31 Jul
|
Helfie.AI
|
Melbourne
31 Jul
Helfie.AI
Melbourne
Helfie is on a mission to redefine global preventative healthcare. We’re pioneering an entirely new operating system for human health – empowering billons with instant, affordable health checks and AI-driven insights. Our vision is to build trust, drive organic engagement, and make preventative healthcare a reality for all 8 billion of us.
About the role:
Helfie develops AI-enabled medical device software (MDSW) and AI-driven health services some of which are subject to EU MDR 2017/745, the EU AI Act, the US FDA framework, HIPAA, GDPR, the Australian Privacy Act, and equivalent regimes across APAC. Personal health information sits at the centre of everything we build.
The Data Protection Officer (DPO) is Helfie's designated statutory privacy officer across the jurisdictions in which we operate, and the senior internal authority on the lawful, ethical and secure handling of personal and health data. The role safeguards patient and user data, ensures compliance with regional privacy and health-data regulations, and supports the Chief Strategy Officer, Head of Regulatory Affairs and Compliance (HRAC), and Notified Body engagement on all aspects of Helfie's data conformity. With the role comes the opportunity to contribute to product development, translating regulatory obligations into engineering controls.
The successful candidate will hold, or be appointed to, the following statutory or equivalent positions on behalf of the Helfie group:
- EU DPO under GDPR Article 37, with primary regulator engagement responsibility for supervisory authorities in the EU/EEA.
- UK DPO under the UK GDPR and the Data Protection Act 2018, with responsibility for engagement with the Information Commissioner's Office (ICO).
- Australian Privacy Officer under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, with responsibility for engagement with the Office of the Australian Information Commissioner (OAIC), including the Notifiable Data Breaches (NDB) scheme.
- HIPAA Privacy Officer for Helfie's US operations under 45 CFR §164.530, working alongside the nominated HIPAA Security Officer (45 CFR §164.308).
- Singapore DPO under the Personal Data Protection Act (PDPA), and equivalent roles in other APAC jurisdictions in which Helfie processes personal data (e.g. Japan APPI Personal Information Protection Manager).
Key responsibilities:
1. Statutory DPO and privacy officer duties
- Act as the designated contact point for supervisory authorities and data subjects across all regions listed above.
- Inform and advise Helfie and its processors on their obligations under applicable privacy and health-data laws (GDPR Art. 39(1)(a); equivalents).
- Monitor compliance with applicable data protection law, internal policies, awareness training and audits.
- Facilitate Data Protection Impact Assessments (DPIAs) under GDPR Art. 35 and cooperate with supervisory authorities on prior consultation where required (Art. 36).
- Maintain and keep current the Records of Processing Activities (ROPA) under GDPR Art. 30 and equivalent registers under other regimes.
2. Health data and medical device interface
- Ensure that all Helfie products handling personal health information (PHI) comply with GDPR, HIPAA, the Australian Privacy Act, and applicable local health-data laws wherever Helfie operates.
- Interface with the CEO, Head of Regulatory Affairs and Compliance (HRAC), the Chief Strategy Officer, and the Quality Manager on data-related risk controls.
- Support Notified Body engagement on data protection, cybersecurity and privacy-by-design aspects of the Technical Documentation.
- Ensure vigilance and post-market surveillance processes correctly handle the appropriate reporting paths
3. EU AI Act and AI governance
- Own the data-governance responsibilities that arise from the EU AI Act for AI systems and their interaction with GDPR.
- Advise on lawful basis, purpose limitation and data minimisation for training, validation and test datasets used in Helfie's AI/ML pipelines, including foundation-model and LLM-based components.
- Support the Chief Strategy Officer and Head of Regulatory Affairs and Compliance in maintaining a coherent regulatory position across MDR, AI Act and privacy regimes.
4. Governance framework and policy
- Own the group data protection and privacy policy framework, including data classification, retention, secure disposal, and data subject rights procedures.
- Author and maintain appropriate breach-response playbooks with defined regulator-notification timelines
- Advise on privacy-by-design and privacy-by-default as new products enter development.
5. International data transfers
- Manage cross-border data-transfer mechanisms including Standard Contractual Clauses, UK IDTA/Addendum, and applicable adequacy decisions.
- Conduct and maintain Transfer Impact Assessments (TIAs) consistent with Schrems II expectations.
- Assess and, where required, put in place Binding Corporate Rules or intra-group data transfer agreements as Helfie scales.
- Lead privacy-incident response: detection, containment, investigation, notification, and remediation.
- Coordinate with the Quality Manager and HRAC where privacy incidents interact with the device vigilance system.
- Own regulator-facing incident communications.
7. Education, culture and stakeholder engagement
- Design and deliver role-based privacy awareness training, including tailored modules for engineering, clinical and commercial teams.
- Advise product and engineering teams on integrating privacy-by-design into the software development lifecycle.
- Represent Helfie in external forums, industry bodies and regulator engagements on data protection matters.
Skills & experience:
- Minimum 8 years' experience in data protection, privacy or information governance, with at least 3 years in a senior privacy leadership role including DPO or equivalent statutory privacy-officer duties.
- Deep working knowledge of GDPR and UK GDPR, the Australian Privacy Act and APPs, and at least one major APAC privacy regime (Singapore PDPA, Japan APPI, or equivalent).
- Demonstrable experience of HIPAA and HITECH in a health-technology setting, including handling of PHI in cloud environments.
- Proven ability to run DPIAs, manage breach notifications across multiple jurisdictions, and maintain ROPAs.
- Experience of Transfer Impact Assessments and cross-border transfer mechanisms post-Schrems II.
- Working understanding of privacy-enhancing technologies (encryption, tokenisation, de-identification, differential privacy, federated learning) sufficient to challenge and validate technical designs.
- Ability to interpret data flows, technical architectures and AI/ML pipelines, and to translate regulatory obligations into concrete engineering and product controls.
- Excellent written and verbal communication, with the ability to brief executives, engage regulators, and challenge senior stakeholders constructively.
- At least one relevant certification: CIPP/E, CIPP/US, CIPM, CIPT, CISM, or ISO 27001 Lead Implementer.
It’s also desirable if you have:
- Prior experience as DPO or Privacy Officer in a health-technology, MedTech or SaMD company.
- Familiarity with EU MDR 2017/745, ISO 13485, ISO 14971 and IEC 81001-5-1, sufficient to interface effectively with the Regulatory Affairs and Quality functions.
- Working knowledge of the EU AI Act obligations for high-risk AI systems.
- Experience integrating privacy controls with AI/ML models, vector databases and large-language-model services in regulated environments.
- Experience of regulator inspections, Notified Bodies and FDA-facing audit-readiness activity.
- Familiarity with data catalogue and metadata management tooling (e.g. Collibra, Azure Purview) sufficient to assess control design without owning implementation.
- A senior seat at the table on one of the most consequential problems in global health.
- Direct engagement with regulators, Notified Bodies and clinical partners globally.
- Flexible working arrangements and a hybrid schedule.
- A team-oriented and innovative team environment.
Equal opportunity statement
Helfie.ai is an Equal Opportunity Employer. We will not discriminate on the basis of age, disability, sex, race, religion or belief, gender reassignment, marriage / civil partnership, pregnancy or sexual orientation. We encourage applications from a wide range of candidates and selection for roles will be based on individual merit alone.
#J-18808-Ljbffr
📌 Data Protection Officer (Melbourne)
🏢 Helfie.AI
📍 Melbourne