SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Bitpanda is Europe's leading multi-asset investment platform, serving over 7 million customers across cryptocurrencies, stocks, precious metals, and commodities. Founded in 2014 in Vienna, the company operates at the intersection of fintech, Web3, and AI, with a Series C funding stage.
In this director-level role, you will serve as the Group Data Protection Officer and lead legal counsel for Bitpanda Group, defining and executing the global data protection strategy across all international markets. You will be the primary point of contact for data protection supervisory authorities across Europe, the UK, and the UAE.
Key responsibilities include:
**Strategic Leadership:** Design, implement, and continuously evolve the enterprise-level data protection management system (DPMS), ensuring a robust internal compliance framework across all international markets.
**Regulatory & Authority Liaison:** Act as the official Group Data Protection Officer and primary contact for data protection supervisory authorities. Lead responses to high-level inquiries and regulatory audits.
**Business Enablement:** Partner directly with the C-suite, engineering, and product divisions to provide pragmatic, solution-oriented privacy advice on complex initiatives at the intersection of data privacy, blockchain technology, and AI.
**Control Framework & Monitoring:** Own the Group's data protection control framework, oversee regular monitoring and control testing, drive remediation of identified gaps, and report on framework effectiveness to senior management.
**Operational Excellence:** Oversee escalation of complex data subject access requests (DSARs), lead incident response strategy for personal data breaches, and handle high-stakes negotiations for critical data processing agreements (DPAs) and international data transfers.
**Regulatory Awareness & Culture:** Monitor the rapidly shifting regulatory landscape in the digital asset space and data protection. Translate complex legal developments into actionable business strategies and drive company-wide privacy training and awareness initiatives.
The role offers hybrid flexibility with 25 additional days per year to work from a city or country of your choice, competitive total compensation aligned with pay-for-impact policy including stock options, mental health support through OpenUP, unlimited Udemy access, and other benefits including free onsite dining in Vienna.
**Requirements:**
- 7+ years of experience in data protection, ideally combining top-tier international law firms, regulatory authority experience, and in-house legal or privacy departments
- Proven experience as an appointed Data Protection Officer
- Strategic management capability navigating complex regulatory environments surrounding digital assets and regulated financial services
- Ability to balance aggressive business growth with strict risk and compliance frameworks
- Pragmatic problem-solving approach: delivering precise, reliable, and commercially viable legal advice while managing multiple competing priorities
- Full fluency in English and C1 or higher level of German (must-have)
- Recognized privacy certifications (e.g., CIPP/E, CIPM) are highly advantageous