- Location
- Porto
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Legal
- Closing date
- Today
- Source
- CareersPage
Description
Luza is an all-inclusive consulting company focused on talent, tech and innovation. We exist to elevate companies and humans all around the world, making change, from the inside to the outside.
We believe that technology + human kindness positively impacts every community around the world. Our approach is simple, we see a world without borders, and believe in equal opportunities. We are guided by our core principles of spreading positivity, good energy and promote equality and care for others.
Our hiring process is unique! People are selected by their value, education, talent and personality. We dont present ethnicity, religion, national origin, age, gender, sexual orientation or identity.
Its time to burst the bubble, and we will do it together!
What You'll do:
- Advise business teams on GDPR, national data protection laws, regulatory guidance, and supervisory authority decisions;
- Monitor developments in privacy, ePrivacy, artificial intelligence, data governance, and financial services regulation;
- Prepare clear written and verbal legal opinions on privacy matters;
- Establish, maintain, and update Records of Processing Activities under Article 30 GDPR;
- Draft and maintain privacy policies, standards, procedures, internal guidance, and privacy notices;
- Conduct and review Data Protection Impact Assessments and legitimate interest assessments;
- Identify privacy risks and recommend proportionate mitigation measures;
- Embed privacy by design and by default into products, services, systems, and business initiatives;
- Review artificial intelligence, automated decision-making, digital, marketing, data, and transformation projects;
- Draft, review, and negotiate Data Processing Agreements, data-sharing agreements, and controller-to-controller or controller-to-processor arrangements;
- Advise on international and intra-group data transfers, including Standard Contractual Clauses and Transfer Impact Assessments;
- Assess the privacy posture of vendors and third parties during procurement and third-party risk reviews;
- Coordinate responses to data subject rights requests within statutory deadlines;
- Manage personal data breaches, including triage, risk assessment, remediation, documentation, and regulatory notifications where required;
- Support communications with supervisory authorities;
- Design and deliver privacy training and awareness sessions;
- Prepare privacy metrics, dashboards, and updates for senior stakeholders and governance committees;
- Work with Legal, Information Security, IT, HR, Procurement, Marketing, and business teams across different jurisdictions;
- Hybrid Work Model.
Who You Are:
- Law degree;
- Qualification or admission in an EU jurisdiction is strongly preferred;
4 to 7 years of relevant experience in data protection or privacy law;
- Experience gained in-house, in a law firm, or within a legal or privacy consultancy;
- Strong working knowledge of the GDPR and national privacy law in at least one European jurisdiction;
- Practical experience with DPIAs, RoPA, privacy policies, DSARs, personal data breaches, DPAs, and international data transfers;
- Experience advising on privacy risks linked to technology, artificial intelligence, or digital projects;
- Experience in financial services, market infrastructure, or another regulated sector is preferred;
- Fluent in English; Portuguese is a plus.
What you'll get:
- Wage according to candidate's professional experience;
- Remote Work whenever possible;
- Delivery of work equipment adjusted to the performance of functions;
- Benefits plan;
- And others.
Work together with expert teams on projects of large magnitude and intensity, long term together with our clients, all leaders in their industries.
Are you ready to step into a diverse and inclusive world with us?
Together we will promote uniquess!