GDPR Specialist
Start Date: Immediate
End Date: To be determined
Location: Belgium
Responsibilities:
- Support the Data Protection Officer (DPO) in maintaining the Register of Data Processing Activities by identifying stakeholders, conducting interviews, and providing guidance for updating data processing activities.
- Perform GAP analysis based on the Register of Processing Activities (ROPA), including assessments, security checks, and identifying missing Data Processing Agreements (DPAs).
- Raise awareness, develop training materials, and provide training to employees on privacy-related obligations.
- Assist the Customer Support Team in responding to Data Subject Requests and escalate privacy, security, or fraud issues to the DPO.
- Collaborate with the IT Security Team to investigate data breaches, analyze risks, and follow up on action plans to address vulnerabilities.
- Review and negotiate Data Processing Agreements with vendors.
- Review GDPR Questionnaires completed by vendors and provide advice to the business.
- Support the business in performing Data Protection Impact Assessments (DPIA) and follow up on risk mitigation measures.
- Conduct Transfer Impact Assessments (TIA) and follow up on risk mitigation measures.
- Provide GDPR advice on marketing, sales, IT, and other matters.
- Perform GDPR analysis of new partnerships, including legal grounds of data processing and data flows.
- Support the business in implementing action plans from internal or external GDPR audits.
- Assist in drafting and rolling out the Privacy Coordinators Program.
- Aid in the implementation of the Privacy Automation Tool.
Skills:
- Excellent analytical and problem-solving skills with the ability to assess risks and develop mitigation strategies.
- Strong communication and interpersonal skills for effective collaboration with stakeholders at all levels.
- Ability to work independently and prioritize tasks in a fast-paced environment.
Requirements:
- University education or equivalent in Legal, IT, or Business. Additional certifications in data protection or privacy (e.g., CIPP/E, CIPIM) are a plus.
- At least 2 years of experience in data protection compliance.
- Strong knowledge of applicable data protection laws and regulations, including GDPR and the Belgian data protection framework, as well as relevant EU guidelines (EDPB, ENISA).
- Good knowledge of IT systems, processes, and data management practices.
- Experience in the energy sector is a plus.
- Language proficiency: Fluent in English, with knowledge of French or Dutch.