- Company Name
- Berger-Levrault
- Job Title
- Délégué à la protection des données (DPO) F/H
- Job Description
-
Job title: Data Protection Officer (DPO)
Role Summary: Provide executive oversight of personal data governance across a multinational software and SaaS organization, ensuring GDPR and ISO 27001/27701 compliance, integrating privacy by design into product development, managing incidents, and representing the company to supervisory authorities.
Expactations: 5‑10 years in a senior data protection role, preferably within a tech/consulting environment, strong legal foundation, professional French and English, Spanish is a plus, and a recognized DPO certification (CIPP/E, AFNOR, etc.).
Key Responsibilities:
- Lead and coordinate the Group’s personal data governance, collaborating with local DPOs and designated counterparts.
- Draft, update, and deploy internal data protection policies, procedures, and best‑practice guidelines.
- Maintain and update mandatory registers (processing activities, processors, requests), conduct DPIAs, and audit processors and third‑party services.
- Review and approve contractual clauses and commitments related to data protection in tenders and vendor agreements.
- Embed privacy by design principles into new software and digital service projects from the architectural phase.
- Process and respond to individuals’ rights requests and client compliance inquiries.
- Manage data breach incidents in partnership with the CSO, product owners, and technical teams—coordinating analysis, remediation, notification, and reporting.
- Organize internal awareness, training, and audit activities, while ensuring continuous regulatory monitoring.
- Serve as the Group’s primary liaison with the CNIL and other supervisory authorities.
Required Skills:
- Expert knowledge of the GDPR, ISO 27001/27701, and non‑EU data protection regulations (Canada, Switzerland, etc.).
- Legal drafting, policy development, and contractual review experience.
- Conducting DPIAs, data processing audits, and incident response.
- Strong collaboration with technical teams (project managers, developers, CSO) and ability to translate legal requirements into technical controls.
- Excellent communication, stakeholder management, and training delivery skills.
- Proficiency in professional English; French required; Spanish an advantage.
Required Education & Certifications:
- Master’s degree or equivalent in Digital Law, Data Protection Law, or related field.
- Valid DPO certification (CIPP/E, AFNOR, ISO or equivalent) preferred.