Your mission
As Data Protection Manager, you will, in close collaboration with the DPO, work on and continuously improve IONITY’s Data Protection Management System and ensure compliant and pragmatic Data Protection and privacy practices across the organisation. You will advise internal stakeholders on GDPR and related requirements, drive Data Protection-by-design, and reduce risk through robust processes, training, and effective incident and vendor management.- Establishment, operation, and continuous further development of the Data Protection management system.
- Manage and continuously improve Data Protection processes, the Records of Processing Activities, retention periods and Data Protection related workflows.
- Perform contract and supplier checks and support contract negotiations.
- Conduct Data Protection vendor assessment and ensure appropriate contractual, technical, and organisational measures are in place.
- Manage personal data breaches in line with legal requirements.
- Act as the point of contact for Data Protection inquiries and related topics from internal and external stakeholders.
- Coordinate and drive EU AI Act compliance for AI use cases by advising stakeholders, performing compliance assessments and documentation, implementing AI literacy measures, and aligning vendor and operational requirements.
Your profile
- Studies in law or a comparable qualification, with comprehensive knowledge of the GDPR and other relevant laws and regulations related to Data Protection (for example E-Privacy Directive and national laws, EU AI Act).
- Several years of professional experience in Data Protection, ideally in a tech- and data-driven environment.
- Strong ability to assess both legal and technical implications of data processing, and to translate requirements into practical solutions.
- Basic understanding of IT security, IT terminology and relevant security standards (for example SOC 2, ISO 27001), and how they translate into technical and organizational measures.
- Ability to provide qualified, clear, and pragmatic advice as a responsible and reliable partner for diverse stakeholders.
- Commitment to staying up to date with and to quickly adapt to new and specialized tasks related to Data Protection, Artificial Intelligence, Information Technology, and compliance.
- Proficient negotiation and communication skills in German and English, both fluent.
- Relevant privacy or security certifications (for example CIPP/E, CIPM, CIPT) is beneficial.
