AI Privacy Engineer / Data Protection
Expleo · Lisbon, Portugal
IT Services and IT Consulting · 10,001+ employees
About the role
The role involves managing AI data protection gates and translating complex regulatory frameworks like GDPR and the EU AI Act into practical technical guidance. You will also conduct privacy risk assessments and act as a liaison between engineering, product, and data protection teams to ensure compliant AI deployments.
What they look for
Requirements
Candidates must have at least 3 years of experience in data protection, privacy, and AI governance. Strong knowledge of technical controls, risk mitigation, and regulatory compliance within AI system architectures is required.
Full description
Overview
Expleo is a trusted partner for your innovation journey. As a global engineering, technology and consulting service provider, we are ideally positioned to help you achieve your ambitions and future-proof your business. With a smart blend of bold thinking and reliable execution, we’re able to fast-track innovation through each step of your value chain.
We are strategically positioned to build value, with global footprint across 30 countries.We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.
We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.
Responsibilities
- 3+ years of experience in Data Protection, Privacy & AI Governance
- Own the AI Data Protection Gate for AI use cases, preparing decision-ready evidence and providing clear go/no-go recommendations.
- Translate GDPR, EU AI Act, internal Data Protection Frameworks and policies into practical technical guidance for AI engineers and platform teams.
- Handle the embedded Privacy by Design and by Default into AI solutions, ensuring compliance with lawful basis, purpose limitation, data minimisation, retention and transparency principles.
- Produce and maintain comprehensive documentation, including data flows, RoPAs, design decisions, technical controls and safeguards, enabling effective review by Data Protection teams.
- Conduct privacy Risk Assessments, including DPIAs and AI risk analyses, identifying risks related to personal data processing, AI models and system architecture.
- Define and implement pragmatic risk mitigation measures in close collaboration with engineering teams, ensuring compliant and secure AI deployments.
- Act as the liaison between engineering, product and Data Protection teams, ensuring technical implementations remained transparent, auditable and aligned with regulatory expectations.
- Responsible for enabled scalable AI governance by maintaining auditable evidence of compliance, accountability and technical implementation across AI initiatives.
- Coordinate data Subject Rights Requests (DSRs) involving AI systems and supported readiness for AI-related personal data incidents alongside AI Security and central Data Protection teams.