.About the job The Data Protection Advisor will act as a trusted advisor for BNP Paribas Business and Functions and oversight BNP Paribas DPOs, to assist in the implementation, management and monitoring of the DPP strategy, by supporting the definition, implementation and operationalization of the Group's DPP framework by Group Entities.
Your Main Activities Are As part of their responsibilities, the candidate will coordinate and oversight activities in relation to the following: Advising on the maintenance of the Group's DPP (Data Protection and Privacy) Governance and framework, as well as the definition and creation of DPP policies, guidelines and procedures of Group BNP Paribas Independent review and challenge of the technical and operational DPP controls implemented and issue recommendations with regards to privacy, data protection and compliance with the Group BNP Paribas DPP framework and regulation (e.G. GDPR, CCPA, LGPD, PDPA, etc) Act as a trusted advisor of key internal stakeholders (e.G. CDOs, CISOs, DPOs, Business...) regarding manage DPP requirements, such as: Oversight and check & challenge complex and transversal DPP initiatives, design and rollout of the DPP strategy, and strategy implementation.
Oversight and check & challenge transversal and complex Group wide data processing/ initiative impact assessments (DPIA), notable the adequacy of controls and measures, controllership, transfers, etc.
Identify key DPP risks, inform BNP Paribas' Management and key stakeholders such IT and Business among other, and oversight the decisions to manage those risks.
Oversight key Group data breaches and other DPP incidents and work with key stakeholders (such CDO, CISO, DPO, IT, Legal, etc.) on the risk identification, ensure the consistency of potential incidents qualification, conduct post mortem analysis, and validate the adequacy and solutions implementation.
Monitor and advice on the interactions with authorities and other external stakeholders, analyzing the requests, actions to be taken and producing lessons learned among the BNP Paribas worldwide DPP community.
Monitor global regulatory changes and authority decisions, share and provide advice on DPP risk anticipation to the DPP community, providing lessons learned, best practices and guidelines, and leveraging on the BNP Paribas DPP knowledge basis.
Promote data protection awareness and privacy by design culture across the Group (e.G. governance, principles of data processing, data subjects' rights, data protection by design and by default, records of processing activities, security, data breach, authority interactions), and influencing/advising the Group Learn & Development agenda/ plans.
Attend regular/ ongoing data protection, information security, privacy training and continuous improvement.
Profile and Skills to Success University degree and relevant professional certifications (e.G. CIPP/E, CIPT, CIPM, ISO*****, etc