Creditinfo logo

Data Protection Officer

Hiring from
Czech Republic
Work type
Hybrid
Posted
Is this job info correct?

511,012 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

At Creditinfo Group, we are on a mission to enable financial inclusion through intelligent data and innovation. As part of our growth journey, we are strengthening the frameworks that enable us to operate responsibly, securely and at scale. We are now looking to appoint a Data Protection Officer to join our expanding legal and compliance function, reporting to the Group General Counsel.

This is a hands-on yet strategically significant role for an experienced data protection professional eager to make an impact across a complex, international business. You will partner closely with the Group General Counsel, business leaders, technology teams and operational stakeholders to drive and embed a robust data protection framework within the Czech Republic legal entity, while aligning with broader Group standards and strategic objectives.

Operating in a fast-paced, international environment, you will be responsible for coordinating and driving the end-to-end data protection framework for the Prague entity, ensuring compliance with GDPR and applicable EU data protection laws. The role goes beyond formal compliance and requires a practical, operational mindset focused on embedding privacy into products, systems, business processes and decision-making. You will work across the Global Technology, Global Solutions and CESE business functions, helping shape the privacy backbone of a rapidly evolving fintech organisation.

This close, day-to-day collaboration with Global Technology and CESE does not affect your independence as DPO, which is safeguarded by your direct reporting line to the Group General Counsel, in line with GDPR Article 38.


Job Purpose

We are seeking a Data Protection Officer to lead and embed the data protection framework for the Czech Republic legal entity. This role combines operational ownership with strategic input, ensuring compliance with GDPR and applicable EU data protection laws while supporting the business in implementing practical, scalable privacy controls. The role works closely with Group Legal & Compliance, Technology, Security, and business stakeholders, with a particular focus on embedding data protection principles across the Global Technology & Global Solutions functions and the CESE business unit.


Responsibilities


Data Protection Leadership & Oversight

  • Coordinate and drive the end-to-end data protection framework for the Czech Republic legal entity, ensuring full compliance with GDPR and applicable EU data protection laws.
  • Own the data protection framework for this entity, embedding data protection principles across the Global Technology & Global Solutions functions as well as the CESE business unit.
  • Serve as the primary point of contact for local data protection matters, working closely with the Group General Counsel and relevant internal stakeholders.
  • Provide practical, risk-based advice on data protection issues arising from business operations, products, systems, and projects.

Governance, Compliance & Risk

  • Maintain and continuously improve records of processing activities (RoPA), data inventories, and data flow mapping across systems, products, and jurisdictions.
  • Lead the design, implementation, and enforcement of data protection policies, retention schedules, and data handling standards.
  • Oversee and operationalise data subject rights processes where relevant, including access, rectification, erasure, and portability, ensuring statutory timelines are met.
  • Establish and manage a robust DPIA framework, ensuring risk assessments are conducted for new products, systems, and cross-border data flows, including AI-driven products and features.
  • Ensure appropriate governance over cross-border data transfers, including implementation of SCCs and other transfer mechanisms.
  • Monitor and audit compliance with GDPR and internal policies, including conducting regular internal audits and tracking remediation actions.
  • Implement measurable controls and KPIs to demonstrate compliance and risk reduction.
  • As a one-off catch-up in the first 90 days, drive remediation of historical gaps in data mapping, audits, and policy enforcement, distinct from the ongoing remediation tracking above.
  • Support the preparation of reporting, updates, and escalations on key privacy risks, compliance issues, and remediation actions.

Operational Embedding

  • Develop clear ownership and accountability for data protection within business and technology teams.
  • Ensure visibility over the full data lifecycle, including collection, processing, sharing, retention, and deletion across systems and processes.
  • Support product and technology teams in implementing privacy-by-design and privacy-by-default principles across Creditinfo solutions.
  • Work with business and technical teams to translate legal requirements into practical, scalable business and technology controls.
  • Promote consistent operational adoption of privacy standards across day-to-day activities, change initiatives, and product development.

Incident Management, Third Parties & Training

  • Lead incident response from a data protection perspective, including breach assessment, regulatory notification, and coordination with legal, cybersecurity, and technology teams.
  • Oversee third-party data protection risk, including due diligence, contractual safeguards, and ongoing monitoring of processors and sub-processors.
  • Support review of data processing terms, data protection clauses, and vendor/privacy-related contractual arrangements where required.
  • Deliver and continuously improve internal data protection training and awareness programmes across the organisation.
  • Promote a strong culture of data protection awareness, accountability, and responsible data handling.




AI Governance (from Data Protection Perspective)

  • Provide guidance on AI governance and compliance with the EU AI Act, including risk assessments for AI-driven products and features.
  • Support Technology and Product teams in assessing AI systems for data protection and ethical risk considerations.
  • Stay current on emerging AI-related regulation and its implications for Creditinfo's products and internal use of AI.




Strategic / Group Responsibilities

Core responsibility for the Czech Republic entity:

  • Align Prague operations with group-wide data protection strategy, policies, and minimum standards.
  • Act as a key interface with Group Legal & Compliance, Technology, and Security functions to ensure consistent global governance.
  • Provide advice on GDPR, ePrivacy, and emerging EU regulatory requirements impacting data-driven products.
  • Monitor relevant legal and regulatory developments and assess their impact on local operations, products, and controls.

Additional, group-wide contribution (valued but not the primary mandate of this role):

  • Contribute to the development of scalable, repeatable data protection controls for rollout across multiple jurisdictions.
  • Support wider Group projects and initiatives involving privacy, data governance, and regulatory change as required.


Requirements

  • Strong expertise in GDPR and EU data protection framework; experience within financial services or data-driven SaaS is a plus.
  • Proven experience balancing strategic advisory with hands-on implementation of data protection programmes.
  • Understanding of data architecture, systems, and data flows in complex, multi-jurisdictional environments.
  • Experience managing regulatory interactions and data breach notifications.
  • Ability to translate legal requirements into practical, scalable business and technology controls.
  • Strong stakeholder management skills across executive, legal, compliance, and engineering teams.
  • Strong analytical, organisational, and problem-solving skills.
  • Clear written and verbal communication skills, with the ability to provide concise and practical guidance.

Profile

  • Hands-on practitioner capable of building and embedding a function locally.
  • Comfortably operating in a global, multi-entity environment with varying regulatory requirements.
  • Pragmatic, solution-oriented approach with a focus on risk management and demonstrable compliance outcomes.
  • Able to operate independently while working collaboratively across legal, business, and technology teams.

Similar jobs

Apply for this job