CDICourbevoie, France
Privacy Counsel – GDPR & Data Protection - Finance
Hybride
Contexte de la mission
A leading European financial markets infrastructure group is looking for an experienced Privacy Counsel to support its Data Protection Office and Group Data Protection Officer.
The consultant will join an international and highly regulated environment and will provide day-to-day legal and operational support on GDPR, local privacy regulations and emerging data-related requirements.
The role will involve working with Legal, Compliance, Information Security, IT, HR, Procurement, Marketing and business teams across several European jurisdictions.
Objectifs et livrables
The consultant will be responsible for providing practical and business-oriented privacy advice across the Group.
Key activities will include:
Advising business and corporate functions on GDPR and local data protection requirements.
Monitoring regulatory developments, including EDPB guidance, supervisory authority decisions, ePrivacy and the EU AI Act.
Preparing clear legal opinions, recommendations and implementation guidance.
Maintaining and updating Records of Processing Activities under Article 30 GDPR.
Drafting and reviewing privacy policies, procedures, standards and privacy notices.
Conducting and reviewing DPIAs and legitimate interest assessments.
Supporting privacy by design and privacy by default initiatives.
Reviewing AI, automated decision-making, data and digital transformation projects.
Drafting, reviewing and negotiating DPAs, data-sharing agreements and other privacy-related contractual arrangements.
Advising on international data transfers, SCCs and Transfer Impact Assessments.
Supporting third-party privacy due diligence and vendor assessments.
Coordinating responses to data subject requests.
Supporting personal data breach management, remediation and regulatory notifications.
Contributing to regulator interactions and responses to supervisory authority requests.
Designing and delivering privacy awareness and training sessions.
Preparing privacy metrics, dashboards and reporting for senior stakeholders and governance committees.
Coordinating with local privacy contacts across multiple European countries.
Required skills and experience
Law degree; qualification or admission in an EU jurisdiction is a strong advantage.
4 to 7 years of relevant experience in privacy, data protection or technology law.
Strong working knowledge of the GDPR and at least one European national data protection framework.
Proven experience with DPIAs, RoPA, legitimate interest assessments and privacy governance.
Strong drafting and negotiation skills, particularly for DPAs and data transfer arrangements.
Good understanding of DSAR management and personal data breach response.
Experience with privacy by design and privacy assessments for digital, data or technology projects.
Knowledge of the EU AI Act, ePrivacy or data governance is an advantage.
Experience in financial services, capital markets or another regulated industry is preferred.
Excellent stakeholder management, communication and organisational skills.
Ability to translate complex legal requirements into clear and actionable business guidance.
Fluency in English is required.
French, Dutch, Italian or Portuguese language skills are a strong plus.
Contact
manon.langlais@littlebigconnection.com
+33 7 44 09 14 90
Informations de la mission :
A leading European financial markets infrastructure group is looking for an experienced Privacy Counsel to support its Data Protection Office and Group Data Protection Officer.
The consultant will join an international and highly regulated environment and will provide day-to-day legal and operational support on GDPR, local privacy regulations and emerging data-related requirements.
The role will involve working with Legal, Compliance, Information Security, IT, HR, Procurement, Marketing and business teams across several European jurisdictions.
Objectifs et livrables
The consultant will be responsible for providing practical and business-oriented privacy advice across the Group.
Key activities will include:
Advising business and corporate functions on GDPR and local data protection requirements.
Monitoring regulatory developments, including EDPB guidance, supervisory authority decisions, ePrivacy and the EU AI Act.
Preparing clear legal opinions, recommendations and implementation guidance.
Maintaining and updating Records of Processing Activities under Article 30 GDPR.
Drafting and reviewing privacy policies, procedures, standards and privacy notices.
Conducting and reviewing DPIAs and legitimate interest assessments.
Supporting privacy by design and privacy by default initiatives.
Reviewing AI, automated decision-making, data and digital transformation projects.
Drafting, reviewing and negotiating DPAs, data-sharing agreements and other privacy-related contractual arrangements.
Advising on international data transfers, SCCs and Transfer Impact Assessments.
Supporting third-party privacy due diligence and vendor assessments.
Coordinating responses to data subject requests.
Supporting personal data breach management, remediation and regulatory notifications.
Contributing to regulator interactions and responses to supervisory authority requests.
Designing and delivering privacy awareness and training sessions.
Preparing privacy metrics, dashboards and reporting for senior stakeholders and governance committees.
Coordinating with local privacy contacts across multiple European countries.
Required skills and experience
Law degree; qualification or admission in an EU jurisdiction is a strong advantage.
4 to 7 years of relevant experience in privacy, data protection or technology law.
Strong working knowledge of the GDPR and at least one European national data protection framework.
Proven experience with DPIAs, RoPA, legitimate interest assessments and privacy governance.
Strong drafting and negotiation skills, particularly for DPAs and data transfer arrangements.
Good understanding of DSAR management and personal data breach response.
Experience with privacy by design and privacy assessments for digital, data or technology projects.
Knowledge of the EU AI Act, ePrivacy or data governance is an advantage.
Experience in financial services, capital markets or another regulated industry is preferred.
Excellent stakeholder management, communication and organisational skills.
Ability to translate complex legal requirements into clear and actionable business guidance.
Fluency in English is required.
French, Dutch, Italian or Portuguese language skills are a strong plus.
Contact
manon.langlais@littlebigconnection.com
+33 7 44 09 14 90
Informations de la mission :
- Début de mission : 27/09/2026
- Durée : 7 mois
- Date de publication : 16/09/2026
- Date limite de candidature : 20/09/2026
Compétences recherchées
GDPR (Indispensable)DPIA (Indispensable)RoPA (Indispensable)DPA (Indispensable)SCCs (Indispensable)Transfer Impact Assessments (Indispensable)DSAR (Indispensable)EU AI Act (Indispensable)ePrivacy (Indispensable)privacy by design (Indispensable)data governance (Indispensable)automated decision-making (Indispensable)Data governance (Indispensable)National data protection framework (Indispensable)Legitimate interest assessments (Indispensable)Privacy governance (Indispensable)English (Apprécié)
Intéressé(e) ?
Rejoignez l'équipe et participez à nos projets ambitieux.