Data Protection Correspondent (DPC) - Italy - Porto or Lisbon
About The Job
BNPP Group Personal Data Protection framework, defined to respond to the new General Data Protection Regulation (GDPR) coming into effect on 25 May 2018, relies on the accountability of teams within BNPP entities and territories in their processing of personal data (customers, employees, UBOs, corporate representatives, vendors, etc. ).
The 1st Line of Defence (Business, IT and CDO) is responsible for embedding data protection regulations and Group policies and guidelines in the internal organization and processes within its perimeter (e. g. privacy by design, PIA, security measures, etc. ).
DPC is positioned in the 2nd line of Defence (within RISK function) and is responsible for the scope outlined under its responsibility. The DPC must assist the relevant Data Protection Officer (DPO) in supervising compliance with data protection regulations and Group policies and guidelines. Its role is to ensure second‑level controls by providing the supervision and assistance required to the 1st Line of Defence.
To ensure consistency with the Group’s management structure, a DPC is positioned at Entity or Territory level. He/she will report to the DPO of the relevant Business Line or Territory.
Your Main Activities Are
The Key Responsibilities Of a Data Protection Correspondent Are
- Communication with internal stakeholders (e. g. employees) and external stakeholders.
- Assist the Territory DPO on exchanges with the authorities in charge of the protection of personal data, in coordination with the Business Line DPO.
- Assist the Territory DPO in the supervision and monitoring of implementation of its main responsibilities, including:
- Review and advise on implementation of Group policies and guidelines on Personal Data Protection and monitor consistency in their implementation (consent collection process, cross‑border transfers, management of retention or personal data obsolescence).
- Review and advise on implementation of privacy by design principles from the design stage and during the lifecycle of all projects, products, services, activities, processes and systems.
- Provide advice on Privacy Impact Assessment (PIA), e. g. whether or not to carry out a PIA, what methodology to follow, what safeguards to apply to mitigate risks to the rights and interests of individuals and monitor that PIAs are performed correctly.
- Monitor the local implementation of Group security strategy in line with Personal Data Protection regulatory requirements.
- Contribute to risk evaluation in case a personal data breach occurs to ensure timely response.
- Participate in local Data Protection Committees when requested by the DPO.
- Support the relevant DPO to oversee the Records of Processing Activities (ROPA).
- Supervise and escalates cases of non‑compliance with regulations, data protection authorities, and local and central Senior Management.
- Assist the DPO with regards to local language, law and practices where required.
- Assist in the construction and implementation of the awareness program and contribute to the promotion of a culture of protection of personal data within its scope of responsibility.
- Assist the DPO with the second level of controls and independent data protection testing to monitor compliance with regulations and internal rules:
- Carry out second‑level controls on processes related to the protection of personal data as part of a risk‑based approach.
- Evaluate the effectiveness of the controls relating to the protection of personal data carried out by the 1st line of defence.
- 6+ years of experience with significant knowledge and experience in Data Protection/Privacy and the banking sector.
- Understanding of data processing operations, including business applications and data use.
- Experience in transversal management and working.
- Experience in interacting with regulators (plus).
- Experience managing compliance programmes on regulatory requirements.
- Strong knowledge and interest in Information Technology, digital and new technologies and understanding of information security controls and principles.
- Fluent in English (mandatory), Italian professional proficiency preferred.
- Data Protection, Risk knowledge and awareness, Risk anticipation, Data quality & Security, Regulatory, Business analytics, New technologies and digital law [IT/IP], IT risk and cyber security awareness.
- Excellent writing and communication skills – acting as a communicator across the bank on behalf of the DPO.
- Attention to detail/rigor.
- Ability to lead, engage and work transversally on behalf of the DPO.
- Independency, objectivity and integrity.
- Creativity & innovation and problem solving.
- Client focus, high level of commitment and self‑motivation, combined with enthusiasm.
- Analytical ability.
- Ability to develop and leverage networks.
- Ability to develop and adapt processes.
- Ability to conduct negotiations.
- Ability to understand, explain and support change.
- Be a role model, supporting and fostering a culture of good conduct.
- Demonstrate proactivity, transparency and accountability for identifying and managing conduct risks.
- Consider the implications of your actions on colleagues, partners and clients before making decisions.
- Take responsibility for your team’s conduct and conduct risks.
- Qualifications on Data Privacy are highly appreciated. He/she will be required to enrich his/her competencies with additional professional qualifications relevant to Data Protection, such as:
- IAPP Information Privacy Professional/Europe (CIPP/E) or Certified Information Privacy Professional/IT (CIPP/IT).
- Certified Information Privacy Manager (CIPM).
- Practitioner Certificate in Data Protection (PC. dp).
- Fellow of Information Privacy (FIP).
- ISEB Data Protection or equivalent data privacy qualification.
- Leading banking institution.
- International reach – presence in 63 countries and almost 183, 000 employees.
- Presence in Portugal – since 1985 with over 8, 700 employees across 10 business entities.
- Three core operating divisions: Retail Banking, Investment & Protection Services, Corporate & Institutional Banking.
- Diversity and inclusion commitment.
- Commitment towards work/life balance.
- Remote working conditions – Smart Working framework based on trust, autonomy and collaboration.
- Only applications submitted in English will be considered.
Confidentiality Obligation
The DPC will be bound by secrecy or confidentiality concerning the performance of his/her tasks, in accordance with applicable laws.
Profile And Skills To Success
Background
Business Skills
Behavioral Skills
Transversal Skills
Conduct
Certification
Qualifications
Why Join BNP Paribas?
Equal Employment Opportunity
BNP Paribas is an equal‑opportunity employer and proud to provide equal employment opportunity to all job seekers. We are actively committed to ensuring that no individual is discriminated against on the grounds of age, disability, gender reassignment, marriage or civil partnership status, pregnancy and maternity/paternity, race, religion or belief, sex or sexual orientation. Equity and diversity are at the core of our recruitment policy because we believe that they foster creativity and efficiency, which in turn increase performance and productivity. We strive to reflect the society we live in, while keeping with the image of our clients.
Additional Information
To find out more on why you should join BNP Paribas, visit https://bnpp. lk/why-BNP-Paribas-Portugal.
In case you are selected for this role, further documentation will be requested to support your hiring process.
- Informações detalhadas sobre a oferta de emprego
Empresa: Phiture Localização: Lisboa
Lisboa, Lisboa, PortugalPublicado: 18. 11. 2025
Vaga de emprego atual
Seja o primeiro a candidar-se à vaga de emprego oferecida!