Data Protection Officer
Function
We’re looking for an experienced Data Protection Officer to join our client’s organization in a critical and highly independent position. As DPO, you will play a key role in ensuring compliance with GDPR and applicable data protection legislation, while advising senior management and business units on privacy risks, governance, and regulatory requirements. You will operate independently, report directly to senior management, and act as the organization’s central point of contact for data protection matters.
Role & Responsibilities
- Monitor compliance with GDPR, data protection legislation, and relevant regulatory requirements, including Articles 5, 6, 24, 25, 30, 32, 33–36 and 37–39.
- Advise management and internal departments on their data protection obligations and provide practical recommendations.
- Develop, maintain, and monitor a coherent data protection governance framework, including roles, responsibilities, procedures, controls, and reporting mechanisms.
- Report to senior management on compliance status, privacy risks, incidents, and opportunities for improvement.
- Maintain the independence of the DPO function and proactively identify and avoid potential conflicts of interest.
- Oversee the creation and maintenance of the Record of Processing Activities (RoPA), supporting departments in documenting processing activities, purposes, legal bases, retention periods, and data flows.
- Advise on and oversee Data Protection Impact Assessments (DPIAs), including mitigation measures, residual risks, and prior consultation with the relevant supervisory authority where required.
- Promote privacy-by-design and privacy-by-default principles across projects, processes, and digital initiatives.
- Advise on strategic initiatives, transformation projects, contracts, outsourcing arrangements, and partnerships from a data protection perspective.
- Review data processing agreements and privacy-related contractual clauses and monitor compliance by processors and external partners.
- Advise on personal data breaches, including assessment, documentation, escalation, and statutory notification requirements within the applicable deadlines.
- Help establish effective incident and escalation mechanisms to ensure data breaches can be assessed and handled promptly.
- Act as the organization’s contact point for the relevant Data Protection Authority and cooperate with supervisory authorities where appropriate.
- Support audits, inspections, and compliance controls relating to data protection.
- Develop and support awareness and training initiatives and promote a strong privacy culture throughout the organization.
- Act as a central privacy contact point for employees, management, departments, and data subjects, including the coordination of questions, notifications, and potential privacy incidents.
- Prepare periodic reports, recommendations, policies, guidelines, procedures, and control frameworks relating to personal data protection.
Profile & Experience
The ideal candidate combines strong legal and regulatory knowledge with extensive practical experience in data protection and risk management.
- Minimum 8 years of professional experience, including at least 5 years of relevant experience in personal data protection.
- Thorough knowledge of GDPR, data protection principles, and related legislation.
- Strong legal affinity and the ability to assess and advise on data processing agreements, contractual clauses, and collaboration agreements.
- 5–7 years of experience with risk assessment methodologies, such as DPIA frameworks.
- At least 4 years of technical experience with secure data exchange between public-sector organizations or similarly regulated environments.
- At least 5 years of experience contributing to or leading the development and implementation of data protection policies, guidelines, procedures, and control frameworks.
- Demonstrable experience acting as an external DPO for large organizations, supported by at least three relevant references.
- Experience working with senior stakeholders and translating complex regulatory requirements into clear, practical advice for non-legal audiences.
- Knowledge of NIS2 and/or relevant cybersecurity frameworks is an advantage.
- Previous experience within a public-sector or government environment is a plus.
Competencies & Languages
You are an independent, analytical, and decisive professional who is comfortable challenging decisions when data protection risks are not adequately addressed. You communicate clearly, handle confidential and sensitive information with a high degree of integrity, and are able to identify potential risks before they become incidents. Strong collaboration skills and the ability to make complex legislation accessible to non-specialist audiences are essential.
The organization operates in a bilingual environment. You must have an excellent command of either Dutch or French and be able to understand and communicate effectively in the other national language.
Contactperson & Reference
- Reference #: INW27648
- Pieter Messely
- pieter.messely@i4m.be