Legal Counsel - Data Protection
Job description
About the role
Join the Bitpanda legal team to manage privacy and data protection initiatives across our international operations. You will work alongside the Group Data Protection Officer to build and maintain a compliant, practical framework for handling personal data. In this capacity, you will serve as a primary interface between the business units and data protection authorities, ensuring that privacy considerations are embedded into every stage of product development. The role requires a proactive approach to identifying regulatory risks and translating complex legal requirements into actionable guidance for non-legal stakeholders. You will own the implementation of data protection strategies that align with the company's growth objectives while maintaining the highest standards of compliance. This position offers the opportunity to shape the privacy culture of a rapidly scaling fintech operating in a global digital environment. Your work will directly influence how personal data is collected, processed, and protected across the organization.
Key facts
What you'll do
Advise product, engineering, and business departments on daily privacy inquiries and new projects, ensuring that data processing activities are lawful and transparent.
Assist the Group Data Protection Officer in developing, implementing, and maintaining internal policies and management systems related to data protection.
Draft and negotiate data transfer mechanisms, processing agreements, and privacy notices to ensure legal compliance and clear communication with data subjects.
Handle data subject requests, regulatory inquiries, and personal data breaches in a timely and accurate manner, coordinating responses across relevant departments.
Track changes in data protection regulations at European and national levels and assess their impact on current and future business operations.
Conduct internal training sessions and awareness programs to foster a strong data protection culture across the organization.
Perform data protection impact assessments and collaborate with stakeholders to mitigate identified risks.
Maintain records of processing activities and ensure that data protection policies are consistently applied across all operational jurisdictions.
Liaise with external counsel and regulatory bodies to address complex privacy matters and ensure adherence to best practices.
Support the continuous improvement of the privacy framework by identifying gaps and recommending enhancements based on operational needs and regulatory updates.
Requirements
- Hold a university degree in law from a European institution, with a focus on IT/IP, data protection, or regulatory law.
- Possess 1 to 3 years of professional experience in privacy law gained through an in-house role, a regulatory authority, or an international law firm.
- Demonstrate proficiency in GDPR and broader European data protection frameworks, including a solid understanding of legal and regulatory obligations.
- Exhibit fluency in English and possess at least B2 level proficiency in German, enabling effective communication with internal and external stakeholders.
- Show the ability to work independently and as part of a team, maintaining a solution-oriented mindset when addressing complex privacy challenges.
- Have a strong attention to detail and the capability to manage multiple priorities in a fast-paced environment.
- Be committed to upholding data protection principles and ensuring that all activities are conducted in compliance with applicable laws.
- Display strong analytical skills to interpret legal texts and apply them to real-world business scenarios.
Nice to have
- Have successfully completed the bar exam.
- Hold privacy certifications such as CIPP/E.
- Possess familiarity with the regulatory landscape for crypto-assets and financial services, including an understanding of how these intersect with data protection rules.
Skills & tools
Expertise in GDPR and European data protection laws.
Strong knowledge of data processing agreements and contractual clauses for international data transfers.
Experience with regulatory compliance frameworks and risk assessment methodologies.
Proficiency in privacy-related documentation, including policies, records of processing activities, and data subject request responses.
Practical notes
This is a full-time position offering a hybrid work model that includes the flexibility to work from a location of your choice for 25 days per year. The compensation package is competitive and includes stock options. Additional benefits consist of 3 days of extra leave after 6 months of service, 8 weeks of gender-neutral parental leave, and access to OpenUP for mental health support. Employees also receive unlimited access to Udemy for ongoing professional development. Onsite dining is provided at our office locations in Barcelona and Vienna. Applicants must be authorized to work in Austria or Spain without the need for sponsorship, and the company will not provide sponsorship for this role. The position is based in either Barcelona, Spain, or Vienna, Austria, allowing for a flexible yet structured work environment.