Senior Lawyer
Department:
Job Summary
At EveryPay we are on a mission to build the digital financial infrastructure that underpins e-commerce in Greece empowering marketplaces and merchants to grow.
We are a team of enthusiastic people driven by our values to Empower Customers work as a Team Together Manage Risk and Get Stuff Done.
We are proud to have built the payments layer connecting most Greek marketplaces and merchants with world-class schemes like Visa and Mastercard. We service most Greek marketplaces including Greeces largest and most successful marketplace Skroutz. Our systems connect to thousands of banks in Greece and abroad. Our technology processes tens of thousands of transactions every day representing billions of euros worth of e-commerce. If you have bought something online in Greece chances are you have already used our payments product.
EveryPay is fully owned by the Skroutz Group of companies and is both a tech company and a regulated financial services institution. Therefore you will be exposed to the world of the tech payments sector as well as the world of financial services.
We are growing our Legal team and we are looking for a talented Senior Lawyer with Data Protection Officer (DPO) Experience.
Role Summary: We are seeking an experienced and results-driven Senior Lawyer and DPO.
Responsibilities:
1. Legal & Regulatory Advisory:
o Provide pragmatic legal advice across EveryPays business with particular focus on payments technology e-commerce data protection cybersecurity and AI.
o Advise internal stakeholders on legal and regulatory risks associated with new products services partnerships technology initiatives and the adoption or development of AI-enabled solutions.
o Provide legal guidance on the EU payments regulatory framework including PSD2 and the evolving PSD3/PSR framework as well as applicable regulatory technical standards.
o Advise on the legal and regulatory implications of the development procurement and use of AI systems including under the EU AI Act and related regulatory guidance.
o Monitor relevant legal and regulatory developments and assess their potential impact on EveryPays products operations policies and contractual arrangements.
o Work closely with Compliance Risk Product and Technology teams to ensure relevant legal requirements are appropriately reflected in business processes and products.
2. Privacy and Data Protection:
In your capacity as EveryPays Data Protection Officer you will:
o Independently advise the company and its employees on their obligations under the GDPR and other applicable privacy and data protection laws.
o Monitor compliance with applicable data protection requirements and EveryPays internal privacy framework.
o Provide advice on Data Protection Impact Assessments (DPIAs) privacy-by-design considerations and other privacy risk assessments.
o Advise on and oversee the appropriate handling of data subject requests and personal data breaches from a data protection perspective.
o Promote privacy awareness across the organisation and support relevant training initiatives.
o Cooperate with and act as a point of contact for the Hellenic Data Protection Authority and other competent supervisory authorities where applicable.
o Report on material data protection risks and matters in accordance with the DPOs independent role within the organisation.
3. Commercial and Technology Contracts:
o Draft review and negotiate various types of contracts including software licenses service agreements data processing agreements technology transfer agreements and payments-related agreements.
o Ensure that contracts align with legal and regulatory requirements and protect the interests of the organization.
4. Policy and Procedure Development:
o Develop and implement internal policies and procedures related to technology intellectual property data protection and regulated payments framework compliance.
5. Stakeholder Collaboration:
o Collaborate with cross-functional teams including technology product and compliance teams to ensure legal considerations are integrated into business decisions and initiatives.
o Translate complex legal and regulatory requirements into clear practical guidance for non-legal stakeholders.
o Support informed decision-making by identifying legal risks explaining available options and recommending proportionate solutions.
Qualifications:
Law degree and admission to practice in Greece or another relevant EU jurisdiction.
Substantial experience (8-12 years) practicing law in the financial services or FinTech sector with a focus on areas such as intellectual property technology transactions data privacy cybersecurity and regulated payments framework compliance.
In-depth knowledge of EU and Greek financial regulations PSD2 GDPR and other relevant data protection laws.
Proven experience as a Data Protection Officer (DPO) or in a similar role.
Excellent communication and interpersonal skills with the ability to influence and collaborate effectively.
Demonstrated experience in leading cross-functional teams and managing stakeholders at various levels.
Proficiency in Greek and English languages.
Personal Attributes:
Strong analytical problem-solving and decision-making skills.
Excellent negotiation communication and interpersonal skills.
Ability to work independently and collaboratively in a dynamic environment.
Leadership skills and ability to mentor junior legal professionals.
If you are a strategic thinker with a passion for driving organizational success we invite you to apply for this challenging and rewarding opportunity.
Why Join EveryPay
- Shape the core payments infrastructure of Greece
- Own a high-impact role directly tied to company growth and revenue
- Work at the intersection of technology payments and financial services
- Be part of a fast-growing ambitious team within the Skroutz ecosystem
Whats it like to work at EveryPay
- Competitive full-time salary
- Private Family Medical Plan
- Monthly meal allowance
- Learning and development programs and access to relevant resources
- A flexible hybrid model of work
- Free Skroutz Plus subscription
- Free wellness subscription
- Birthday leave
- Being part of an environment that gives employees large goals autonomy and mentoring creating incredible opportunities both for you and the company!
Disclaimer:
EveryPay collects and processes personal data in accordance with the EU General Data Protection Regulation (GDPR). We are bound to use the information provided within your job application for recruitment purposes only and not to share these with any unauthorized third parties. Please read our Recruitment Privacy Policy below.
Recruitment Privacy PolicyThe Company EVERYPAY PAYMENT SERVICES SINGLE MEMBER SOCIETE ANONYME (hereinafter referred to as EVERYPAY) collects CVs and personal data in order to evaluate and select suitable candidates for potential employment.
In accordance with Regulation (EU) 2016/679 on the protection of personal data EVERYPAY provides you with the following information regarding the collection and processing of your personal data.
- Data Collection
The personal data we collect is voluntarily submitted to EVERYPAY by you and includes the information contained in your CV and any accompanying documents. This data may include: full name contact phone number e-mail address educational and professional background etc.
- Purpose
The data is processed solely for the purpose of evaluating your qualifications for potential employment within EVERYPAY.
- Legal Basis
The legal basis for processing your personal data is your consent which is provided upon submission of your CV.
- Data Recipients and Transfers
Your personal data will only be accessed by authorized personnel of EVERYPAY involved in the recruitment process. It will not be transferred to any third party or to any country outside the European Economic Area (EEA).
- Data Retention
In case you do not enter into an employment relationship with EVERYPAY your personal data will be deleted permanently from our records unless you have provided your consent to retain your CV for future that case your data will be securely stored for up to two (2) years from the date of our last contact. EVERYPAY ensures that only authorized personnel have access to this data and that appropriate technical and organizational measures are in place to safeguard confidentiality and integrity.
- Your Rights
You have the right to:
- Withdraw your consent at any time (without affecting the lawfulness of processing carried out before withdrawal)
- Request access to your personal data
- Request rectification or erasure of your data
- Restrict or object to the processing of your data
- Request data portability
- Lodge a complaint with the Hellenic Data Protection Authority ()
To exercise these rights you can contact us here: or at the address: Averof 34A 14232 Nea Ionia Athens for the attention of: Data Protection Officer.
CONSENT FOR THE PROCESSING OF PERSONAL DATA By submitting your CV you explicitly consent to the collection and processing of your personal data as described above. You may revoke this consent at any time by contacting us at:
Required Experience:
Senior IC