
GDPR Compliance Consultant
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Carry out assessments and gap analyses to evaluate readiness for GDPR and UK GDPR compliance.
• Create and implement programs for GDPR compliance and develop remediation roadmaps.
• Prepare and sustain Records of Processing Activities (ROPA).
• Conduct Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments (LIAs), and Transfer Impact Assessments (TIAs).
• Draft, review, and negotiate Data Processing Agreements (DPAs).
• Evaluate privacy notices, consent mechanisms, cookie disclosures, and related privacy documentation.
• Design and establish processes for Data Subject Rights (DSAR).
• Advise clients on requirements for international data transfers, including EU Standard Contractual Clauses, UK IDTA/Addendum, and the EU-U.S. Data Privacy Framework.
• Assess privacy risks associated with third parties and assist with vendor due diligence.
• Develop privacy policies, governance documents, and operational procedures.
• Support organizations that handle special category data, including healthcare and clinical research information.
• Provide guidance on Article 27 representative requirements and interactions with supervisory authorities.
• Conduct client workshops, deliver executive presentations, and provide privacy awareness training.
• Work collaboratively with cybersecurity consultants to ensure alignment between privacy and security controls.
• Stay updated on GDPR guidance, enforcement actions, and changes in privacy regulations.
• Execute GDPR consulting engagements within designated timelines and scope.
• Produce high-quality compliance documentation requiring minimal revisions.
• Guide clients towards achieving GDPR compliance and suggest practical remediation strategies.
• Foster trusted advisor relationships with executive stakeholders.
• Bachelor’s degree in Information Security, Privacy, Law, Business, Computer Science, Healthcare Administration, or a related field, or equivalent professional experience.
• A minimum of five years of experience in GDPR consulting or privacy compliance.
• Proven track record of implementing GDPR compliance programs.
• Experience in conducting GDPR readiness assessments and gap analyses.
• Proficient in preparing and maintaining ROPA documentation.
• Skilled in performing DPIAs, LIAs, and TIAs.
• Experienced in drafting and reviewing Data Processing Agreements.
• Knowledgeable in developing privacy governance programs.
• Capable of advising executive leadership and client stakeholders.
• Strong understanding of EU GDPR and UK GDPR.
• Comprehensive knowledge of ROPA, DPIAs, LIAs, TIAs, DSAR, DPAs, international data transfers, SCCs, UK IDTA/Addendum, EU-U.S. Data Privacy Framework, vendor risk management, Privacy by Design, privacy governance frameworks, Article 27 representative requirements, consent management, privacy notices, data mapping, data retention, and special category data processing.
• Excellent written and verbal communication abilities.
• Ability to engage directly with executive-level clients.
• Professional privacy certifications such as CIPP/E, CIPM, CIPT, or equivalent are strongly preferred.
• Experience supporting multinational organizations is preferred.
• Previous consulting experience is strongly preferred.
• Industry experience in healthcare, life sciences, biotechnology, clinical research, pharmaceuticals, medical devices, SaaS, or technology is highly desirable.
• Familiarity with ICH-GCP, clinical trial regulations, informed consent requirements, HIPAA, or special category health data processing is preferred.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible working hours and remote work options.
• Opportunities for professional development and certifications.
• Supportive and inclusive company culture.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.