Privacy Counsel (GDPR & Data Protection)

Extia

Porto

Presencial

EUR 60 000 - 90 000

Tempo integral

há 28 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te para esta função — gera um currículo e uma carta de apresentação personalizados em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

Extia is seeking a Privacy Counsel / GDPR Lawyer with 4 to 7 years of relevant experience to provide GDPR and privacy legal advice across multiple jurisdictions. The role requires a law degree and strong knowledge of GDPR and national privacy laws, with a focus on DPAs, DPIAs, and data transfers.

Fluent English is essential, with optional proficiency in other EU languages. The position is based in Porto, Portugal, in a fast-paced, international environment.

Qualificações

  • 4 to 7 years of relevant professional experience in data protection/privacy.
  • Law degree, with EU legal qualification/admission strongly preferred.
  • Strong hands-on knowledge of the GDPR and national privacy laws.
  • Experience with privacy governance, RoPAs, DPIAs, legitimate interest assessments, privacy policies, and regulatory monitoring.
  • Strong experience with DPAs, data-sharing arrangements, SCCs, and international data transfers.
  • Experience managing DSARs and personal data breach/incident response.
  • Strong drafting, negotiation, stakeholder management, and communication skills.
  • Fluent English is required; knowledge of French, Dutch, Italian, or Portuguese is a strong plus.

Responsabilidades

  • Provide GDPR and privacy legal advice to the business across multiple jurisdictions.
  • Monitor developments in EU and national privacy legislation, EDPB guidelines, and supervisory decisions.
  • Assess regulatory developments and translate them into practical guidance, policies, and procedures.
  • Provide clear and pragmatic legal opinions on complex privacy matters balancing regulatory requirements with business objectives.
  • Establish and update Records of Processing Activities across entities and functions.
  • Draft and maintain Group privacy policies, standards, and privacy notices.
  • Conduct DPIAs and legitimate interest assessments, identifying risks and mitigation measures.
  • Embed privacy by design and by default into products, services, and initiatives.
  • Advise on privacy aspects of AI and data-driven initiatives, including the EU AI Act.
  • Draft and negotiate DPAs, SCCs, and data-sharing agreements.

Descrição da oferta de emprego

You want to join a company that places people at the heart of its concerns? We are waiting for you at Extia!

Extia is an engineering consultancy which proposes since 2007 an unprecedented approach in its sector by combining well-being and performance at work. A successful model: more than 3000 Extians working in 22 agencies in France and abroad, 1st Great Place To Work® in France, 160 millions of euros of turnover and plenty of energy!

At Extia, it's "First who, then what" so, let's do it!

First who:
  • Experienced Privacy Counsel / GDPR Lawyer with 4 to 7 years of relevant professional experience in data protection and privacy, gained in-house, in a law firm, or in consultancy
  • Law degree, with qualification/admission in an EU jurisdiction strongly preferred
  • Strong, demonstrable knowledge of the GDPR and national data protection laws
  • Good understanding of privacy governance, regulatory monitoring, DPIAs, RoPAs, data subject rights, and data breach management
  • Strong experience drafting, reviewing, and negotiating Data Processing Agreements (DPAs), data-sharing agreements, and international data transfer arrangements
  • Ability to translate complex legal and regulatory requirements into clear, practical, and business-oriented advice
  • Rigorous, well-organised, autonomous, and comfortable managing multiple priorities in a fast-paced, international environment
  • Fluent English is required;
Then what:
What You'll Do:
  • Provide GDPR and privacy legal advice to the business across multiple jurisdictions
  • Monitor developments in EU and national privacy legislation, EDPB guidelines, supervisory authority decisions, ePrivacy, the EU AI Act, data governance, and financial-services data regulations
  • Assess regulatory developments and translate them into practical guidance, policies, and procedures
  • Provide clear and pragmatic legal opinions on complex privacy matters, balancing regulatory requirements with business objectives and risk appetite
  • Establish, maintain, and update Records of Processing Activities (RoPAs) across entities and functions
  • Draft, review, and maintain Group privacy policies, standards, internal guidelines, procedures, and privacy notices
  • Conduct and review Data Protection Impact Assessments (DPIAs) and legitimate interest assessments, identifying risks and recommending proportionate mitigation measures
  • Embed privacy by design and by default principles into new products, services, systems, and business initiatives
  • Provide privacy advice on AI, data-driven initiatives, automated decision-making, and new technologies, including consideration of the EU AI Act
  • Draft, review, and negotiate DPAs, controller-to-controller and controller-to-processor arrangements, and data-sharing agreements
  • Advise on international and intra-group data transfers, including Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs)
  • Assess the privacy posture of vendors and third parties as part of procurement and third-party risk management
  • Manage and coordinate data subject requests (DSARs), ensuring compliance with statutory deadlines
  • Manage the personal data breach and incident response process end to end, including triage, risk assessment, remediation, record-keeping, and regulatory notifications where required
What We're Looking For:
  • 4 to 7 years of relevant professional experience in data protection/privacy
  • Law degree, with EU legal qualification/admission strongly preferred
  • Strong hands-on knowledge of the GDPR and national privacy laws.
  • Experience with privacy governance, RoPAs, DPIAs, legitimate interest assessments, privacy policies, and regulatory monitoring
  • Strong experience with DPAs, data-sharing arrangements, SCCs, and international data transfers
  • Experience managing DSARs and personal data breach/incident response
  • Strong drafting, negotiation, stakeholder management, and communication skills
  • Ability to work independently, manage multiple priorities, and take ownership of matters through to resolution
  • Fluent English is required; French, Dutch, Italian, or Portuguese is a strong plus
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector
Devoteam Cyber Trust | Privacy Counsel (GDPR & Data Protection) | FinTech Sector

Devoteam • Porto

Presencial
EUR 70 000 - 100 000
Professional development and talent
Commitment to employees' development
Growth-focused collaboration
+1
Global Privacy Counsel: GDPR & Data Protection
Global Privacy Counsel: GDPR & Data Protection

Extia • Porto

Presencial
EUR 60 000 - 90 000
Privacy Counsel, GDPR and Data Protection
Privacy Counsel, GDPR and Data Protection

LUZA Group • Porto

Híbrido
EUR 45 000 - 65 000
Remote work whenever possible
Equipment provided
Benefits plan
AI Privacy Engineer / Data Protection | Lisbon | Hybrid
AI Privacy Engineer / Data Protection | Lisbon | Hybrid

Decskill • Lisboa

Híbrido
EUR 60 000 - 85 000
AI Privacy Engineer
AI Privacy Engineer

UltraCon Consultoria • Portugal

Presencial
EUR 45 000 - 75 000
AI Privacy Engineer / Data Protection Coordinator
AI Privacy Engineer / Data Protection Coordinator

Planck Technologies • Lisboa

Híbrido
EUR 45 000 - 70 000
Ai Privacy Engineer
Ai Privacy Engineer

Ultracon Consultoria • Lisboa

Presencial
EUR 70 000 - 90 000
AI Privacy Engineer
AI Privacy Engineer

Axians Portugal • Lisboa

Presencial
EUR 60 000 - 90 000
Health insurance
Employee assistance program
Training & certifications
Data Protection Officer
Data Protection Officer

Pipedrive • Lisboa

Presencial
EUR 60 000 - 90 000
Performance-based bonuses
Stock options
28 days paid leave
+3
AI Privacy Engineer / Data Protection
AI Privacy Engineer / Data Protection

Expleo Group • Lisboa

Presencial
EUR 60 000 - 90 000