DPO

Il y a 6 heures

Arrondissement de BruxellesCapitale, Bruxelles, Belgique ACENSI Temps plein

Description

Expanding steadily since its launch in 2003, the ACENSI group is an IT consultancy firm, well known for their technical and functional know-how, who specialize in Telecommunications, Media and Financial Markets, as well as in the Energy industry. ACENSI guides businesses in evolutionary IT projects from the initial strategies through to their realization (Management and Project management, Development, Design and Implementation, Infrastructure). From its original focus on technical engineering and Business Analysis, ACENSI has developed new areas of expertise in Human Resource Management Systems, Business Intelligence, e-learning and Client Relationship Management. Dynamism, enthusiasm and social development are all valued at ACENSI, allowing our clients to benefit from consultants with a true blend of talents.

ACENSI BELGIUM is looking for his client a DPO (F/M/X)

Context and Reporting Line

This is a critical position as the DPO is a legally required role within a federal public service organization. The DPO operates within a staff department reporting to the Chief Executive Officer. The DPO reports directly to the department director and to the CEO. The DPO performs their function independently and does not manage a dedicated team.

The DPO role is defined by Articles 38 and 39 of the GDPR. The DPO is responsible, among other duties, for monitoring compliance with GDPR requirements. The DPO assists the Data Controller and Data Processor in assessing and ensuring internal GDPR compliance.

As part of this compliance oversight, the DPO may:

Collect information to identify processing activities.

Analyze and monitor the compliance of organizational processing activities.

Provide information, advice, and recommendations to the Data Controller or Processor.

Key Responsibilities

1. Governance & Oversight

Monitor compliance with GDPR, privacy legislation, and related regulations.

Advise management and business departments regarding data protection obligations.

Contribute to the development, documentation, and follow-up of a coherent framework of roles, responsibilities, procedures, and reporting mechanisms related to data protection within our client.

Report to senior management on the status, risks, and improvement opportunities concerning data protection.

Safeguard the independence of the DPO function and avoid conflicts of interest.

Monitor compliance with Articles 5, 6, 24, 25, 30, 32, 33-36, and 37-39 GDPR.

Advise on and monitor Privacy by Design and Privacy by Default principles.

Document advice and recommendations to ensure accountability.

Support audits, inspections, and reviews related to data protection.

Prepare periodic reports on compliance, risks, and remediation actions.

2. Record of Processing Activities

Oversee the creation, maintenance, and updating of the Record of Processing Activities (Article

30 GDPR).

Support internal departments in identifying and documenting personal data processing activities.

Evaluate processing purposes, legal bases, retention periods, and data flows.

3. Data Protection Impact Assessments (DPIA)

Advise on the need to conduct DPIAs.

Guide and validate DPIAs for new or modified processing activities.

Monitor mitigation measures and follow up on residual risks.

Advise on prior consultation with the Data Protection Authority when required.

4. Policy & Strategic Advisory Role

Contribute to the development, evaluation, and updating of our client's data protection policies.

Advise on strategic choices, new initiatives, and digital transformation projects from a data protection perspective.

Integrate data protection into broader governance, compliance, and risk management frameworks.

Identify structural gaps and formulate policy recommendations for management.

Develop recommendations regarding personal data protection and coordinate the drafting and implementation of policies, guidelines, procedures, and control mechanisms based on legislation, case law, and legal doctrine.

Advise on the assessment and handling of personal data breaches.

Monitor compliance with legal notification requirements, including reporting to the Data Protection Authority within 72 hours in accordance with Article 33 GDPR.

Advise on and monitor notifications to data subjects where required (Article 34 GDPR).

Support the organization in establishing an escalation and on-call mechanism to ensure data breaches are assessed and reported in a timely manner, including outside normal working hours.

Evaluate root causes of data breaches and recommend corrective and preventive actions.

6. Contracts & Processors

Advise on Data Processing Agreements and data protection clauses.