Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector

Devoteam

Porto

Presencial

EUR 70 000 - 100 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura completa num minuto — currículo e carta de apresentação personalizados, prontos a enviar.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Professional development and talent
Commitment to employees' development
Growth-focused collaboration
Strong organisational culture

Resumo da oferta

Devoteam Cyber Trust in Porto, Portugal, seeks a Privacy Counsel (GDPR & Data Protection) for the FinTech sector. You will advise on GDPR, implement RoPA controls, and manage data transfer agreements across the group.

Strong drafting, negotiation, and stakeholder skills are essential. This permanent, full-time role requires 4–7 years in data protection, fluency in English, and a proactive, business‑oriented mindset to balance legal requirements with risk.

Qualificações

  • Law degree and EU admission strongly preferred.
  • 4–7 years of experience in data protection/privacy, in-house or advisory.
  • Strong knowledge of GDPR and national privacy laws across Europe.
  • Excellent drafting and negotiation skills for DPAs and data transfers.
  • Fluency in English is required; another European language is a plus.

Responsabilidades

  • Advise on GDPR and national privacy laws across the Group’s European markets.
  • Draft, review and update privacy policies, notices and procedures.
  • Lead DPIAs, risk assessments and data transfer governance.
  • Provide privacy input to transformation, digital, marketing and data initiatives.
  • Manage data subject requests and breach response with regulators and stakeholders.

Conhecimentos

English fluency
Leadership
Stakeholder management
Analytical thinking

Formação académica

Law degree

Descrição da oferta de emprego

Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector
  • Full-time
  • Contract type: Permanent contract

Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.

Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.

The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.

Advisory & Regulatory Guidance

GDPR & local law advice — Act as a trusted adviser to the business on the interpretation and application of the GDPR and national data protection laws across the Group's European markets, including local implementing legislation and sector-specific rules.

Regulatory monitoring — Track developments in EU and national privacy law, EDPB guidelines, supervisory authority decisions and related regimes, including ePrivacy, the EU AI Act, data governance and financial-services data rules. Assess their impact and translate them into practical guidance and updated policies.

Legal opinions — Provide clear, pragmatic written and verbal advice on complex privacy questions, balancing legal requirements with business objectives and risk appetite.

Privacy Governance & Documentation

Records of Processing (RoPA) — Establish, maintain and update the Article 30 records of processing activities across entities and functions.

Policies & procedures — Draft, review and maintain Group privacy policies, standards, internal guidelines, procedures and privacy notices, ensuring they remain aligned with regulatory developments.

DPIAs & risk assessments — Conduct and review Data Protection Impact Assessments and legitimate interest assessments, identify risks and recommend proportionate mitigation measures.

Privacy by Design, Projects & New Technology

Privacy by design & by default — Embed privacy requirements into new products, services, systems and business initiatives from the outset.

AI & new technology — Review data-driven, automated decision-making and artificial intelligence initiatives for privacy risk, coordinating with Legal, Technology and Risk teams and considering the interplay with the EU AI Act.

Project support — Provide privacy input to transformation, digital, marketing and data initiatives across the Group.

Vendors, Contracts & Data Transfers

Data Processing Agreements — Draft, review and negotiate DPAs, controller-to-controller and controller-to-processor arrangements and data-sharing agreements with vendors, clients and partners.

International transfers — Advise on cross-border and intra-group data transfers, implement Standard Contractual Clauses (SCCs) and conduct transfer impact assessments.

Third-party due diligence — Assess the privacy posture of vendors and third parties as part of procurement and third-party risk management.

Data Subject Rights & Incident Response

Data subject requests (DSARs) — Manage and coordinate responses to access, rectification, erasure, portability, objection and other data subject rights requests within statutory deadlines.

Breach & incident response — Manage the personal data breach process end to end, including triage, risk assessment, remediation, record-keeping and notifications to supervisory authorities and data subjects where required.

Regulator liaison — Support engagement with supervisory authorities on notifications, queries and investigations.

Training & awareness — Design and deliver privacy training and awareness sessions and promote a strong data protection culture across the Group.

Stakeholder cooperation — Work closely with Legal, Information Security, IT, HR, Procurement, Marketing and the business, and coordinate with local privacy contacts across jurisdictions.

Reporting — Prepare privacy metrics, dashboards and updates for compliance management, senior stakeholders and relevant governance committees.

Law degree; qualification/admission in an EU jurisdiction is strongly preferred.

4 to 7 years of relevant experience in data protection/privacy, gained in-house and/or in a law firm or consultancy.

Strong, demonstrable working knowledge of the GDPR and of national privacy laws in at least one relevant European jurisdiction.

Experience in financial services, market infrastructure or another regulated environment is an advantage.

Ability to translate complex legal requirements into clear, practical and business-oriented advice.

Strong drafting and negotiation skills, particularly for DPAs and data transfer arrangements.

Rigorous, well-organised and able to manage multiple priorities autonomously in a fast-paced environment.

Excellent stakeholder management and communication skills, comfortable engaging with senior management.

Fluency in English is required; an additional European language such as French, Dutch, Italian or Portuguese is a strong plus.

Sound judgement, discretion and a high standard of professional integrity when handling confidential information.

Team spirit — A genuinely collaborative mindset, contributing positively to the Data Protection Office and building trusted relationships across teams and jurisdictions.

Leadership — The ability to take ownership of matters, drive them to resolution and constructively influence and guide stakeholders, including in the absence of direct authority.

Dynamism — An energetic, proactive and solutions-oriented approach, adapting readily to change and thriving in a fast-moving, international environment.

The Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

What we offer:

  • Professional development and monitoring talent;
  • Commitment to our employees' development;
  • Collaboration in a company that is constantly growing and evolving.
  • Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Privacy Counsel (GDPR & Data Protection)
Privacy Counsel (GDPR & Data Protection)

Extia • Porto

Presencial
EUR 60 000 - 90 000
Privacy Counsel: GDPR & Data-Protection Strategist
Privacy Counsel: GDPR & Data-Protection Strategist

Devoteam • Porto

Presencial
EUR 70 000 - 100 000
Professional development and talent
Commitment to employees' development
Growth-focused collaboration
+1
Devoteam Cyber Trust Privacy Counsel GDPR & Data Protection FinTech Sector
Devoteam Cyber Trust Privacy Counsel GDPR & Data Protection FinTech Sector

OpenTalent • Porto

Presencial
EUR 50 000 - 80 000
Privacy Counsel, GDPR and Data Protection
Privacy Counsel, GDPR and Data Protection

LUZA Group • Porto

Híbrido
EUR 45 000 - 65 000
Remote work whenever possible
Equipment provided
Benefits plan
Devoteam Cyber Trust | Cybersecurity Analyst
Devoteam Cyber Trust | Cybersecurity Analyst

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 40 000 - 60 000
Professional development and monitoring talent
Commitment to employee development
Collaboration in a growing company
+1
AI Privacy Engineer / Data Protection | Lisbon | Hybrid
AI Privacy Engineer / Data Protection | Lisbon | Hybrid

Decskill • Lisboa

Híbrido
EUR 60 000 - 85 000
Personal Data Protection Analyst – GDPR
Personal Data Protection Analyst – GDPR

act digital • Lisboa

Híbrido
EUR 30 000 - 52 000
Devoteam Cyber Trust | Cyber Security Engineer
Devoteam Cyber Trust | Cyber Security Engineer

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 35 000 - 60 000
Equal opportunity employer
Diversity-focused workplace
Data Protection Officer
Data Protection Officer

Pipedrive • Lisboa

Presencial
EUR 60 000 - 90 000
Performance-based bonuses
Stock options
28 days paid leave
+3
Devoteam Cyber Trust | Application Security - Lead | Banking Sector
Devoteam Cyber Trust | Application Security - Lead | Banking Sector

Devoteam • Viseu

Presencial
EUR 45 000 - 65 000