Live opening · Posted 5 days ago

Data Protection Officer

Creditinfo Group · Prague, Prague, Czechia (Remote)
Linkedin Yes
You are 5 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 5 days ago
CompanyCreditinfo Group
LocationPrague, Prague, Czechia (Remote)
Work modeYes
SourceLinkedin
Listed5 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Linkedin publishing this role to us finding it
15 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,672 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

About the roleKey Responsibilities1. Data Protection Leadership & Oversight
Coordinate and drive the end-to-end data protection framework for the Czech Republic legal entity, ensuring full compliance with GDPR and applicable EU data protection laws.
Own the data protection framework for this entity, embedding data protection principles across the Global Technology & Global Solutions functions as well as the CESE business unit.
Serve as the primary point of contact for local data protection matters, working closely with the Group General Counsel and relevant internal stakeholders.
Provide practical, risk-based advice on data protection issues arising from business operations, products, systems, and projects.
Governance, Compliance & Risk
Maintain and continuously improve records of processing activities (RoPA), data inventories, and data flow mapping across systems, products, and jurisdictions.
Lead the design, implementation, and enforcement of data protection policies, retention schedules, and data handling standards.
Oversee and operationalise data subject rights processes where relevant, including access, rectification, erasure, and portability, ensuring statutory timelines are met.
Establish and manage a robust DPIA framework, ensuring risk assessments are conducted for new products, systems, and cross-border data flows, including AI-driven products and features.
Ensure appropriate governance over cross-border data transfers, including implementation of SCCs and other transfer mechanisms.
Monitor and audit compliance with GDPR and internal policies, including conducting regular internal audits and tracking remediation actions.
Implement measurable controls and KPIs to demonstrate compliance and risk reduction.
As a one-off catch-up in the first 90 days, drive remediation of historical gaps in data mapping, audits, and policy enforcement, distinct from the ongoing remediation tracking above.
Support the preparation of reporting, updates, and escalations on key privacy risks, compliance issues, and remediation actions.
3. Operational Embedding
Develop clear ownership and accountability for data protection within business and technology teams.
Ensure visibility over the full data lifecycle, including collection, processing, sharing, retention, and deletion across systems and processes.
Support product and technology teams in implementing privacy-by-design and privacy-by-default principles across Creditinfo solutions.
Work with business and technical teams to translate legal requirements into practical, scalable business and technology controls.
Promote consistent operational adoption of privacy standards across day-to-day activities, change initiatives, and product development.
Incident Management, Third Parties & Training
Lead incident response from a data protection perspective, including breach assessment, regulatory notification, and coordination with legal, cybersecurity, and technology teams.
Oversee third-party data protection risk, including due diligence, contractual safeguards, and ongoing monitoring of processors and sub-processors.
Support review of data processing terms, data protection clauses, and vendor/privacy-related contractual arrangements where required.
Deliver and continuously improve internal data protection training and awareness programmes across the organisation.
Promote a strong culture of data protection awareness, accountability, and responsible data handling.
AI Governance (from Data Protection Perspective)
Provide guidance on AI governance and compliance with the EU AI Act, including risk assessments for AI-driven products and features.
Support Technology and Product teams in assessing AI systems for data protection and ethical risk considerations.
Stay current on emerging AI-related regulation and its implications for Creditinfo’s products and internal use of AI.
Strategic / Group Responsibilities
Core responsibility for the Czech Republic entity:
Align Prague operations with group-wide data protection strategy, policies, and minimum standards.
Act as a key interface with Group Legal & Compliance, Technology, and Security functions to ensure consistent global governance.
Provide advice on GDPR, ePrivacy, and emerging EU regulatory requirements impacting data-driven products.
Monitor relevant legal and regulatory developments and assess their impact on local operations, products, and controls.
Additional, group-wide contribution (valued but not the primary mandate of this role):
Contribute to the development of scalable, repeatable data protection controls for rollout across multiple jurisdictions.
Support wider Group projects and initiatives involving privacy, data governance, and regulatory change as required.
Skills & Experience
Strong expertise in GDPR and EU data protection framework; experience within financial services or data-driven SaaS is a plus.
Proven experience balancing strategic advisory with hands-on implementation of data protection programmes.
Understanding of data architecture, systems, and data flows in complex, multi-jurisdictional environments.
Experience managing regulatory interactions and data breach notifications.
Ability to translate legal requirements into practical, scalable business and technology controls.
Strong stakeholder management skills across executive, legal, compliance, and engineering teams.
Strong analytical, organisational, and problem-solving skills.
Clear written and verbal communication skills, with the ability to provide concise and practical guidance.
Profile
Hands-on practitioner capable of building and embedding a function locally.
Comfortable operating in a global, multi-entity environment with varying regulatory requirements.
Pragmatic, solution-oriented approach with a focus on risk management and demonstrable compliance outcomes.
Able to operate independently while working collaboratively across legal, business, and technology teams.
What We Can Offer
A stimulating job in a multinational but medium-sized company that develops cutting edge banking and financial applications for customers worldwide, with occassional travel to exciting destinations (e.g. Oman, Indonesia, Seychelles).
A competitive salary package, flexible working hours, home office, 25 vacation days, 3 sick days, language courses, training and conferences, multisport card, cafeteria, pension contribution, meal vouchers, free coffee and regular company events.
A modern, relaxed office in Karlín with a stunning view of Vítkov park and a terrace, located right by the Metro (Křižíkova).
Think We Are The Perfect Match? Get In Touch

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App