Looking for a new challenge in Data Privacy? Look no further, we have just the job for you.
DKV Belgium, a loyal partner in insurance, but there’s more than meets the eye —we’re a dynamic team of around 500 engaged colleagues driving digital transformation. As part of the international Munich Re Group, we proudly lead private health insurance in Belgium, supporting our clients during good and difficult times. You will arrive in an environment where everybody is able to be who they are, where you can get the most out of yourself day in and day out, with the support of your colleagues.
Together, we put our values of success, diversity, collegiality, and development into practice every day to strengthen the trust of our two million clients.
Sounds like a plan? Continue reading!
What the key tasks will look like
As a Member of the Data Protection Officer (DPO) Office you will report to the DPO and assist alongside the team and other stakeholders in the oversight and management of the organization’s data privacy program, support in responding to data subject requests, oversee the handling of incidents, advise in privacy-related queries and data protection impact assessments, and contribute to maintaining a culture of privacy within the organization. In a nutshell, the job involves a combination of privacy governance, compliance checks, advisories, awareness, oversight, and collaboration with various departments, to protect the privacy of the individuals whose personal data is processed at DKV and ERGO Belgium.
Given the increased focus on AI governance, cross-border data flows, and the rise of new data protection laws, your role will also involve staying updated on the latest privacy and data-related regulatory landscape and practices (CJEU case law, EDPB's guidelines, Artificial Intelligence Act, ...).
You will contribute to
- Support with the further elaboration of the DPO monitoring plan, its effective execution, and make sure resulting actions are properly documented, communicated to the business and followed-up upon,
- Support the Business Owners in keeping the Register of Processing Activities (RoPA) complete and up-to-date, and make sure that the defined actions and recommendations to further reduce the risks are followed-up and implemented with the respective Business Owners,
- Support with and/or monitor the effective execution of handling individual’s requests (Data Subject Right Requests) and complaints related to personal data,
- Support with and/or monitor the assessment, investigation and adequate handling and reporting of personal data breaches,
- Advise in data privacy related projects, and where required, support the conduct of Data Protection Impact Assessments (DPIA’s),
- Overview whether Data Protection Agreements (DPA’s) are duly signed with third parties, advise where required, and make sure that periodic audits are done by the business and that the defined measures are effectively implemented,
- Assist in maintaining an ongoing risk assessment program targeting privacy matters from a data subject point of view. Keep an overview on the privacy risks, help translating these into company privacy risks, propose prioritization according to the associated risk, and monitor the effective mitigation of risks,
- Overview the Data Protection Management Framework (data privacy policy guidelines, work instructions, roles & responsibilities), monitor their adequate documentation and implementation,
- Support in conducting the education, training and awareness program for employees and other authorized users,
- Further establish a Data Privacy Organization through the network of Business Risk Officers (BRO’s) and liaise with other departments such as Procurement, IT security, Transformation Office, Legal, ISO (Information Security Office), Risk Management and Compliance to make sure that the privacy related matters and processes are understood, followed up and aligned with other company requirements, policies and rules, and adequately balanced with business requirements,
- Support in following up on internal or external related audit initiatives,
- Keep track of the internal, group and overall regulatory requirements related to privacy and other data-related practices,
- Support the regular Data Protection Officer reporting requirements to the highest management levels.
Required skills and competencies
- You have a master’s degree in law and a CIPP/M certification (or motivation to achieve within reasonable time) with minimum 5 years experience in the domain of data privacy,
- You are acquainted with Governance Risk and Compliance (GRC) or privacy-related tools (such as e.g. RSA Archer, OneTrust, …),
- You are a sociable communicator, both written and spoken in French and Dutch, and you are proficient in English.
- You are an expert in stakeholder management, which translates to a business orientation and quick understanding of how business works as well as their issues and requirements,
- You are creative and solution-oriented with experience in process automation,
- You like working autonomously and yet also show team spirit, and can easily adapt to a changing environment,
- You can build trust and show integrity by being genuine, listening carefully, and following up on your words with actions.
Want to grow with us?
At DKV we offer you a varied job with growth opportunities (thanks to training, coaching, growth projects, and internal mobility) and all this at a prime location in the heart of Brussels.
Besides a competitive gross salary, we offer an extensive standard package of extra-legal benefits such as:
- insurance package (hospitalization, ambulatory insurance, guaranteed income insurance, pension plan)
- a year-end premium, collective company premium, and individual bonus
- meal and eco vouchers
- internet and homeworking allowance
Moreover, you can count on an attractive leave scheme (up to 34 days), flexible working hours, and the possibility to work from home up to three days a week. This way of hybrid working guarantees you a good balance between work and your private life.
We are an equal-opportunity employer. All aspects of employment are based solely on performance, competence, conduct, or business needs. If you require any support or access requirements, we encourage you to advise us at the time of your application so that we can make any reasonable adjustments needed to support you through your recruitment journey.