As Privacy Champion, you act as the privacy and GDPR subject matter expert within the Central Data Governance Office. In close collaboration with the SNCB Legal Digital & Data team, the Data Protection Officer, and the Privacy Champion network, you support the implementation of SNCB's privacy framework within Ypto. You promote privacy-by-design, strengthen privacy awareness, and help stakeholders fulfil their responsibilities while remaining accountable for their own decisions and obligations.
What is your role at SNCB?
- You maintain and improve privacy governance processes, controls and documentation.
- You support the implementation and adoption of SNCB privacy policies, standards, procedures and guidelines within Ypto.
- You help translate enterprise privacy requirements into practical actions and clear guidance for local stakeholders.
- You support stakeholders in maintaining RoPA, processor registers, privacy assessments and breach documentation.
- You advise on DPIAs, DTIAs, privacy risks, compliance obligations and privacy-by-design practices.
- You represent Ypto in the NMBS/SNCB Privacy Champion network and Privacy Committee.
- You contribute to privacy awareness, training initiatives, reporting, audits and compliance reviews.
- You support privacy requirements in projects, operations and third-party processor assessments.
Why is this job a good fit for you?
You hold a master's degree or equivalent experience and have 3-5 years of experience in IT, cybersecurity, risk management, compliance, governance, and 3-5 years of experience in privacy, GDPR or data protection.
You also possess these technical skills:
- You have strong knowledge of GDPR and Belgian privacy legislation.
- You have knowledge of or a strong interest in AI governance frameworks, Responsible AI principles and the EU AI Act.
- You have experience with privacy governance, compliance and risk management frameworks.
- You understand cybersecurity, information security and privacy standards.
- You have experience performing or reviewing DPIAs and privacy risk assessments.
- You can translate regulatory requirements into practical business solutions.
- You are professionally proficient in English, Dutch and French.
And these soft skills:
- You communicate effectively with operational teams and senior management.
- You have strong analytical, communication and stakeholder engagement skills.
- You promote awareness, collaboration and knowledge sharing across the organisation.
- You demonstrate a commitment to continuously develop privacy expertise through training, certifications, professional communities and regulatory monitoring.
Asset:
- You hold certifications such as CIPP/E, CIPM, CIPT, AIGP, ISO 27001-related certifications or a recognized DPO certification.
Diversity Statement
Everyone is unique. That's why we believe it’s important that you can be yourself —
It makes SNCB stronger. We therefore place great value on diversity and inclusion.
What can you expect from us?
Choosing NMBS/SNCB means choosing to contribute to the digital transformation of Belgian railways. You will have a job with social impact and ample opportunity to make your own contribution. Alongside a healthy work-life balance and a competitive salary, we offer:
- Hybrid working, with a balanced weekly mix of office and remote work, combined with flexible hours.
- 35 days of annual leave.
- A mobility package with a company car (also available via our mobility plan) or alternative mobility choices, complemented by a public transport season ticket.
- A target bonus.
- A comprehensive insurance package, with hospitalisation and dental care for the whole family.
- Coverage of outpatient medical costs.
- Group insurance, including a supplementary pension (cafeteria plan).
- Net allowances for hybrid working and an internet allowance.
Where will you be working?
You will work near Brussels-South station and join the Data Governance team.