About the assignment
You lead privacy compliance and data protection strategy for a growing organisation managing sensitive customer and employee data. You translate complex regulations (GDPR, AI Act, ePrivacy) into practical policies and controls that embed privacy into business processes.
Your impact extends beyond compliance. You design privacy-by-design frameworks, conduct Data Protection Impact Assessments, and partner with Legal, IT, and Business teams to mitigate privacy risks before they escalate. You own the privacy incident response process and represent the organisation to regulators and data subjects.
Your responsibilities
- Develop and maintain privacy policies, procedures, and governance aligned with GDPR, AI Act, and sector-specific regulations
- Conduct Data Protection Impact Assessments (DPIA) for new systems, projects, and data processing activities
- Manage privacy incident response: detect breaches, investigate root causes, notify regulators and affected parties within legal timelines
- Partner with IT Security, Legal, and Product teams to embed privacy controls into system design and operations
- Monitor regulatory changes and emerging privacy standards; update compliance frameworks accordingly
- Lead privacy training and awareness programmes for staff and stakeholders
- Handle data subject requests (access, erasure, portability) and maintain privacy register of processing activities
- Report privacy metrics and compliance status to leadership and audit committees
Tech Stack & Tools
Platforms & Tooling
Frameworks & Standards
Cloud & Infrastructure
Methodologies
Certifications (preferred)
Must-haves
- 5+ years in privacy, data protection, or compliance roles
- Deep knowledge of GDPR and European privacy laws; understanding of AI Act implications
- Experience conducting DPIAs and managing privacy incident response
- Proven ability to translate regulations into actionable controls and policies
- Strong stakeholder management across technical, legal, and business teams
Nice-to-haves
- Experience with OneTrust, TrustArc, or similar privacy management platforms
- Background in regulated industries (financial services, healthcare, energy)
- CIPP/E, CIPM, or equivalent privacy certification
- Exposure to AI governance and algorithmic accountability
What we offer
- Lead privacy strategy for an organisation scaling its compliance maturity
- Work with modern privacy tools and governance platforms
- Direct collaboration with C-suite on board-level risk reporting
- Professional development support for privacy certifications
- Flexible work arrangement with focus on impact, not hours
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
Introduction
Phone call with your MVPeople consultant (within 24 hours)
Match & Brief
We discuss the assignment in detail and prepare you
Client meeting
Introduction to the client
Start
Contracting and onboarding
Details
Type
Consultancy
Location
Apeldoorn, GE
Work model
Hybrid
Level
Senior
Industry
overige
Posted
29 April 2026
Contact
MVPeople Group
jobs@mvpeoplegroup.com