A Belgian public infrastructure organisation operates energy distribution networks and manages data on customers, connections, meters, interventions and energy consumption. A Privacy Consultant will support the Data Protection Officer (DPO) and Legal Team as the organisation prepares for ISO 27001 and ISO 27701 certification in 2027, focusing on GDPR compliance, the Record of Processing Activities (RoPA) and data protection risk.
The mission
The organisation delivers essential public services through its energy networks. It is adapting its infrastructure for smart meters, energy sharing and new energy uses, creating processing across customer, technical and consumption domains. These activities must comply with GDPR, Belgian data protection legislation and NIS2, while supporting the controls expected for ISO 27001 and ISO 27701 certification. Privacy governance must connect these requirements to data governance for classification, retention, transfers and cloud environments.
At medior level, you will provide day-to-day support to the DPO and Legal Team, using at least three years of legal and privacy experience. You will maintain the RoPA, identify processing activities requiring a DPIA, and complete DPIAs and risk assessments with relevant stakeholders. You will review DPAs, supplier contracts and policies, then help establish a repeatable process and plan for maintaining compliance. The role combines autonomous delivery with collaboration across legal, security and operational teams.
Your responsibilities
- Maintain and improve the RoPA by validating processing purposes, data categories, ownership, retention and transfer information.
- Identify gaps and complete DPIAs and risk assessments, documenting mitigations and follow-up actions.
- Establish an ownership and review process that keeps the RoPA, DPIAs and supporting evidence current.
- Draft and review DPAs, supplier contracts and client agreements, focusing on information security and privacy clauses.
- Strengthen data governance for classification, retention, international transfers and cloud environments.
- Advise the DPO and Legal Team on policy updates and a practical compliance plan aligned with GDPR, ISO 27001/27701 and NIS2.
Your profile
Essential skills
- Bring at least three years of demonstrable experience as a Legal Expert and Privacy Expert, supported by reference projects in your CV.
- Apply GDPR and Belgian data protection legislation to operational processing activities and internal policies.
- Build and maintain a RoPA, including processing purposes, data categories, retention and transfer details.
- Prepare DPIAs and risk assessments, identify mitigations and follow up on actions.
- Manage data governance questions involving classification, retention, transfers and cloud environments.
- Draft and review DPAs, supplier contracts and client agreements covering information security and privacy.
- Work proactively and autonomously, take responsibility for deliverables and collaborate with legal, security and operational stakeholders.
Preferred skills
- Apply ITIL concepts to privacy-related processes where relevant.
- Bring knowledge of the Belgian energy market.
- Hold a CIPP/E certification or equivalent.
Languages
- Dutch: CEFR B2 or higher.
- French: CEFR B2 or higher.
- English: CEFR B2 or higher.
Education
- Master's degree in Law.

