Data Privacy and Classification Officer

Posted 2 Days Ago
Be an Early Applicant
Málaga, Andalucía, ESP
Hybrid
Mid level
Professional Services • Real Estate • Consulting
The Role
Implement and maintain data protection, governance, and classification frameworks. Ensure regulatory compliance (GDPR, ISO, NIST), run DPIAs, map and classify datasets, define retention policies, support data minimization and incident response, deliver training, and advise on technical controls (DLP, encryption, access controls). Collaborate with cybersecurity, legal, compliance, IT, and business units and support audits and governance programs.
Summary Generated by Built In
Company Description

Creating a future worth living for future generations gets us out of bed every morning. Depending on the project, we are consultants, implementers, or both for sustainable, innovative and economical solutions for real estate, industry, energy and infrastructure. Our more than 6,500 employees at over 80 locations worldwide support our customers in interdisciplinary teams. Our thinking is both visionary and realistic. We work independently and as part of a team. With passion and the latest technologies. We unite. Join us at Dreso and let’s create a world we want to live in. 

Job Description

The Data Protection & Classification Officer is responsible for implementing, improving and maintaining the organization’s data protection, data governance, and information classification framework. This role ensures that data is handled in accordance with legal, regulatory, and internal security requirements, while enabling secure and efficient business operations. The officer supports head of GRC in collaboration with cybersecurity, legal, compliance, IT, and business units to drive consistent data protection practices across the enterprise.

The Data Privacy and Classification Officer is a professional with extensive expertise in Data Privacy Governance, Risk, and Compliance (GRC), bringing a deep understanding of global data privacy frameworks, regulations, and best practices. With a strong track record in executing compliance programs and embedding data privacy controls within large-scale and multinational environments, this role supports Drees & Sommer’s mission to ensure regulatory compliance, business continuity, and long-term data privacy and information security maturity. Support yearly internal and external assessment and audit programme in alignment with the head of the department. Support the development, implementation, and maintenance of the company’s GRC framework.

Core Responsibilities

1. Data Protection Governance

  • Develop, maintain, and enforce policies, standards, and procedures related to data protection and information classification.
  • Ensure compliance with relevant regulations (e.g., GDPR, national and international privacy laws) and industry frameworks (ISO/IEC 27001, TISAX, NIST).
  • Conduct impact assessments (e.g., DPIAs) and advise on data handling best practices.

2. Information Classification & Handling

  • Define and maintain the organization’s data classification scheme and associated handling requirements.
  • Coordinate classification of new and existing data assets across systems and business processes.
  • Provide guidance and tooling for labelling, tagging, and securing sensitive data.
  • Knowledge and experience implementing Data Governance and Compliance with Microsoft Purview.

3. Lifecycle & Data Governance Management

  • Support data owners and business units in identifying, mapping, and documenting personal and sensitive datasets.
  • Define retention, deletion, and archival requirements aligned with legal and business needs.
  • Oversee implementation of data minimization and “privacy-by-design” principles.

4. Monitoring, Reporting & Risk Management

  • Monitor compliance with data protection and classification rules.
  • Identify, assess, and report data protection risks to relevant stakeholders.
  • Support incident response related to data breaches or data loss—including documentation, remediation, and lessons learned.

5. Awareness & Training

  • Develop and deliver training programs on data protection, secure handling, and classification requirements.
  • Serve as the subject matter expert (SME) for questions related to data governance and classification.

6. Collaboration & Advisory

  • Work closely with Cyber Security, Data Governance, Legal, and Compliance teams.
  • Provide input for technical solutions such as DLP, access controls, encryption, data discovery, and classification tools.
  • Participate in audits and support responses to regulatory inquiries.

Qualifications

Key Competencies

  • Strong understanding of data lifecycle, protection mechanisms, and cybersecurity controls.
  • Knowledge of relevant frameworks (GDPR, NIST Privacy Framework, ISO 27001/27701, TISAX)
  • Familiarity with technical tooling (DLP, CASB, data discovery, encryption tools, etc.)
  • Excellent communication, documentation, and stakeholder management skills
  • Ability to work across business units and manage complex topics with clarity
  • Proficiency in policy and process implementation
  • Strong writing and documentation skills
  • Awareness of operational security practices in IT and industrial environments
  • Strong analytical thinking and attention to detail

 

Certifications & Qualifications

  • CIPP/E, CIPM, CIPT
  • Microsoft Azure / Microsoft Purview
  • Good Knowledge on GDPR and other international Data Privacy Standards
  • Good Knowledge on ISO 27001/27701/22301

Additional Information

  • To ensure your work-life balance, we offer the option of mobile working
  • We promote your professional and personal development through individual training and further education at the Drees & Sommer Academy
  • We support your health with a bonus for sports enthusiasts. We offer the possibility of subscribing to a private health insurance policy
  • Employees benefit from tax advantages related to their commuting expenses for the office
  • Fiscal advantages for employees expenses in meal costs during the worktime. Employee referral program with attractive bonus scheme
  • Supporting career and familiy by receiving tax benefits for kindergarten expenses

Skills Required

  • Proven experience in data privacy governance, GRC and implementing privacy programs
  • Strong knowledge of GDPR and other international data privacy standards
  • Familiarity with ISO 27001/27701/22301, NIST Privacy Framework and TISAX
  • Experience implementing Data Governance and Compliance with Microsoft Purview
  • Experience with Microsoft Azure
  • Hands-on familiarity with DLP, CASB, data discovery tools and encryption tools
  • Ability to conduct DPIAs, define retention/deletion policies, and support audits
  • Excellent communication, documentation, stakeholder management and training delivery skills
  • Certifications such as CIPP/E, CIPM, or CIPT
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
6,500 Employees
Year Founded: 1970

What We Do

Drees & Sommer is an international consulting and implementation firm specializing in sustainable, innovative, and economical solutions for real estate, infrastructure, and industry. Founded in 1970, they employ over 6,500 people across 80+ cities worldwide, focusing on driving sustainability and digitalization simultaneously across their diverse portfolio of projects.

Similar Jobs

CrowdStrike Logo CrowdStrike

Regional Sales Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Spain
10000 Employees

SEON Logo SEON

Senior Site Reliability Engineer

Artificial Intelligence • Cybersecurity
In-Office or Remote
28 Locations
415 Employees

SailPoint Logo SailPoint

Manager, Professional Services

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
2461 Employees

Deepgram Logo Deepgram

Research Staff, LLMs

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
49 Locations
150 Employees
150K-250K Annually

Similar Companies Hiring

Agora RE Thumbnail
Fintech • Real Estate • PropTech
Tel Aviv, IL
200 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees
Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account