Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.
L'olivier Assurance is seeking a Data Protection & Privacy Compliance Lead to operate the local data protection framework, advise the business, and support the EU DPO. You will manage governance, risk assessments, and engagement with authorities and data subjects.
The role requires strong expertise in EU data protection laws, a Law degree with a Master in related fields, and fluency in French and English. Travel may be required occasionally.
Responsible for supporting, challenging and monitoring the data protection & privacy compliance framework at a local/country level. The primary objectives include operational management of the data protection compliance framework at a local level, providing day-to-day support and advice to the business, assessing data protection risks, and assisting the EU Data Protection Officer in fulfilling their duties locally.
Local data protection governance support: Collaborate on providing information and advice on data protection laws and policies at the country level. Maintain and update internal policies and procedures at a local level.
Privacy by Design: Conduct Privacy Impact Assessments on new products and services mitigating data protection and privacy risks.
Advisory: Provide the business with data protection technical advice, guidance and expertise, and ensure that all necessary data protection documentation is in place and up to date.
Data Incident and Breach Management: Collaborate in managing the data incident response and data breach notification procedures, dealing with data incidents and breaches management.
Data Protection Authorities Engagement and Cooperation: Liaise and cooperate with local Data Protection Authorities, ensuring an effective communication in the local language and serving as the initial point of contact supporting the EU DPO.
Data Subjects Engagement: Manage engagement with data subjects when exercising their individual rights, ensuring an effective communication in the local language.
Reporting and KPIs: Producing and reporting data protection KPIs. Provide regular updates and reports to the EU DPO and to local governance bodies and committees.
Training and Awareness and Privacy Culture: Lead the implementation of the data protection training and awareness programme at the local level. Identify local training needs and address them accordingly, while fostering a strong culture of privacy.
Data protection assurance: Manage the implementation of the data protection assurance programme at a local level, as well as conducting data protection controls.
You won’t be working in a silo! In this role, you will collaborate daily with a truly international network and cross-functional teams:
European Privacy Leadership: European Data Protection Officer (Spain) and European DP team members (Spain, Italy, and France).
UK Digital Risk Team : Head of Digital Risk, UK Data Protection Officer, and the UK DP team.
Business & Innovation Teams: Pricing, Analytics, Marketing, Development & Growth, Data & Innovation, IT, and Info Security.
Corporate Governance: Risk, Legal & Compliance teams.
Note: Occasional business travel may be required (1 to 2 times a year) to meet with international teams.
Education: Bachelor’s degree in Law + Master’s degree in Data Protection, IT Law, or Digital Law. Professional certifications (CIPP/E, CIPM, or local equivalents) are a plus.Experience: Minimum 5-7 years of hands-on working experience in data protection, ideally gained within a regulated industry (insurance or financial services preferred) or a consultancy. Proven track record in management positions, including senior stakeholder management.Legal Expertise: High-level proficiency in French and European data protection laws. Knowledge of insurance law is a plus.Languages: Fluency in French and English is a must (about 75% of the work will be done in English).Skills & CompetenciesData Protection & Privacy Expertise: Strong proficiency in risk methodologies (identification and management), Privacy by Design & Default, advisory, incident response, regulatory & data subject engagement, third-party oversight, and fostering a privacy culture.IT Tools: Hands-on practice with OneTrust, Office Suite, and GDrive. Experience with AI tools or advanced language models (e.g., Gemini, NotebookLM) is a plus.Teamwork: Ability to work seamlessly within a multinational team.Strategic Agility & Forward Thinking: Ability to align operational compliance management with broader strategic business objectives.Stakeholder Management & Influence: Capacity to provide constructive challenge to business areas while maintaining collaborative relationships at all levels.Communication: Excellent verbal and written skills, with the ability to explain complex concepts to non-experts and provide high-level summaries to senior management.Resilience & Change Management: Ability to adapt to a fast-paced environment, including evolving regulations, shifting interpretations, and technological advancements.