SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Viva.com is Europe's first Tech Bank for businesses, operating a pan-European critical infrastructure for payments and banking services across 31 countries. The company offers omnichannel payment acceptance, deposit accounts, card issuing, and financing solutions through a single integrated platform, pioneering Tap on Any Device technology.
You will serve as the organization's appointed Data Protection Officer, acting independently with direct access to senior management and governing bodies. This is a senior, hands-on role requiring strong legal and regulatory expertise, sound business judgment, and deep understanding of how personal data is used across digital products, financial services, AI-enabled solutions, and large-scale technology environments.
Key responsibilities include:
- Acting as the appointed DPO under GDPR Articles 37–39, performing the role independently and without conflict of interest
- Monitoring compliance with GDPR, applicable national and European privacy legislation, internal policies and regulatory expectations
- Advising senior management, business functions and governing bodies on complex data protection matters, emerging risks and remediation actions
- Serving as primary point of contact for Data Protection Authorities, managing regulatory enquiries, inspections, consultations and notifications
- Overseeing the Data Protection Impact Assessment (DPIA) framework and advising on high-risk processing activities, new products, technologies and strategic initiatives
- Providing privacy guidance on AI systems, profiling, automated decision-making, analytics, fraud prevention, biometric data and emerging technologies
- Embedding privacy by design throughout product development, system implementation, process redesign and third-party integrations
- Overseeing management of personal data breaches, ensuring appropriate assessment, documentation, escalation and regulatory notification
- Monitoring handling of data subject requests and ensuring completion within regulatory deadlines
- Reviewing and advising on records of processing activities, privacy notices, retention frameworks, consent mechanisms and lawful bases
- Assessing data protection provisions in agreements with customers, suppliers, processors and strategic partners, including international data transfers
- Providing oversight and challenge regarding third-party privacy risk assessments and data processing arrangements
- Designing and maintaining data protection policies, governance frameworks, controls, reporting mechanisms and annual compliance plans
- Delivering targeted training and awareness initiatives to strengthen accountability and privacy awareness
- Producing regular reports for senior management and relevant committees on privacy risks, incidents, compliance performance and remediation progress
- Working closely with Legal, Compliance, Risk, Information Security, Technology, Product and Internal Audit while maintaining DPO independence
- Leveraging AI-enabled and automated tools to improve compliance monitoring, risk identification, reporting and operational efficiency
Requirements:
- Bachelor's degree in Law; postgraduate qualification in Data Protection, Technology Law, Information Security or related discipline highly desirable
- At least 8 years of relevant professional experience, including significant experience in a senior privacy role or as an appointed DPO
- Proven experience within banking, payments, fintech, technology or another highly regulated and data-intensive environment
- Expert knowledge of GDPR, ePrivacy requirements, international data transfer mechanisms and relevant European data protection guidance
- Strong understanding of privacy risks associated with AI, automated decision-making, cloud technologies, digital identity, biometrics and large-scale data processing
- Demonstrated experience managing DPIAs, personal data breaches, regulatory interactions and complex data subject matters
- Ability to interpret regulatory requirements and translate them into practical, proportionate and business-oriented controls
- Strong stakeholder management skills and confidence to provide independent challenge and influence senior decision-makers
- Excellent analytical, communication, drafting and presentation skills
- High level of integrity, professional judgment and discretion
- Professional certification such as CIPP/E, CIPM, CIPT, CDPO or equivalent considered a strong advantage
- Fluency in English and Greek