DPO

Il y a 4 heures

Arrondissement de BruxellesCapitale, Bruxelles, Belgique ACENSI Temps plein

About The Job

Expanding steadily since its launch in 2003, the ACENSI group is an IT consultancy firm, well known for their technical and functional know-how, who specialise in Telecommunications, Media and Financial Markets, as well as in the Energy industry. ACENSI guides businesses in evolutionary IT projects from the initial strategies through to their realisation (Management and Project management, Development, Design and Implementation, Infrastructure). From its original focus on technical engineering and Business Analysis, ACENSI has developed new areas of expertise in Human Resource Management Systems, Business Intelligence, e-learning and Client Relationship Management. Dynamism, enthusiasm and social development are all valued at ACENSI, allowing our clients to benefit from consultants with a true blend of talents.

DPO (F/M/X)

Description

Context and Reporting Line

This is a critical position as the DPO is a legally required role within a federal public service organisation. The DPO operates within a staff department reporting to the Chief Executive Officer. The DPO reports directly to the department director and to the CEO. The DPO performs their function independently and does not manage a dedicated team.

ACENSI BELGIUM is looking for its client a DPO (F/M/X).

As Part Of This Compliance Oversight, The DPO May:

  • Collect information to identify processing activities.
  • Analyze and monitor the compliance of organizational processing activities.
  • Provide information, advice, and recommendations to the Data Controller or Processor.

Key Responsibilities

  • Governance & Oversight

Possible Tasks:

  • Monitor compliance with GDPR, privacy legislation, and related regulations.
  • Advise management and business departments regarding data protection obligations.
  • Contribute to the development, documentation, and follow-up of a coherent framework of roles, responsibilities, procedures, and reporting mechanisms related to data protection within our client.
  • Report to senior management on the status, risks, and improvement opportunities concerning data protection.
  • Safeguard the independence of the DPO function and avoid conflicts of interest.

Record of Processing Activities

  • Oversee the creation, maintenance, and updating of the Record of Processing Activities (Article 30 GDPR).
  • Support internal departments in identifying and documenting personal data processing activities.
  • Evaluate processing purposes, legal bases, retention periods, and data flows.

Data Protection Impact Assessments (DPIA)

  • Advise on the need to conduct DPIAs.
  • Guide and validate DPIAs for new or modified processing activities.
  • Monitor mitigation measures and follow up on residual risks.
  • Advise on prior consultation with the Data Protection Authority when required.

Policy & Strategic Advisory Role

  • Contribute to the development, evaluation, and updating of our client's data protection policies.
  • Advise on strategic choices, new initiatives, and digital transformation projects from a data protection perspective.
  • Integrate data protection into broader governance, compliance, and risk management frameworks.
  • Identify structural gaps and formulate policy recommendations for management.
  • Develop recommendations regarding personal data protection and coordinate the drafting and implementation of policies, guidelines, procedures, and control mechanisms based on legislation, case law, and legal doctrine.

Data Breaches & Incident Management

  • Advise on the assessment and handling of personal data breaches.
  • Monitor compliance with legal notification requirements, including reporting to the Data Protection Authority within 72 hours in accordance with Article 33 GDPR.
  • Advise on and monitor notifications to data subjects where required (Article 34 GDPR).
  • Support the organization in establishing an escalation and on-call mechanism to ensure data breaches are assessed and reported in a timely manner, including outside normal working hours.
  • Evaluate root causes of data breaches and recommend corrective and preventive actions.

Contracts & Processors

  • Advise on Data Processing Agreements and data protection clauses.
  • Monitor GDPR compliance of processors and business partners.
  • Identify privacy risks in outsourcing arrangements and partnerships.
  • Act as the primary contact point for the Data Protection Authority.
  • Collaborate with other supervisory authorities where relevant.
  • Participate as a member of our client's Information Security Committee (monthly meetings).

Awareness &