Role: Group Data Protection Officer
Location: Berlin or London - Hybrid, Permanent
Closing date: Sunday 25th of October 2026
About Springer NatureSpringer Nature is one of the leading publishers of research in the world. We publish the largest number of journals and books and are pioneers in open research. Through our leading brands, trusted for more than 180 years, we provide technology-enabled products, platforms and services that help researchers to uncover new ideas and share their discoveries, health professionals to stay at the forefront of medical science, and educators to advance learning. We are proud to be part of progress, working together with the communities we serve to share knowledge and bring greater understanding to the world. For more information, please visit about.springernature.com and @SpringerNature.
At Springer Nature, we recognise that talent is developed through a range of career paths. We encourage applications from individuals with strong transferable skills, provided they are supported by relevant experience that shows how those skills have been successfully applied in practice. Our hiring approach balances skills, experience, and potential to ensure each role is fulfilled with both short term effectiveness and long-term growth in mind.
About The RoleThe Group Data Protection Officer (Group DPO) shall perform for Springer Nature the tasks of a Data Protection Officer as defined in Art. 39 GDPR and additionally maintain the Group’s Article 30 record. The Group DPO plays a pivotal role in supporting the business with achieving GDPR compliance and is responsible for coordinating and driving the execution of cross-functional initiatives that ensure compliance with other applicable law in data processing. The Group DPO acts as a central point of contact for data protection authorities and internal teams searching authority guidance.
The Group DPO shall directly report to the highest level of management of the individual Springer Group entities and shall have direct access to the executive board if necessary.
The Group DPO reports to the Chief Risk & Compliance Officer.
This is a hybrid role based in Berlin or London. These locations support effective collaboration with the team and aligns with business needs.
Role ResponsibilitiesLegal / Advisory
- Inform and advise Springer and its employees regarding their obligations under the GDPR and other applicable European, EU-Member State or UK data protection provisions, applying strong Governance, Risk and Compliance Management
- Cooperate with data protection supervisory authorities, Building Trust through effective and transparent engagement
- Act as the contact point for supervisory authorities on issues relating to personal data processing, including prior consultations referred to in Art. 36 GDPR/UK GDPR, demonstrating strong Accountability
- Provide advice as regards data protection impact assessments and monitor their performance pursuant to Art. 35 GDPR/UK GDPR, exercising sound Decision Quality
- Monitoring Legislative / Regulatory Developments: tracking legal changes, EDPB guidelines, and supervisory authority guidance, and informing management of their impact, leveraging strong Business Insights
- Working closely with members of the Governance, Risk & Compliance and Legal to ensure reliable, aligned advice towards the business about risk and compliance under both AI Act and GDPR/UK GDPR, demonstrating the ability to Manage Complexity
Supervisory
- Monitor compliance with the GDPR, other applicable European, EU-Member State or UK data protection provisions and the policies of the Springer Group in relation to the protection of personal data, utilizing Data Security & Governance expertise
- Awareness & Training Programmes: designing, coordinating and delivering staff training, in addition to the monitoring role already required under Art. 39 GDPR/UK GDPR
- Integration with GRC / Risk Management: mapping data protection risks into the wider risk management framework, supporting internal audits, and ensuring consistency with other compliance domains through strong Governance, Risk and Compliance Management
- Coordinating external consultation on legal development, in law suits and supporting global business projects with a data protection focus, demonstrating Being Resilient
Operational
- Continued development and enhancement of the existing Springer Nature data protection framework
- Reporting: preparing regular reports to senior management or the board on data protection compliance, risks, and KPIs, applying Data Analytics / Quantitative Skills
- Coordinating maintenance of Records of Processing Activities (ROPA)
- Data Breach Management Support: coordinating the incident response process, collecting relevant information, and advising on notification duties, utilizing strong Conflict Management skills
- Liaison Role: acting as a contact point for data subjects (e.g. handling access requests and complaints, supported by operational teams), Building Trust through responsive and professional stakeholder engagement
- Policy and Procedure Development: drafting and updating data protection policies, retention schedules, privacy notices, and related internal standards
- Vendor Management Support: advising on or maintaining registers of data processors and sub-processors, supporting due diligence, and checking contractual compliance
- International Data Transfers: monitoring transfer mechanisms (e.g. SCCs, BCRs), supporting Transfer Impact Assessments, and advising on related compliance requirements
Team Lead
- Assignment of responsibilities, distribution of advisory and operational duties within the team, demonstrating strong Accountability
- Defining, scoping and staffing data protection development projects, applying sound Decision Quality
- Coordinating cooperation with other teams inside the General Counsel’s Office and with business partners, leveraging Business Insights
- Managing team performance and feedback workflows, utilizing Accounting Principles to support effective governance and control processes
Skills, Experience & Qualifications:Essential
- * In-depth knowledge of data protection law in the EU and UK
- Experience with implementation and maintenance of a concise data protection framework
- Experience with consent requirements and the development of consent management systems
- Degree or certificate in a data protection-related discipline, at least IAPP certification, preferably a second proof of knowledge, legal degree or certificate welcome
- Experience with work processes in the legal department of a medium-to-large industrial company, preferably in the communications, publishing or IT sector
- Familiarity with cross-functional collaboration in matrix organizations
- Fluent English, business-confident skills in another European language
- Experience of responding to change and growth
- Strong organizational and time management skills
- Strong influencing and collaboration skills at all levels
- Analytical mindset with attention to detail
- Team-oriented, proactive, and adaptable
Desirable
- Knowledge of data protection law in other jurisdictions, preferably including Indian law and US state law
- Knowledge of EU and UK Digital Law impacting data processing conditions
- Experience with joint risk evaluation and compliance of processing subject to GDPR/UK GDPR and AI Act
- Experience using DP documentation and reporting tools (e.g. Onetrust)
- German language skills
At Springer Nature, our mission is to be part of progress – and that begins with inclusion: of people, perspectives, and ideas. We believe that diverse perspectives drive progress, and we are committed to creating an environment where people and ideas can flourish. If you have any access needs related to disability, neurodivergence or a chronic condition, please contact us so we can make all necessary accommodation. Find out more about our DEI work here https://group.springernature.com/gp/group/taking-responsibility/diversity-equity-inclusion
For more information about career opportunities in Springer Nature please visit https://springernature.wd3.myworkdayjobs.com/SpringerNatureCareers/
Job Posting End Date:
25-10-2026