About this Senior Data Protection Officer role at Viva.com
Viva.com is the first Tech Bank in Europe for businesses, serving 31 countries through its pan-European critical infrastructure for payments & banking services.
Viva.com’s offering spans omnichannel payment acceptance, deposit accounts, card issuing, and a broad suite of financing solutions, providing businesses of all sizes and sectors with the tools they need to operate efficiently, both domestically and internationally, through a single integrated platform.
Viva.com pioneered and leads in Tap on Any Device technology, enabling acceptance on any Android device or iPhone, while connecting directly to all major international and domestic card schemes, local payment systems, and alternative payment methods across Europe.
The Role
We are seeking an experienced Data Protection Officer to lead and continuously strengthen our data protection framework across our banking, payments and technology operations.
Acting independently and with direct access to senior management and the relevant governing bodies, you will oversee compliance with the GDPR and applicable privacy legislation, advise the organisation on complex data protection matters and serve as the primary point of contact for supervisory authorities and data subjects.
This is a senior, hands-on role requiring strong legal and regulatory expertise, sound business judgement and a deep understanding of how personal data is used across digital products, financial services, AI-enabled solutions and large-scale technology environments.
Key Responsibilities
- Act as the organisation’s appointed Data Protection Officer in accordance with Articles 37–39 of the GDPR, performing the role independently and without conflict of interest.
- Monitor compliance with the GDPR, applicable national and European privacy legislation, internal policies and regulatory expectations across the organisation.
- Advise senior management, business functions and governing bodies on complex data protection matters, emerging risks and required remediation actions.
- Serve as the primary point of contact for Data Protection Authorities, managing regulatory enquiries, inspections, consultations and notifications.
- Oversee the Data Protection Impact Assessment (DPIA) framework and advise on high-risk processing activities, new products, technologies and strategic initiatives.
- Provide privacy guidance on AI systems, profiling, automated decision-making, analytics, fraud prevention, biometric data and other emerging technologies.
- Embed privacy by design and by default throughout product development, system implementation, process redesign and third-party integrations.
- Oversee the management of personal data breaches, ensuring appropriate assessment, documentation, escalation and regulatory notification.
- Monitor the handling of data subject requests and ensure they are completed accurately and within applicable regulatory deadlines.
- Review and advise on records of processing activities, privacy notices, retention frameworks, consent mechanisms and lawful bases for processing.
- Assess data protection provisions in agreements with customers, suppliers, processors and strategic partners, including international data transfers.
- Provide oversight and challenge regarding third-party privacy risk assessments and data processing arrangements.
- Design and maintain data protection policies, governance frameworks, controls, reporting mechanisms and annual compliance plans.
- Deliver targeted training and awareness initiatives to strengthen accountability and privacy awareness across the organisation.
- Produce regular reports for senior management and relevant committees on privacy risks, incidents, compliance performance and remediation progress.
- Work closely with Legal, Compliance, Risk, Information Security, Technology, Product and Internal Audit while maintaining the independence of the DPO function.
- Leverage AI-enabled and automated tools to improve compliance monitoring, risk identification, reporting and operational efficiency.
At Viva.com, we believe in amplifying human potential through AI. When you join us, you're stepping into a future-forward environment where technology empowers every role, driving smarter, more efficient.
Requirements
- Bachelor’s degree in Law; a postgraduate qualification in Data Protection, Technology Law, Information Security or a related discipline is highly desirable.
- At least 8 years of relevant professional experience, including significant experience in a senior privacy role or as an appointed DPO.
- Proven experience within banking, payments, fintech, technology or another highly regulated and data-intensive environment.
- Expert knowledge of the GDPR, ePrivacy requirements, international data transfer mechanisms and relevant European data protection guidance.
- Strong understanding of privacy risks associated with AI, automated decision-making, cloud technologies, digital identity, biometrics and large-scale data processing.
- Demonstrated experience managing DPIAs, personal data breaches, regulatory interactions and complex data subject matters.
- Ability to interpret regulatory requirements and translate them into practical, proportionate and business-oriented controls.
- Strong stakeholder management skills and the confidence to provide independent challenge and influence senior decision-makers.
- Excellent analytical, communication, drafting and presentation skills.
- High level of integrity, professional judgement and discretion.
- Professional certification such as CIPP/E, CIPM, CIPT, CDPO or equivalent is considered a strong advantage.
- Fluency in English and Greek.
Benefits
💸 Competitive compensation package;
🎯Annual bonus based on your performance and targets’ achievement;
🏥 Private health insurance for you and your family;
💻 Top of the Line tools and equipment;
📚 Career development and regular feedback to develop your skills;
🏃🏽♂️ Employee Wellness Program like Daily group sessions led by professional coaches.