Mission:
Act as a Chief Data Office Protection Analyst (CDOPA), ensuring compliance of personal data processing activities with GDPR and Group requirements, and supporting the effective implementation of data protection principles, including alignment with data lifecycle and records management practices.
The role contributes to privacy governance and to the control of personal data–related risks, ensuring consistency of practices across the personal data lifecycle, in coordination with relevant stakeholders.
The scope of CDOPA’s responsibilities may be extended to include the protection of non‑personal data, to address security and regulatory compliance requirements (e.g. Insider information, banking secrecy…).
Responsibilities:
GDPR Operational Support
- Support project and operational teams in qualifying personal data processing activities and identifying appropriate data protection measures.
- Provide GDPR expertise on new processes, projects, tools, application evolutions, and outsourcing initiatives.
- Contribute to the resolution of complex privacy issues related to innovative uses or technologies.
- Support business teams in the closure of NFAs within MyActions.
Processing Records and GDPR Analyses
- Maintain and instruct the Record of Processing Activities (DPR / RoPA) for the relevant entity.
- Perform or coordinate required analyses, including PIA/DPIA, TIA, data flow analyses, and LIA where applicable.
- Ensure completeness, accuracy, consistency, and ongoing relevance of documentation, in coordination with all relevant stakeholders.
Governance and Controls – First Line of Defence
- Contribute to the personal data protection governance and internal control framework.
- Perform ongoing First Line of Defence (LoD1) controls across the assigned scope.
- Ensure effective application of GDPR principles, including data minimization and storage limitation.
- Identify, document, and escalate risks and non‑compliance situations.
- Contribute to ensuring consistency between GDPR requirements and data retention, archiving and deletion practices.
4. Coordination, Reporting, and Stakeholder Interaction
- Provide regular visibility to the PRU GDPR Team Manager on GDPR compliance status, risks, and action plans.
- Support CDOs in implementing and monitoring Group requirements and controls by delivering a consolidated view of the Service Unit’s GDPR activities.
- Interact regularly with IT, Security, Risk, Legal and Business teams, and coordinate closely with the Data Protection Officer (LoD2) within a complementary Three Lines of Defence approach.
- Coordinate with PRU team to ensure alignment between GDPR obligations and records lifecycle practices.