Jobs › GDPR
GDPR Compliance Jobs
The GDPR is the EU's comprehensive data-protection law and the global benchmark for privacy.
The General Data Protection Regulation has been the world's reference privacy law since it took effect on May 25, 2018. It governs any organization that processes the personal data of people in the EU, wherever that organization is based, and it rests on principles of lawful basis, purpose limitation, data minimization, and accountability. It gives individuals enforceable rights, access, rectification, erasure, portability, and objection, and it requires breach notification within 72 hours, data protection by design, and, for many organizations, a Data Protection Officer.
The GDPR set the template that California, Brazil, India, and dozens of other jurisdictions have followed, so the skills it demands travel. As AI raises the stakes on every data decision, GDPR fluency has moved from a legal nicety to a core requirement for privacy, governance, and AI roles alike. Fines reach 20 million euros or 4 percent of global annual turnover.
GDPR: Frequently Asked Questions
Who must comply with the GDPR?
Any organization that processes the personal data of individuals in the EU, including organizations established outside the EU that offer goods or services to, or monitor, people in the EU.
What rights does the GDPR give individuals?
Rights of access, rectification, erasure (the right to be forgotten), restriction, data portability, and objection, among others.
What are the maximum GDPR fines?
Up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher, for the most serious violations.
Open GDPR GRC jobs (47)
Cybersecurity Requirements and Data Protection Lead
Senior Data Governance - AI Driven Metadata Management
Senior Data Governance - CIB SME (Markets, FSS, Banking)
Supvy IT Spec (SEC) 'Cyber Ops Branch Chief', GS-2210-15 FPL GS-15 (DH)
Governance, Risk, and Compliance Manager - FedRAMP
Governance, Risk, and Compliance Manager - Privacy
Information Security Controls Manager - Cloud & AI Governance
Security Compliance, GRC Engineer
Senior Privacy Counsel - APAC
Manager, Legal Programs (Privacy & AI)
Head of Data Governance - Product Line
Senior Third-Party Risk Specialist
Compliance Director
Compliance Officer - Associate
Business Risk Manager – Growth
Privacy Legal Counsel
Compliance Manager (Data Protection Officer, Regulatory Compliance & Privacy)
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Data Protection Specialist, Germany
Senior Compliance Officer, Japan
Global Risk and Compliance Manager
Staff+ Software Engineer, Privacy
Privacy Operations Program Manager
Sr. Counsel, Privacy Compliance
DTE Audit & Compliance Manager (Sr. Principal Analyst)
Senior Manager, Information Compliance, AI Governance & Privacy
Senior Privacy Counsel
Product & Privacy Counsel
Field CISO
Director of IT Governance
Governance, Risk & Compliance Analyst
Senior AI Governance Counsel
Security, Risk and Compliance Consultant
Director of IT Governance
GRC Lead, Governance, Risk & Compliance (Cybersecurity)
Staff Software Engineer - Data Governance
Security Compliance Analyst, Privacy
IT Enterprise Risk Analyst
Data and AI Governance Lead, Computing Services
EMEA Assurance Lead
GDPR jobs: what the market looks like right now
A snapshot built from the 47 GDPR roles currently on this page.
What these roles pay
Of the 47 open GDPR roles on this page, 14 publish a salary range. Across those:
- Median advertised midpoint: $220k
- Middle half of the market: $165k to $233k
- Full advertised range: $116k to $405k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 4 remote, 2 hybrid, 41 on-site or unstated.
- Seniority mix: senior (22), mid (19), executive (3), director (3)
- Employers hiring more than one: SEI (9), Mistral AI (3), Capco (2), Decagon (2), N26 (2), Adyen (2)
Skills these postings ask for
- data mapping and records of processing
- DSAR and rights request handling
- privacy impact assessments (DPIA/PIA)
- GDPR and CCPA/CPRA application
- vendor and transfer assessments
How to get a privacy job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in GDPR postings to be worth knowing: CIPP/US, CIPP/E, CIPM, CIPT, AIGP. The certification academy covers what each one actually tests and who it is for.
Hiring for GDPR?
We have 47 open GDPR roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts