Data Protection Risk Advisor
About The Job
The Data Protection Advisor will act as a trusted advisor for BNP Paribas Business and Functions and oversight BNP Paribas DPOs, to assist in the implementation, management and monitoring of the DPP strategy, by supporting the definition, implementation and operationalization of the Group's DPP framework by Group Entities.
Your Main Activities Are
As part of their responsibilities, the candidate will coordinate and oversight activities in relation to the following:
- Advising on the maintenance of the Group's DPP (Data Protection and Privacy) Governance and framework, as well as the definition and creation of DPP policies, guidelines and procedures of Group BNP Paribas
- Independent review and challenge of the technical and operational DPP controls implemented and issue recommendations with regards to privacy, data protection and compliance with the Group BNP Paribas DPP framework and regulation (e. G. GDPR, CCPA, LGPD, PDPA, etc)
- Act as a trusted advisor of key internal stakeholders (e. G. CDOs, CISOs, DPOs, Business…) regarding manage DPP requirements, such as:
- Oversight and check & challenge complex and transversal DPP initiatives, design and rollout of the DPP strategy, and strategy implementation.
- Oversight and check & challenge transversal and complex Group wide data processing/ initiative impact assessments (DPIA), notable the adequacy of controls and measures, controllership, transfers, etc.
- Identify key DPP risks, inform BNP Paribas' Management and key stakeholders such IT and Business among other, and oversight the decisions to manage those risks.
- Oversight key Group data breaches and other DPP incidents and work with key stakeholders (such CDO, CISO, DPO, IT, Legal, etc. ) on the risk identification, ensure the consistency of potential incidents qualification, conduct post mortem analysis, and validate the adequacy and solutions implementation.
- Monitor and advice on the interactions with authorities and other external stakeholders, analyzing the requests, actions to be taken and producing lessons learned among the BNP Paribas worldwide DPP community.
- Monitor global regulatory changes and authority decisions, share and provide advice on DPP risk anticipation to the DPP community, providing lessons learned, best practices and guidelines, and leveraging on the BNP Paribas DPP knowledge basis.
- Promote data protection awareness and privacy by design culture across the Group (e. G. governance, principles of data processing, data subjects' rights, data protection by design and by default, records of processing activities, security, data breach, authority interactions), and influencing/advising the Group Learn & Development agenda/ plans.
- Attend regular/ ongoing data protection, information security, privacy training and continuous improvement.
Profile And Skills To Success
- University degree and relevant professional certifications (e. G. CIPP/E, CIPT, CIPM, ISO27001, etc. ) in fields relevant to DPP and cybersecurity
- Desirable experience working for a
- national company from a central position (e. G. Group/ Head office level), preferably in the Financial sector - Experience working as a consultant, advisor or auditor in initiatives related with data management, data protection, privacy and information security (notably Privacy by Design and Data Flow Mapping), preferably in a relevant audit/ consulting Firm
- Has experience analysing potential privacy incidents to proactively mitigate risk, in determining reporting requirements and corrective action plans when needed
- Desirable experience of promoting a data privacy culture and awareness
- Experience in communicating and presenting effectively to senior management and
- making individuals within the organization - Experience of working with and managing stakeholders from different disciplinary backgrounds (e. G. IT, Risk, CDO and Data management, Legal, Compliance, Security, HR, etc. ), notably providing technical advice and producing technical deliverables
- English Fluent mandatory
- French is a plus
Technical Skills
- Understands information security controls and principles that ensure confidentiality, integrity, availability of sensitive information
- Understanding of
- scale technology infrastructure and programmes where large quantities of data are used/managed - Has a hybrid understanding of cross over requirements (risk, IT, regulatory, data security)
- Is able to evaluate DPP policies, regulations and decisions, and produce actionable insight
- Familiarity with privacy and security risk assessment, best practices and gap analysis, privacy certifications/seals, information security and DPP certifications, and tools
- Personal Skills and Behaviours
- Good interpersonal skills and ability to collaborate across business lines and geographies
- Ability to work in a
- cultural,
- lingual environment adapting ways of working as required - Good communication skills
- Rigor and attention to details
- Flexibility and customer orientation
About The Team
- BNPP Group Personal Data Protection framework, defined to respond to applicable privacy regulations throughout BNPP territories, relies on the accountability of teams within BNPP entities in their processing of Personal Data (customer, employees, UBOs, representatives of corporate, vendors, etc. )
- Data Protection Office (DPO) is part of the RISK Department within BNP Paribas, positioned in the 2nd Line of Defence. Integrated within the Iberian Centre of Excellence, the DPC must assist the Business Line DPO and contribute to supervise the compliance with data protection regulations and Group policies and guidelines, oversighting/ensure the control framework, and give the necessary guidance/advice to support the 1st Line of Defence.
- The 1st Line of Defence (Business, IT and CDO), managing the operations, has the responsibility to embed data protection regulations and Group policies and guidelines in the internal organization, processes and tools/assets (e. G. IT, DB's, contracts, etc. ) within its perimeter (e. G. privacy by design, PIA, security measures, etc. ).
Why joining BNP Paribas?
- Leading banking institution
BNP Paribas is the European Union's leading
- Informações detalhadas sobre a oferta de emprego
Empresa: BNP Paribas Localização: Viseu
Viseu, Viseu District, PortugalPublicado: 12. 11. 2025
Vaga de emprego atual
Seja o primeiro a candidar-se à vaga de emprego oferecida!