector
- Experience working as a consultant, advisor or auditor in initiatives related with data management, data protection, privacy and information security (notably Privacy by Design and Data Flow Mapping), preferably i



  • Lisboa, Portugal BNP Paribas Tempo inteiro

    DATA PROTECTION RISK ADVISOR (JOB NUMBER: 2201RSK9613) **About the job** - The Data Protection Risk Advisory department (DPRA), under the Group Data Protection Officer (GDPO) who in turn reports to the Group Chief Risk Officer (CRO), is part of the Group Risk Functions within BNP Paribas acting as the Second Line of Defence (2LoD). The DPRA, with a...


  • Lisboa, Portugal BNP Paribas Tempo inteiro

    **About the job** The Data Protection Advisor will act as a trusted advisor for BNP Paribas Business and Functions and oversight BNP Paribas DPOs, to assist in the implementation, management and monitoring of the DPP strategy, by supporting the definition, implementation and operationalization of the Group’s DPP framework by Group Entities. **Your Main...


  • Lisboa, Portugal Triggerise Tempo inteiro

    Do you have practical experience within the data protection space? Would you be able to bring a fresh perspective to managing data privacy risks, while providing advice and oversight across all aspects of data privacy? Read more to find out about the role of Data Protection Officer. **The Company** We are a fast-growing non-profit social enterprise with...

  • Data Protection Manager

    2 semanas atrás


    Lisboa, Portugal Merkle DACH Tempo inteiro

    Company Description **We Dream. We Do. We Deliver.** As a **full-service, data-driven customer experience transformation, **we partner with Top 500 companies in the DACH region and in Eastern Europe. Originally from Switzerland, Merkle DACH was created out of a merger Namics and Isobar - two leading full-service digital agencies. **Our 1200+ digital...

  • Data Protection Specialist

    1 semana atrás


    Lisboa, Portugal BNP Paribas Tempo inteiro

    DATA PROTECTION SPECIALIST - M/F - FLUENT IN ENGLISH - LISBON - OPEN ENDED CONTRACT - HYBRID (JOB NUMBER: CS_PSEC_356_2024_2) DATA PROTECTION SPECIALIST - M/F - Lisbon - Open Ended Contract - Hybrid **WHO ARE WE ?** **BNP PARIBAS CARDIF**, the **Insurer for a Changing World**. We are the world leader in the creditor insurance market with strong positions...


  • Lisboa, Portugal act digital Tempo inteiro

    We are looking for a Personal Data Protection Analyst to support day-to-day GDPR business-as-usual activities within the 1st Line of Defense (1LoD). This role focuses on ensuring Privacy by Design principles are embedded into projects and operations, while acting as a key point of contact for data protection matters in close collaboration with central data,...


  • Lisboa, Portugal act digital Tempo inteiro

    We are looking for a Personal Data Protection Analyst to support day-to-day GDPR business-as-usual activities within the 1st Line of Defense (1LoD). This role focuses on ensuring Privacy by Design principles are embedded into projects and operations, while acting as a key point of contact for data protection matters in close collaboration with central data,...


  • Lisboa, Lisboa, Portugal act digital Tempo inteiro

    We are looking for a Personal Data Protection Analyst to support day-to-day GDPR business-as-usual activities within the 1st Line of Defense (1LoD).This role focuses on ensuring Privacy by Design principles are embedded into projects and operations, while acting as a key point of contact for data protection matters in close collaboration with central data,...

  • Data Protection Analyst

    2 semanas atrás


    Lisboa, Portugal HN Services Portugal Tempo inteiro

    🚀 We’re looking for a Data Protection Analyst (Lisboa)Who We're Looking For:✅ Professional Experience & Main TasksEnsure project validation processes comply with Privacy by Design principles, and supporting Project Managers on their data protection activities Manage incoming external and internal requests in the outlook inbox, including Data Subject...

  • Data Protection Analyst

    2 semanas atrás


    Lisboa, Portugal HN Services Portugal Tempo inteiro

    🚀 We’re looking for a Data Protection Analyst (Lisboa)Who We're Looking For:✅ Professional Experience & Main TasksEnsure project validation processes comply with Privacy by Design principles, and supporting Project Managers on their data protection activities Manage incoming external and internal requests in the outlook inbox, including Data Subject...