Booking NL

Senior Compliance Specialist- Data & AI Governance (For independent contractors)

Posted Sep 3, 2026
Project ID: 13641-1
Location
Amsterdam, NH
Hours/week
40 hrs/week
Timeline
6 months
Starts: Oct 1, 2026
Ends: Mar 31, 2027
Payrate range
60 - 120 €/hr

We are seeking to secure a risk expert to design and operationalize our privacy governance and violation management operating model. This specialist will establish the formal decision models and accountability structures to turn our technical privacy monitoring into a clear, day-to-day process for handling issues. They will help us define ownership, ensure violations are handled per SLA, and set up a system that feeds metrics to provide assurance over privacy risks.



Key Responsibilities:



  • Establish a Violation Decision Model: Partner with Privacy Legal, Risk, and Platform owners to design a clear, agreed-upon model to classify detected privacy violations (e.g., immediate remediation, accepted exceptions, or policy updates, etc.).


  • Define Operational Workflows: Document and map out mandatory next steps for each violation category, ensuring every issue has a defined tracking path, resolution target, SLA and designated owner.


  • Manage High-Risk Issues: Monitor and accelerate the resolution of High and Very High privacy risk violations, ensuring they are remediated or safely mitigated within the defined SLAs.


  • Assign Clear Roles and Accountability: Map out explicit ownership for key tasks, including policy governance, exception approvals, violation escalations, and regulatory reporting.


  • Design Actionable Risk Metrics: Develop key performance and risk indicators (KPIs/KRIs) to track open violations, exception aging, and remediation times, including clear escalation triggers for overdue items.


  • Integrate with Privacy Risk Frameworks: Work with the privacy risk team to ensure the defined privacy violation workflow aligns seamlessly with existing company wide (privacy) risk processes and can produce reliable evidence for audits and regulators.


  • Create a Closed-Loop Feedback Process: Design a mechanism to analyze recurring violation patterns so that teams can use these insights to update core policies, system rules, and engineering backlogs.


  • Facilitate Cross-Functional Alignment: Lead workshops with Legal, Risk, Security, and Engineering teams to build consensus on the new operating model and ensure smooth collaboration.


  • Develop Operational Playbooks: Draft practical, easy-to-follow standard operating procedures (SOPs) and response templates for teams handling day-to-day violation management.


  • Plan the Transition to BAU: Prepare training materials and handover documentation to ensure the new governance model is smoothly transitioned to permanent internal owners once the contract ends.


Requirements:

  • Ability to impact-assess privacy violations and define remediation paths

  • Practical understanding of GDPR and privacy risk frameworks

  • Proven track record of building governance, issue, or violation management processes from the ground up

  • Great communicator who can work independently to get different teams (legal, engineering, leadership) on the same page

  • Has experience interacting with senior stakeholders up to Directors, Senior Directors, and VPs.