Group Data Protection Officer H/F - CMA CGM
- Marseille - 13
- CDI
- CMA CGM
Les missions du poste
Led by Rodolphe Saadé, the CMA CGM Group, a global leader in shipping and logistics, serves more than 420 ports around the world on five continents. With its subsidiary CEVA Logistics, a world leader in logistics, and its air freight division CMA CGM AIR CARGO, the CMA CGM Group is continually innovating to offer its customers a complete and increasingly efficient range of new shipping, land, air and logistics solutions.
Committed to the energy transition in shipping, and a pioneer in the use of alternative fuels, the CMA CGM Group has set a target to become Net Zero Carbon by 2050.
Through the CMA CGM Foundation, the Group acts in humanitarian crises that require an emergency response by mobilizing the Group's shipping and logistics expertise to bring humanitarian supplies around the world.
Present in 160 countries through its network of more than 400 offices and 750 warehouses, the Group employs more than 155,000 people worldwide, including 4,000 in Marseilles where its head office is located.
YOUR ROLE
As Group Data Protection Officer, you will strengthen the Group's privacy and digital compliance function by playing a dual role :
- Data Protection Officer for CMA CGM SA / Head Office and
- Group Privacy Leader, driving major cross-functional and international privacy initiatives across the Group.
You will collaborate closely with the Group Data Protection Officer, AI Governance and AI Compliance teams, Privacy Compliance Officers, Compliance Project Managers, Digitalisation, Global Business Services, Internal Control, Legal, IT, Cybersecurity, HR, Procurement, and operational stakeholders.
WHAT ARE YOU GOING TO DO?
DPO Responsibilities for CMA CGM SA
- Provide independent, practical, and risk-based advice on personal data protection matters.
- Support privacy-by-design reviews and compliance assessments for Group projects (IT, AI, HR, operational initiatives).
- Advise on Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments (LIAs), Transfer Impact Assessments (TIAs), and other privacy-risk assessments.
- Monitor compliance with applicable data protection requirements, internal policies, and Group standards.
- Manage data subject rights requests, complaints, personal data breaches, and related documentation.
- Act as an escalation point for complex privacy projects, significant incidents, and sensitive compliance matters.
- Support relations with supervisory authorities and contribute to internal control activities, audits, and compliance reporting.
- Provide expert privacy input to the Group's sustainability reporting (including CSRD-related statements) and external sustainability assessments.
- Contribute to privacy awareness and training initiatives for employees and management.
Group Privacy Leadership
- Lead strategic, cross-functional, and international Group privacy initiatives as a key stakeholder.
- Define privacy direction, compliance outcomes, and governance expectations for major initiatives.
- Mobilize executive sponsors, business stakeholders, and decision-makers to ensure visibility, support, and resources.
- Contribute to budget identification and resource allocation for major Group privacy initiatives.
- Ensure projects have appropriate delivery arrangements (Project Managers, external consultants, law firms, or specialist providers).
- Provide senior privacy expertise and strategic direction throughout project delivery (without day-to-day project management).
- Escalate material obstacles, unresolved strategic choices, and resource gaps to relevant governance bodies.
- Support the deployment of Group privacy policies, guidelines, templates, and standards through the Group privacy compliance network.
Exceptional Provider Management
- Prepare and manage targeted Requests for Proposals (RFPs), including scope, deliverables, timetable, assessment criteria, confidentiality, and budget.
- Select, coordinate, and supervise external privacy advisers, law firms, consulting firms, and specialist providers.
- Use external support for complex DPIAs, major audits, biometric data assessments, international transfer programs, Binding Corporate Rules (BCR) initiatives, and other strategic compliance matters.
- Review and challenge external deliverables to ensure legal robustness, consistency with Group standards, and operational usability.
WHO ARE WE LOOKING FOR?
- Minimum 10 years of professional experience in personal data protection, privacy law, digital law, or privacy compliance.
- Strong practical expertise in GDPR and international privacy matters, including: Privacy governance, Data subject rights, Incident management, Vendor relationships, International data transfers.
- Proven ability to operate in a complex, international, and multicultural environment.
- Ability to translate complex legal requirements into clear, scalable policies, templates, practical guidance, and training.
- High level of integrity, independence, sound judgment, and discretion.
- Excellent communication and influencing skills with senior leaders, operational teams, and technical stakeholders.
- Strong stakeholder management, negotiation, and prioritization skills.
- Pragmatic, solution-oriented, with the ability to balance legal requirements, business needs, and operational realities.
- Comfortable working in a dynamic environment shaped by international growth, digital transformation, and AI innovation.
- Able to work independently while building trusted partnerships across the Group.
- Fluent English is essential.
Come along on CMA CGM's adventure !