About the assignment
You are the organisation's conscience on data protection. You translate GDPR requirements and data privacy principles into actionable policies and processes that protect the organisation and build stakeholder trust.
Your role bridges compliance, legal, and operations. You advise business units on privacy risks, design consent mechanisms, and handle data subject rights requests. You ensure privacy-by-design is embedded across systems and processes.
You drive compliance maturity. You conduct privacy impact assessments, monitor regulatory changes, and report on compliance posture to leadership.
Your responsibilities
- Develop, maintain, and update privacy policies aligned with GDPR, AI Act, and local data protection laws
- Conduct Data Protection Impact Assessments (DPIA) for new systems, projects, and processing activities
- Handle data subject rights requests (access, deletion, portability) within legal timelines
- Advise business units and technical teams on privacy-compliant system design and data handling
- Monitor privacy risk exposure, audit vendors and processors, and track compliance metrics
- Report privacy incidents and breaches to supervisory authorities where required
- Train staff on privacy obligations and data protection best practices
- Maintain privacy documentation and registers of processing activities
Tech Stack & Tools
Platforms & Tooling
Frameworks & Standards
Methodologies
Certifications (preferred)
Must-haves
- Proven experience as Privacy Officer, Data Protection Officer (DPO), or equivalent privacy compliance role
- Deep knowledge of GDPR, EU data protection law, and cross-border data transfer rules
- Ability to translate legal requirements into business-friendly guidance and technical controls
- Strong stakeholder management: advising non-privacy teams with confidence
- Attention to detail and ability to handle sensitive documentation and incident management
Nice-to-haves
- Experience with privacy platform tools (OneTrust, TrustArc, Collibra)
- Familiarity with AI Act, NIS2, or sector-specific privacy laws
- Background in legal, compliance, or information security
- Formal CIPP/E or CIPM certification
What we offer
- Lead privacy strategy for an organisation taking data protection seriously
- Grow expertise in emerging privacy laws (AI Act, NIS2, sector regulations)
- Work with cross-functional teams: legal, IT, operations, and business units
- Influence product and system design from the privacy ground up
- Build a privacy-aware culture across the organisation
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
Introduction
Phone call with your MVPeople consultant (within 24 hours)
Match & Brief
We discuss the assignment in detail and prepare you
Client meeting
Introduction to the client
Start
Contracting and onboarding
Details
Type
Consultancy
Location
Amsterdam
Work model
Hybrid
Level
Senior
Industry
overige
Posted
24 March 2026
Contact
MVPeople Group
jobs@mvpeoplegroup.com