- Company Name
- CONMED Corporation
- Job Title
- International Compliance Manager – GDPR & Privacy
- Job Description
-
Job title: International Compliance Manager – GDPR & Privacy
Role Summary:
Lead the global privacy and data protection program for a medical technology organization, ensuring compliance with GDPR, UK Data Protection Act, and related international regulations. Act as the primary liaison with data protection authorities, conduct impact assessments, oversee cross‑border transfers, and drive culture of compliance across sales, distribution, and partner channels.
Expectations:
* Maintain and evolve a robust privacy framework that aligns with evolving regulations and corporate ethics.
* Deliver timely, actionable risk insights to executive leadership and support strategic decision‑making.
* Foster an environment where employees and partners feel empowered to raise compliance concerns without fear of retaliation.
Key Responsibilities:
1. Develop, implement, and maintain a global privacy and data protection framework (GDPR, UK DPA, etc.).
2. Serve as point of contact for UK, Ireland, and other applicable Data Protection Authorities.
3. Conduct and manage privacy impact assessments (PIAs) and data protection impact assessments (DPIAs).
4. Oversee cross‑border data transfer mechanisms (SCCs, BCRs) and ensure contractual alignment with partners (distributors, physicians, education providers).
5. Provide guidance on privacy‑by‑design and privacy‑by‑default principles to internal teams.
6. Lead internal audits, risk assessments, and compliance reviews; identify and mitigate risks.
7. Design and deliver privacy and compliance training for all levels of staff, including sales and distribution teams.
8. Monitor regulatory developments, advise on emerging privacy risks, and update policies accordingly.
9. Manage complaint channels, conduct investigations, and drive remediation to prevent recurrence.
10. Establish metrics and benchmarks to evaluate compliance program effectiveness and report findings to leadership.
11. Collaborate with Finance, HR, and other functional units on investigations and resolution of compliance matters.
Required Skills:
* In‑depth knowledge of GDPR, UK DPA, and international privacy regulations.
* Experience with U.S. FCPA compliance and publicly traded company requirements.
* Proficiency in conducting PIAs, DPIAs, audits, and risk assessments.
* Strong project management and resource allocation abilities.
* Excellent oral and written communication, presentation, and stakeholder influence skills.
* Ability to navigate ambiguity, prioritize multiple projects, and meet deadlines.
* Integrity, confidentiality, and high ethical standards.
Required Education & Certifications:
* Bachelor’s degree in Law, Business, Information Security, or related field from an accredited university.
* Minimum of 5 years’ experience in a medical device or medical technology company, including 3 years focused on GDPR compliance.
* Preferred: Graduate degree and/or professional accreditation (e.g., Certified Information Privacy Professional – Europe).
---