DPO (Ontario)

DPO (Ontario)

06 Sep
|
ACENSI
|
Ontario

06 Sep

ACENSI

Ontario

About The Job

About The Job

Expanding steadily since its launch in 2003, the ACENSI group is an IT consultancy firm, well known for their technical and functional know-how, who specialize in Telecommunications, Media and Financial Markets, as well as in the Energy industry. ACENSI guides businesses in evolutionary IT projects from the initial strategies through to their realization (Management and Project management, Development, Design and Implementation, Infrastructure). From its original focus on technical engineering and Business Analysis, ACENSI has developed new areas of expertise in Human Resource Management Systems, Business Intelligence, e-learning and Client Relationship Management.

Dynamism, enthusiasm and social development are all valued at ACENSI, allowing our clients to benefit from consultants with a true blend of talents.

ACENSI BELGIUM is looking for his client a DPO (F/M/X)

Description

Context and Reporting Line

This is a critical position as the DPO is a legally required role within a federal public service organization. The DPO operates within a staff department reporting to the Chief Executive Officer. The DPO reports directly to the department director and to the CEO. The DPO performs their function independently and does not manage a dedicated team.

The DPO role is defined by Articles 38 and 39 of the GDPR. The DPO is responsible, among other duties, for monitoring compliance with GDPR requirements. The DPO assists the Data Controller and Data Processor in assessing and ensuring internal GDPR compliance.

As Part Of This Compliance Oversight, The DPO May

- Collect information to identify processing activities.
- Analyze and monitor the compliance of organizational processing activities.
- Provide information, advice, and recommendations to the Data Controller or Processor.

Key Responsibilities

- Governance & Oversight

Possible Tasks

- Monitor compliance with GDPR, privacy legislation, and related regulations.
- Advise management and business departments regarding data protection obligations.
- Contribute to the development, documentation, and follow-up of a coherent framework of roles, responsibilities, procedures, and reporting mechanisms related to data protection within our client.
- Report to senior management on the status, risks, and improvement opportunities concerning data protection.
- Safeguard the independence of the DPO function and avoid conflicts of interest.

Essential GDPR Responsibilities

- Monitor compliance with Articles 5, 6, 24, 25, 30, 32, 33-36, and 37-39 GDPR.
- Advise on and monitor Privacy by Design and Privacy by Default principles.
- Document advice and recommendations to ensure accountability.
- Support audits, inspections, and reviews related to data protection.
- Prepare periodic reports on compliance, risks, and remediation actions.
- Record of Processing Activities

Possible Tasks

- Oversee the creation, maintenance,



and updating of the Record of Processing Activities (Article

30 GDPR).
- Support internal departments in identifying and documenting personal data processing activities.
- Evaluate processing purposes, legal bases, retention periods, and data flows.
- Data Protection Impact Assessments (DPIA)

Possible Tasks

- Advise on the need to conduct DPIAs.
- Guide and validate DPIAs for new or modified processing activities.
- Monitor mitigation measures and follow up on residual risks.
- Advise on prior consultation with the Data Protection Authority when required.
- Policy & Strategic Advisory Role

Possible Tasks

- Contribute to the development, evaluation, and updating of our client's data protection policies.
- Advise on strategic choices, new initiatives, and digital transformation projects from a data protection perspective.
- Integrate data protection into broader governance, compliance, and risk management frameworks.
- Identify structural gaps and formulate policy recommendations for management.
- Develop recommendations regarding personal data protection and coordinate the drafting and implementation of policies, guidelines, procedures, and control mechanisms based on legislation, case law, and legal doctrine.
- Data Breaches & Incident Management

Possible Tasks

- Advise on the assessment and handling of personal data breaches.
- Monitor compliance with legal notification requirements, including reporting to the Data Protection Authority within 72 hours in accordance with Article 33 GDPR.
- Advise on and monitor notifications to data subjects where required (Article 34 GDPR).
- Support the organization in establishing an escalation and on-call mechanism to ensure data breaches are assessed and reported in a timely manner, including outside normal working hours.
- Evaluate root causes of data breaches and recommend corrective and preventive actions.
- Contracts & Processors

Possible Tasks

- Advise on Data Processing Agreements and data protection clauses.
- Monitor GDPR compliance of processors and business partners.
- Identify privacy risks in outsourcing arrangements and partnerships.
- Act as the primary contact point for the Data Protection Authority.
- Collaborate with other supervisory authorities where relevant.
- Participate as a member of our client's Information Security Committee (monthly meetings).
- Awareness & Training

Possible Tasks

- Develop and support awareness and training initiatives regarding data protection.
- Act as a point of contact for employees regarding personal data protection matters.




- Contribute to building a privacy-aware organizational culture.
- Data Protection Helpdesk Function

Possible Tasks

- Act as the central point of contact within our client for all questions, notifications, and concerns related to personal data.
- Serve as the first contact point for employees, management, and departments regarding questions, new projects, or processing changes.
- Receive, register, and coordinate notifications of potential incidents or risks.
- Function as an accessible contact point for data subjects regarding data protection matters.

Must-Have Requirements Experience & Expertise

- Demonstrable in-depth knowledge of GDPR, personal data protection principles, and related

legislation.
- Sufficient legal affinity to analyze and advise on contractual clauses, Data Processing Agreements, and cooperation agreements related to data protection.
- Minimum 8 years of professional experience.
- Minimum 5 years of relevant experience in personal data protection.
- 5 to 7 years of experience with risk assessment methodologies (such as DPIA models).
- 4 years of technical knowledge related to secure data exchange between public sector organizations.
- 5 years of experience leading the development and implementation of policies, guidelines, procedures, and control frameworks concerning personal data protection.
- At least three references from assignments performed as an external DPO within large organizations.

Nice-to-Have

- Knowledge of NIS2 and CyFun.
- Experience working within a public sector organization.

Key Behavioral Competencies

- Strong communication and collaboration skills.
- High level of integrity, particularly in handling confidential and sensitive information.
- Ability to work independently and challenge incorrect decisions when necessary.
- Solid analytical mindset with the ability to quickly identify risks.
- Proactive and decisive approach, including anticipating issues before they become incidents and making clear decisions during data breach situations.
- Ability to translate complex regulations into practical guidance for non-legal audiences.

Language Requirements As our client operates in a federal and bilingual environment, both Dutch and French are working languages.

The DPO Must

- Have perfect command of at least one of these two languages.
- Be able to understand and communicate fluently in the other national language.

Additional Language Requirements

- Dutch: Native.
- French: Native.
- English: Active knowledge.

Required Skills

- Development and management of policies, procedures, and guidelines related to personal data

protection.
- Experience in personal data protection.
- Experience with risk assessment methodologies (e.g., DPIA models).
- Strong knowledge of GDPR, personal data protection principles, and related legislation.
- Technical knowledge of secure data exchange between public sector organizations.

📌 DPO (Ontario)
🏢 ACENSI
📍 Ontario

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: dpo (ontario) / ontario

Subscribe to this job alert:

Get the latest job offers by email for: dpo (ontario) / ontario