
Data Protection Officer
- Stockholm
- Permanent
- Heltid
- Oversee and ensure the protection of personal data across our platforms and operations
- Provide strategic advice to business stakeholders on a broad range of data privacy matters, with a focus on the EU, UK and Australia.
- Interpret and apply data protection laws (including GDPR, UK GDPR, and other global privacy frameworks) to business operations.
- Monitor and advise on global developments in privacy and data protection law.
- Develop, implement, and maintain privacy policies and procedures to ensure compliance across jurisdictions.
- Collaborate with Procurement, Security, IT teams and Internal Audit to perform supplier audits and due diligence under the supplier risk management framework.
- Design and deliver privacy training and awareness programs across the business.
- Lead investigations into data breaches, prepare reports to regulators where required, and manage regulatory or customer complaints.
- Contribute to enhancing group-wide data governance frameworks.
- Promote and embed data protection by design and default into business processes.
- Oversee and handle data subject requests (access, rectification, erasure, objection, etc.) in a timely and compliant manner.
- Maintain and update the Record of Processing Activities (RoPA) in collaboration with business units.
- Define and track privacy KPIs, and report regularly to senior management on compliance status and risk exposure.
- Ensure that you adhere to the Governance, Risk & Compliance (GRC) obligations for your role.
- Identify and raise any non-compliance incidents promptly to your line manager.
- Challenge processes, policies and projects that will negatively impact compliance within the Group.
- Complete all mandatory compliance training assigned to you.
- Reach out to the Compliance Teams if unsure of any of your compliance obligations or the requirements are unclear.
- Acting in line with FDJ UNITED values
- Successful completion of all relevant training and other compliance activities that support FDJ's sustainable and responsible growth
- Law degree.
- 7-10 years' experience also with global data protection laws from the data controller's perspective and Artificial Intelligence.
- Proven managerial and leadership experience.
- Background in B2C and digital industries, with experience leading cross-functional, international projects.
- Strong understanding of online technologies and their privacy implications.
- Excellent communication and collaboration skills, with the ability to build trusted relationships with legal and business stakeholders.
- Skilled at translating complex legal and regulatory requirements into practical, risk-based recommendations.
- Strong organisational skills with the ability to prioritise multiple projects.
- Proactive and independent working style.
- Fluency in English is essential; proficiency in French is a strong asset.