ABOUT MEDLOOP
With prevention as its core focus, Medloop is a tech-enabled provider, on a mission to transform the relationship between patients and doctors. By leveraging patient data and best preventive practices, Medloop offers a smart cloud-based doctor desktop and patient mobile application to enrich the relationship between doctors and patients. Medloop has raised over €8M from Kamet and the AXA group.
Role Overview
As our Data Protection Officer, you will be the guardian of patient privacy and the primary architect of our data governance framework. You will bridge the gap between complex healthcare regulations (like GDPR, or local equivalents) and agile product development. Your mission is to ensure that Privacy by Design is baked into every feature we ship.
Key Responsibilities
- Compliance Leadership: Act as the primary point of contact for supervisory authorities and data subjects. Ensure the venture remains compliant with GDPR and other relevant digital health regulations.
- Privacy by Design: Collaborate with Product and Engineering teams during the SDLC (Software Development Life Cycle) to ensure privacy controls are integrated into new health features, AI models, and data integrations.
- Risk Assessment: Lead and manage Data Protection Impact Assessments (DPIAs), Data Protection Agreements, IDTA, TRA for high-risk processing activities, particularly those involving sensitive clinical or genetic data.
- Policy Management: Create, maintain, and enforce internal data protection policies, including data retention schedules, subject access request (SAR) protocols, and incident response plans.
- Monitoring & Auditing: Conduct regular internal audits to ensure data processing activities align with the Record of Processing Activities (RoPA).
- Vendor Due Diligence: Evaluate the security and privacy posture of third-party partners (e.g., cloud providers, EHR integrations, and wearable device manufacturers).
- Training & Culture: Foster a privacy-first culture by providing engaging, role-specific training for clinical, technical, and marketing staff.
Required Qualifications
- Experience: 5+ years in privacy/data protection, with at least 2 years specifically within Digital Health, MedTech, or BioTech.
- Legal & Regulatory Mastery: Deep expertise in GDPR and data processing activities including processing of special category data, offshore
- Technical Literacy: Comfort discussing encryption, anonymization/pseudonymization techniques, and API security with engineers.
- Certifications: CIPP/E, CIPM, or CIPT (IAPP) are highly preferred.
- Communication: The ability to translate legalese into actionable requirements for developers and clear value propositions for stakeholders.
Preferred Attributes
- Experience scaling a startup through Series B or beyond.
- Familiarity with AI/ML ethics and the regulatory landscape for Software as a Medical Device (SaMD).
- Proactive problem-solver who views privacy as a competitive advantage rather than a roadblock.