Compliance, Data Privacy Officer, Vice President, Frankfurt
Generate a McCoy IQ challenge in 30 seconds.
See how candidates think and approach the work this role demands, before the phone screen. We'll build a video challenge from this posting, and you can edit or share it before it goes live.
Key details
Job Description
OUR IMPACT
Our division prevents, detects and mitigates compliance, regulatory and reputational risk across the firm and helps to strengthen the firm’s culture of compliance. Compliance accomplishes these through the firm’s enterprise-wide compliance risk management program. As an independent control function and part of the firm’s second line of defense, Compliance assesses the firm’s compliance, regulatory and reputational risk; monitors for compliance with new or amended laws, rules and regulations; designs and implements controls, policies, procedures and training; conducts independent testing; investigates, surveils and monitors for compliance risks and breaches; and leads the firm’s responses to regulatory examinations, audits and inquiries. You'll be part of a team with members from a wide range of academic and professional backgrounds, such as law, accounting, sales, and trading. We look for those who possess sound judgment, curiosity, and are able to adapt to a changing regulatory landscape.
YOUR IMPACT
We are seeking a qualified and experienced Data Protection Officer (DPO) to join Goldman Sachs’ Global Privacy Office (GPO), in Frankfurt. In this role, you will serve as the appointed DPO for our German and EU-based entities (including Goldman Sachs Bank Europe SE and its branches). Beyond local privacy compliance, you will act as a key advisor on cross-border privacy challenges, international data transfers, and the evolving global regulatory landscape. You will partner closely with business leaders, engineers, and control functions to navigate complex privacy risks, technological innovations, and regulatory changes in a highly regulated financial services environment.
Key Responsibilities
- Formal DPO Appointment: Act as the designated Data Protection Officer for Goldman Sachs Bank Europe SE and other EU-based affiliates and branches.
- Regulatory Liaison: Serve as the primary, official point of contact for the German Federal and State Data Protection Authorities (e.g., the Hessian Commissioner for Data Protection and Freedom of Information - HBDI) and other EU supervisory authorities, as required.
- Business & Engineering Advisory: Provide expert, risk-based privacy guidance to business units, engineers, operations, and compliance teams to enable the compliant development of financial products, digital marketing initiatives, and technology platforms.
- Data Protection Impact Assessments (DPIAs): Advise on, facilitate, and monitor DPIAs for high-risk processing operations, particularly regarding complex financial technologies, profiling, and AI-driven systems.
- Financial Sector Compliance Integration: Align privacy risk management with financial regulatory frameworks, including BaFin requirements (MaRisk, BAIT) and anti-financial crime standards (AML/KYC), balancing data minimization with statutory retention duties.
- Cross-Border Data Transfers: Advise on complex international data flows, utilizing Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and transfer impact assessments (TIAs) to safeguard global operations.
- Privacy Governance: Support the development, implementation, and maintenance of the GPO's privacy program governance frameworks in collaboration with Legal, Compliance, Technology, and Risk.
- Policy Development: Shape and update internal privacy policies, procedures, and guidelines to reflect emerging regulatory expectations, German case law, and business realities.
- Privacy Culture: Promote a culture of privacy accountability across the first line of defense through targeted training, education, and strategic influence.
Basic Qualifications
- Bachelor’s Degree or international equivalent; Law Degree helpful
- At least 7 years of work experience, with at least 5 of those working in the Privacy or Data Protection domain, ideally within a highly regulated sector (e.g., investment banking, financial services, or fintech)
- Deep, authoritative knowledge of the GDPR and the German Federal Data Protection Act (BDSG). Strong familiarity with the Telecommunications Digital Services Data Protection Act (TDDDG) and the EU AI Act is highly desirable.
- Proven track record of serving as an appointed DPO or Deputy DPO, with direct experience managing relationships with German supervisory authorities.
- CIPP/E, TÜV / DEKRA, GDDcert.EUor Betriebliche/r Datenschutzbeauftragte/r (IHK) useful
- Experience in digital marketing and financial services is a plus
- Professional fluency in both German and English (written and spoken) is mandatory to effectively liaise with local regulators and global stakeholders
Required Skills
- Highly motivated with the ability to work autonomously as well as in a team and collaboration-oriented environment
- Highly organized, attention to detail and excellent follow-through skills
- Strong analytical and problem-solving skills; risk-based prioritization
- Excellent verbal and written communication skills to effectively articulate complex regulatory requirements to a broad range of stakeholders and dependent teams at all levels of the firm
- Able to coordinate activities with multiple interdependencies and to escalate items that are unresolved or at risk
- Comfortable working with incomplete information, to ask focused questions and rapidly gain an in-depth understanding of the current processes and compare and relate to similar situations
- Detailed problem tracking, resolutions and completion of all actions and issues by their deadlines
Audit details(provenance, verification trail, raw fields)
Core fields
goldmansachs:165360_GS_MID_CAREERProvenance
https://api-higher.gs.com/gateway/api/v1/graphqlVerification trail
This posting hasn't been probed by our closure verifier yet. Stream C runs on a rolling schedule against postings approaching the close-decision threshold.
LLM enrichment
See how we measure for definitions, or our corrections log for known issues. Found something wrong? Flag a correction.
