Ember Talent - Data Protection Officer
Requirements
• · Minimum 8 years' experience in data protection, privacy or information governance, with at least 3 years in a senior privacy leadership role including DPO or equivalent statutory privacy-officer duties. • · Deep working knowledge of GDPR and UK GDPR, the Australian Privacy Act and APPs, and at least one major APAC privacy regime (Singapore PDPA, Japan APPI, or equivalent). • · Demonstrable experience of HIPAA and HITECH in a health-technology setting, including handling of PHI in cloud environments. • · Proven ability to run DPIAs, manage breach notifications across multiple jurisdictions, and maintain ROPAs. • · Experience of Transfer Impact Assessments and cross-border transfer mechanisms post-Schrems II. • · Working understanding of privacy-enhancing technologies (encryption, tokenisation, de-identification, differential privacy, federated learning) sufficient to challenge and validate technical designs. • · Ability to interpret data flows, technical architectures and AI/ML pipelines, and to translate regulatory obligations into concrete engineering and product controls. • · Excellent written and verbal communication, with the ability to brief executives, engage regulators, and challenge senior stakeholders constructively. • · At least one relevant certification: CIPP/E, CIPP/US, CIPM, CIPT, CISM, or ISO 27001 Lead Implementer. • · Prior experience as DPO or Privacy Officer in a health-technology, MedTech or SaMD company. • · Familiarity with EU MDR 2017/745, ISO 13485, ISO 14971 and IEC 81001-5-1, sufficient to interface effectively with the Regulatory Affairs and Quality functions. • · Working knowledge of the EU AI Act obligations for high-risk AI systems. • · Experience integrating privacy controls with AI/ML models, vector databases and large-language-model services in regulated environments. • · Experience of regulator inspections, Notified Body audits, or FDA-facing audit-readiness activity. • · Familiarity with data catalogue and metadata management tooling (e.g. Collibra, Azure Purview) sufficient to assess control design without owning implementation.
Responsibilities
• 1. Statutory DPO and privacy officer duties • · Act as the designated contact point for supervisory authorities and data subjects across all regions listed above. • · Inform and advise Helfie and its processors on their obligations under applicable privacy and health-data laws (GDPR Art. 39(1)(a); equivalents). • · Monitor compliance with applicable data protection law, internal policies, awareness training and audits. • · Facilitate Data Protection Impact Assessments (DPIAs) under GDPR Art. 35 and cooperate with supervisory authorities on prior consultation where required (Art. 36). • · Maintain and keep current the Records of Processing Activities (ROPA) under GDPR Art. 30 and equivalent registers under other regimes. • 2. Health data and medical device interface • · Ensure that all Helfie products handling personal health information (PHI) comply with GDPR, HIPAA, the Australian Privacy Act, and applicable local health-data laws wherever Helfie operates. • · Interface with the CEO, Head of Regulatory Affairs and Compliance (HRAC), the Chief Strategy Officer, and the Quality Manager on data-related risk controls. • · Support Notified Body engagement on data protection, cybersecurity and privacy-by-design aspects of the Technical Documentation. • · Ensure vigilance and post-market surveillance processes correctly handle the appropriate reporting paths • 3. EU AI Act and AI governance • · Own the data-governance responsibilities that arise from the EU AI Act for AI systems and their interaction with GDPR. • · Advise on lawful basis, purpose limitation and data minimisation for training, validation and test datasets used in Helfie's AI/ML pipelines, including foundation-model and LLM-based components. • · Support the Chief Strategy Officer and Head of Regulatory Affairs and Compliance in maintaining a coherent regulatory position across MDR, AI Act and privacy regimes. • 4. Governance framework and policy • · Own the group data protection and privacy policy framework, including data classification, retention, secure disposal, and data subject rights procedures. • · Author and maintain appropriate breach-response playbooks with defined regulator-notification timelines • · Advise on privacy-by-design and privacy-by-default as new products enter development. • 5. International data transfers • · Manage cross-border data-transfer mechanisms including Standard Contractual Clauses, UK IDTA/Addendum, and applicable adequacy decisions. • · Conduct and maintain Transfer Impact Assessments (TIAs) consistent with Schrems II expectations. • · Assess and, where required, put in place Binding Corporate Rules or intra-group data transfer agreements as Helfie scales. • 6. Incident response • · Lead privacy-incident response: detection, containment, investigation, notification, and remediation. • · Coordinate with the Quality Manager and HRAC where privacy incidents interact with the device vigilance system. • · Own regulator-facing incident communications. • 7. Education, culture and stakeholder engagement • 7. Education, • culture • and stakeholder engagement • · Design and deliver role-based privacy awareness training, including tailored modules for engineering, clinical and commercial teams. • · Advise product and engineering teams on integrating privacy-by-design into the software development lifecycle. • · Represent Helfie in external forums, industry bodies and regulator engagements on data protection matters.
Benefits
• · A senior seat at the table on one of the most consequential problems in global health. • · Direct engagement with regulators, Notified Bodies and clinical partners globally. • · Flexible working arrangements and a hybrid schedule. • · A collaborative and innovative team environment. • Equal opportunity statement
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT