Data Protection & Compliance Officer
Hybrid (Office & Remote), Full Time
Fixed-term contract: 2 years
One of the market leaders in Employee Rewards and Benefits is hiring! Join the great team of this competitive employer (Bucharest offices) and take the opportunity to work in a fulfilling and stable environment.
Responsibilities:
Data Protection Responsibilities:
- Monitors and evaluates compliance with personal data protection legislation and the internal policies applicable across the company and its affiliates;
- Advise the company, its affiliates, and internal departments on data protection obligations, including within new projects, processes, products, and services;
- Coordinate and/or participate in Data Protection Impact Assessments (DPIAs), internal audits, and relevant compliance reviews;
- Manage, investigate, and document information security incidents and personal data breaches, proposing corrective and preventive measures;
- Prepare and maintain records of processing activities, registers, privacy notices, procedures, policies, and reports related to data protection;
- Draft and review contractual documentation related to personal data protection, including but not limited to Data Processing Agreements (DPAs);
- Act as a point of contact with the Supervisory Authority and support responses to data subject requests;
- Organize and deliver data protection and privacy awareness training sessions and communication campaigns.
Compliance Responsibilities:
- Monitor and assess compliance with applicable regulatory requirements, internal policies, and Group standards;
- Conduct compliance risk assessments and recommend preventive, mitigating, and corrective actions;
- Support the implementation and regular update of compliance policies and procedures, including those related to ethics, anti-corruption, conflicts of interest, and whistleblowing/reporting;
- Investigate, document, and monitor the remediation of compliance incidents and reports within the scope of the role;
- Prepare compliance reports for management, the Group, and, where applicable, competent authorities;
- Deliver compliance, ethics, and integrity training and provide guidance to employees;
- Collaborate with internal departments to integrate compliance and data protection requirements into operational processes.
Administrative Responsibilities:
- Prepare reports, statistics, documentation, and action plans related to assigned activities, ensuring accuracy and timely delivery;
- Perform any other duties related to the role as assigned by the direct manager, in accordance with professional experience, competencies, and the applicable legal framework.
Requirements:
- Bachelor’s degree in Law, Economics, Information Security, Business Administration, or another relevant field;
- Minimum of 3–5 years of experience in data protection, compliance, audit, risk management, legal, or related fields;
- Professional certifications such as CIPP/E, CIPM, Certified Data Protection Officer (DPO), CCEP, or equivalent are considered an advantage;
- Strong knowledge of personal data protection legislation, including the General Data Protection Regulation (GDPR), applicable national legislation, and privacy and information security best practices;
- Good understanding of compliance requirements, ethics, anti-corruption, conflicts of interest, internal investigations, reporting obligations, and internal policies;
- Proven ability to conduct compliance risk assessments, Data Protection Impact Assessments (DPIAs), audits, controls, and remediation plans;
- Experience in investigating and managing compliance incidents, information security incidents, and personal data breaches;
- Ability to develop, update, and implement policies, procedures, registers, reports, and training materials;
- Excellent communication, stakeholder management, and training skills, with the ability to work effectively with internal departments, regulatory authorities, customers, suppliers, and other stakeholders;
- Excellent written and spoken English;
- High level of integrity, professional ethics, attention to detail, analytical thinking, confidentiality, professional independence, and a solution-oriented mindset.
Benefits:
- Flexible hybrid working environment
- The 13th salary
- Meal, Gift & Holiday vouchers
- Medical subscription & medical insurance
- Life insurance
- And many more
You can apply for this job by sending your CV to the following e-mail address office@hrgold.ro