- setting up the privacy department
- performing risk analyses (including DPIAs) and drafting and implementing control measures
- developing and maintening a processing register
- drafting processing agreements
- developing, implementing and monitoring compliance with the privacy policy
- giving solicited and unsolicited privacy advice to the entire organization from management to employee level
- creating privacy awareness by means of trainingprogramms, campaigns and workshops
In the position of Senior Manager Legal & Compliance, Heleen was ultimately responsible for the Privacy department consisting of 3 FTEs. Also at the time of the implementation of the GDPR. Due to understaffing in the department, Heleen, as a cooperating foreman, made a substantial contribution to the successful implementation of the GDPR. She was also responsible for:
- providing solicited and unsolicited advice on complex privacy issues from the business perspective, for example with the implementation of a customer loyalty / CRM system
- developing and successfully implementing a Privacy-Champions
network
- creating privacy awareness through training programms, campaigns and workshops
- drafting processing agreements
- developing and updating the privacy policy
- maintaining a processing register
- performing DPIAs
As DPO, Heleen works independently. She is curious and likes to discuss why processes and methods are as they are. She likes to ask critical questions and she likes researching, however, not in an unpleasant way. She knows how to adapt to her conversation partner and works pragmatically and with integrity.