Springer Nature
Springer Nature
Springer Nature is an international academic publisher and information provider with more than 180 years of experience serving the research, healthcare, education, business, and professional communities. Its publishing portfolio spans science, technology, medicine, business, and education, giving researchers, clinicians, educators, and other professionals access to books, journals, research, and insights. The company publishes Nature and other influential journals, including a substantial body of Open Access content, and operates through a global workforce across offices worldwide.

Group Data Protection Officer – Berlin (Hybrid)

Lead GDPR, UK GDPR and AI Act compliance for Springer Nature, a global research publisher. Advise authorities, senior management and cross-functional teams on data protection.

Description

  • Carry out the responsibilities of a Data Protection Officer under Article 39 of the GDPR.
  • Maintain the Group’s Article 30 record of processing activities.
  • Support business teams in meeting GDPR compliance requirements.
  • Lead cross-functional initiatives to ensure compliance with applicable data-processing laws.
  • Serve as the central contact for data protection authorities and internal teams seeking regulatory guidance.
  • Report to the highest management level of individual Springer Group entities and access the executive board when required.
  • Report to the Chief Risk & Compliance Officer.
  • Advise Springer Nature and its employees on GDPR and other European, EU Member State and UK data protection obligations.
  • Cooperate with supervisory authorities and handle personal-data processing matters.
  • Advise on and monitor data protection impact assessments.
  • Monitor legislative developments, EDPB guidelines and supervisory authority guidance.
  • Partner with Governance, Risk & Compliance and Legal teams on AI Act, GDPR and UK GDPR compliance.
  • Monitor adherence to data protection laws and Springer Group policies.
  • Design, coordinate and deliver employee awareness and training programmes.
  • Integrate data protection risks into the broader risk-management framework and support internal audits.
  • Coordinate external advice on legal developments and support litigation and global data protection projects.
  • Develop and strengthen the Springer Nature data protection framework.
  • Prepare compliance, risk and KPI reports for senior management and the board.
  • Coordinate the upkeep of Records of Processing Activities (ROPA).
  • Coordinate data-breach response and advise on notification obligations.
  • Act as the contact for data subjects, including access requests and complaints.
  • Draft and maintain data protection policies, retention schedules, privacy notices and internal standards.
  • Advise on or maintain data processor and sub-processor registers and support due diligence.
  • Monitor international data-transfer arrangements and support Transfer Impact Assessments.
  • Allocate responsibilities and distribute advisory and operational work within the team.
  • Define, scope and resource data protection development projects.
  • Coordinate with the General Counsel’s Office and business partners.
  • Manage team performance and feedback processes.

Requirements

  • Deep expertise in data protection law across the EU and UK.
  • Experience implementing and maintaining a focused data protection framework.
  • Experience handling consent requirements and developing consent management systems.
  • A degree or certificate in a data protection-related discipline.
  • At least one IAPP certification.
  • Experience in the legal department of a medium-to-large industrial company, ideally in communications, publishing or IT.
  • Experience collaborating across functions in matrix organizations.
  • Fluent English communication skills.
  • Business-level proficiency in another European language.
  • A demonstrated ability to work effectively through change and growth.
  • Strong organizational and time-management capabilities.
  • Strong influencing and collaboration skills across organizational levels.
  • Analytical approach with close attention to detail.
  • Team-oriented, proactive and adaptable working style.
  • Knowledge of data protection laws in other jurisdictions, ideally including Indian law and US state law.
  • Knowledge of EU and UK digital law affecting data-processing conditions.
  • Experience jointly assessing risk and compliance for processing governed by GDPR, UK GDPR and the AI Act.
  • Experience with data protection documentation and reporting tools such as OneTrust.
  • German language skills are desirable.

Benefits

  • Hybrid working arrangement based in Berlin or London.
  • Inclusive workplace focused on diversity, equity and inclusion.
  • Workplace accommodations available for disability, neurodivergence or chronic conditions.

Related Jobs

Kreato Global | BPO and Language Solutions

Remote English-Spanish OPI/VRI Interpreter

Kreato Global | BPO and Language Solutions
201 – 500 Employees
HealthcareHospitalityLogistics

Interpret remotely between English- and Spanish-speaking people in medical, financial, social service, and customer care settings. Provide language support for Kreato Global across Latin America.

Open
SPERTON - Where Great People Meet

Sales Executive, Elevators and Car Parking Systems

SPERTON - Where Great People Meet
51 – 200 Employees

Drive elevator and car parking system sales across Mumbai’s Western Region. Build client and dealer relationships, and manage deals from initial enquiry through project execution.

Open