Lead Legal Counsel, Group DPO
About the Role
As Europe’s leading multi-asset broker, Bitpanda operates at the cutting edge of FinTech, Web3, and AI. With hyper-growth comes the responsibility of safeguarding our users' trust. In this lead role, you will define and execute the global data protection strategy for the Bitpanda Group. You will serve as the primary point of contact for supervisory authorities, and act as a crucial business enabler; ensuring that our innovative product pipeline scales securely and completely in line with the GDPR and emerging regulatory frameworks.
What You’ll Do
Strategic Lead: Design, implement, and continuously evolve the Bitpanda Group's enterprise-level data protection management system (DPMS), ensuring a robust internal compliance framework across all international markets.
Regulatory & Authority Liaison: Serve as the official Group Data Protection Officer and primary point of contact for data protection supervisory authorities across Europe, UK and the UAE. Lead the response to high-level inquiries and regulatory audits.
Business Enablement & AI: Partner directly with the C-suite, engineering, and product divisions to provide pragmatic, solution-oriented privacy advice on complex, cutting-edge initiatives; specifically at the intersection of data privacy, blockchain technology, and AI.
Control Framework & Monitoring: Own the Group's data protection control framework, oversee regular monitoring and control testing, drive remediation of identified gaps, and report on framework effectiveness to senior management to ensure continuous improvement.
Operational Excellence: Oversee the escalation of complex data subject access requests (DSARs), lead the incident response strategy for personal data breaches, and handle high-stakes negotiations for critical data processing agreements (DPAs) and international data transfers.
Awareness & Culture: Monitor the rapidly shifting regulatory landscape in the digital asset space and data protection. Translate complex legal developments into actionable business strategies and drive company-wide privacy training and awareness initiatives.
Who You Are
Extensive Legal Experience: You bring 7+ years of experience in data protection , ideally with a mix of top-tier international law firms, regulatory authority, and in-house legal or privacy departments and you acted as an appointed Data Protection Officer.
Strategic Management: you navigate complex regulatory environments surrounding digital assets and regulated financial services. You understand how to balance aggressive business growth with strict risk and compliance frameworks.
Pragmatic Problem Solver: You don't just point out legal roadblocks; you navigate them. You are known for delivering precise, reliable, and commercially viable legal advice while managing multiple competing priorities.
Communication Skills: You are fully fluent in English and C1 or higher level of German is a must have.
Certifications: Recognized privacy certifications (e.g., CIPP/E, CIPM) are highly advantageous.