- Company Name
- JCDecaux
- Job Title
- CDI - Juriste en Données Personnelles (F/H)
- Job Description
-
**Job Title**
Personal Data Lawyer (Data Protection Attorney) – CDI
**Role Summary**
Provide legal expertise on data protection and privacy compliance across a multinational group. Support the Data Protection Officer (DPO) and operational teams to secure projects involving personal data, ensure GDPR and related regulations are met, manage contractual obligations, conduct risk assessments, deliver training, and coordinate global data protection initiatives including cross‑border data transfers and AI governance.
**Expectations**
- Draft and review legal documents, advisories, contracts, and privacy policies.
- Conduct compliance reviews and impact assessments for new and ongoing projects.
- Serve as an internal consultant on data protection matters, advising multiple business units.
- Lead data protection training, awareness campaigns, and cultivate a culture of privacy.
- Maintain up‑to‑date knowledge of evolving privacy laws, cyber‑security standards, and AI regulations.
- Coordinate with group subsidiaries to harmonise GDPR compliance and local legislation.
**Key Responsibilities**
1. **Legal Advice & Project Support**
- Analyse project compliance with GDPR and related statutes.
- Provide legal recommendations and drafted instruments for operational teams.
2. **Contract Management & Partner Relations**
- Draft, negotiate, and secure data‑privacy clauses in contracts with partners, clients, and suppliers.
- Establish Data Processing Agreements (DPAs) and joint‑responsibility agreements.
- Monitor sub‑processor compliance.
3. **Governance & Compliance**
- Maintain and update the Processing Activities Register.
- Lead or support Data Protection Impact Assessments (DPIAs).
- Update privacy policies, notices, retention schedules, and rights‑exercising procedures.
4. **Rights Management**
- Process and respond to individuals’ rights requests (access, rectification, erasure, etc.).
5. **Education & Culture Building**
- Design and deliver privacy awareness training.
- Author guides and practical sheets for staff.
- Promote GDPR culture and manage the intranet privacy hub.
6. **Regulatory & Technological Monitoring**
- Track legislative and jurisprudential developments in privacy, digital, and cyber‑security.
- Monitor emerging technologies that impact personal data handling, including AI.
7. **International Coordination**
- Advise subsidiaries on GDPR compliance and local requirements.
- Organise group‑wide data protection coordination and intra‑group data transfer agreements.
8. **AI Governance**
- Participate in AI governance initiatives, ensuring legal soundness of AI projects involving personal data.
**Required Skills**
- Advanced knowledge of GDPR, e‑Privacy, French Loi Informatique et Libertés, CNIL/EDPB guidelines.
- Proficiency in drafting and negotiating data‑protection clauses in IT and digital contracts.
- Strong analytical, problem‑solving, and advisory capabilities.
- Effective communication skills for training and stakeholder engagement.
- Awareness of cyber‑security risks and data‑management technologies.
- Ability to operate in a multilingual, international environment.
**Required Education & Certifications**
- Master’s degree (Bac +5) in Digital Law, Data Protection Law, or equivalent.
- Minimum 3‑5 years experience in data protection roles (corporate, law firm, or consulting).
- Experience within a large or international organization is highly desirable.
Neuilly-sur-seine, France
On site
15-01-2026