Job Description, Responsibilities & Requirements
About the Position
Senior Privacy Counsel & DPO Germany (Berlin) - lead DPIAs, DPO duties, and privacy automation across Europe; shape a scalable, compliant privacy program in a lean, collaborative team.
We usually respond within a week
About Shine
Shine is the financial copilot for entrepreneurs and small business owners.
Founded by serial entrepreneurs Rico Andersen and Martin Hegelund, Shine is a leading European fintech unicorn on a mission to restore the joy of running a business, by ending wasted time on financial admin. Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing, meaning business owners can focus their energy on growing a healthy business, not held back by manual admin.
Part of something bigger
Today we're part of Cegid, a European leader in cloud software for finance and accounting. Together we're building Europe's leading financial copilot for small businesses and their accountants.
Shine already supports more than 400,000 small businesses. As part of Cegid, we now reach over one million small businesses and 15,000 accountants across Europe.
We're a multicultural team working from France, Germany, Denmark and the Netherlands, contributing to a wider European network that spans Spain, Portugal and Belgium.
Your hiring experience matters
Just as we respect our customers' time, we respect yours. Your experience with Shine and Cegid should feel simple, transparent and genuinely supportive.
If this sounds like somewhere you want to grow, we'd love to hear from you.
Responsibilities
Day-to-Day Privacy Operations & Statutory DPO
- Act as the officially designated DPO for our German subsidiaries before the relevant supervisory authorities, managing regulatory interactions and inquiries.
- Take full ownership of daily privacy operations: lead Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments (LIAs), and manage internal privacy workflows and requests.
- Draft, review, and negotiate Data Processing Agreements (DPAs) and privacy clauses with clients, vendors, and strategic partners.
- Own and continuously optimise the German Records of Processing Activities (ROPAs), ensuring accuracy, scalability, and audit readiness.
- Investigate and manage data breaches, security incidents, and complex Data Subject Requests (DSRs).
- Identify opportunities to automate privacy processes and implement scalable tools, ensuring efficiency and consistency in a lean team environment.
Cross-functional Business Partnering (Privacy by Design & AI Enablement)
- Partner closely with Product and Engineering to embed Privacy by Design and by Default, particularly within AI-driven products and features.
- Act as a key advisor on AI-related privacy risks and opportunities, ensuring compliant and responsible use of data in AI systems.
- Provide pragmatic, business-oriented legal guidance to Marketing and Sales (e.g., cookie compliance, outreach regulations, consent frameworks).
- Collaborate on the adoption of AI and automation tools within privacy operations, enabling smarter workflows and faster decision-making.
Group Privacy Construction, Automation & Scaling
- Work closely with the Lead Privacy to build and scale a transversal Group Privacy program across multiple regions.
- Drive the standardisation and automation of privacy processes, templates, and policies, reducing manual effort and increasing consistency.
- Take a hands-on role in implementing scalable frameworks, including AI Governance policies aligned with the EU AI Act.
- Act as a builder, designing and embedding tools, systems, and processes that allow a small team to operate with high impact.
M&A and Organisational Transformation
- Lead operational privacy workstreams during post-merger integrations and organisational scaling initiatives.
- Conduct privacy due diligence and assess existing frameworks across acquired entities.
- Execute the migration and integration of privacy infrastructures, ensuring alignment with Group standards.
- Identify opportunities to streamline and automate legacy processes, accelerating integration and reducing operational complexity.
Requirements
Experience
- Minimum of 4 years of hands-on experience in a privacy role, preferably within a fast-paced B2B tech company, Banking, SaaS environment, or a top-tier law firm. Experience working with automation tools, AI-driven solutions, or building scalable processes is a strong advantage.
Operational Grit
- You are an individual contributor who enjoys the day-to-day operational work (drafting DPAs, updating ROPAs, answering product questions) just as much as high-level strategy, and you proactively identify opportunities to streamline and automate workflows in a lean team environment.
M&A/Integration Expertise:
- Proven track record of working through complex integration phases, major organisational restructurings, or M&A activities in a pan-European context, with the ability to simplify, standardise, and scale processes.
Legal Background:
- Strong, practical knowledge of German (BDSG) and European (GDPR) data protection laws. A legal degree (First/Second State Examination or equivalent) is highly preferred.
Business Acumen
- Ability to translate complex legal requirements into actionable, business-friendly solutions. Experience with AI regulations, AI governance, and SaaS products, as well as an interest in leveraging AI to enhance privacy operations, is a significant plus.
Languages
- Full professional proficiency in English and German is required.
We Offer
- Competitive salary
- Opportunity to work in a leading European fintech unicorn
- Be part of a multicultural team working across Europe
- Professional growth and development opportunities
Equal Opportunity Employer
We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, colour, racial or ethnic origin, religion, disability, etc. as per applicable law.
Our Recruitment Process
- Initial call (30 min) with a Recruiting Partner
- Interview with hiring manager (45-60 min)
- Case study interview + personality and logic assessment feedback
- A 30' introduction with the Chief Banking & Compliance Officer, followed by a soft skills conversation to explore how we can best support your growth at Shine.
Locations
- Berlin, DE
- Job located in Berlin, with the possibility of two remote working days per week.
Already working at Shine?
Let’s recruit together and find your next colleague.