Head of Compliance

Team.blue — Netherlands · Posted ~2 hours ago

Head Visa History ✓

Skills

Compliance leadership Regulatory compliance AI Act Digital Services Act Data Act DORA NIS2 GDPR Multi-country compliance Legal and regulatory risk management DSA

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A hands-on compliance leader is sought to establish and lead a central compliance function within a fast-growing technology environment operating across multiple European markets. The role covers major AI, digital services, data, financial resilience, cybersecurity, and privacy regulations while building practical governance processes across a fragmented international organization.

Highlights

Leadership opportunity to build and lead a central compliance function across a complex European technology environment, with strong exposure to major emerging digital, AI, cybersecurity, and data regulations.

Description

Company Overviewteam.blue is an ecosystem of 60+ successful brands working together across 22 European countries to provide its 3.3 million SMB customers with everything they need to succeed online by offering best-in-class expertise and services.team.blue's brands are a mix of traditional hosting businesses that offer services from domain names, email, shared hosting, e-commerce, and server hosting solutions and, as specialist SaaS providers, adjacent products such as compliance, marketing tools, and team collaboration products. This broad product offering makes it a one-stop partner for online businesses and entrepreneurs across Europe.Role:We are looking for a hands-on, tech-savvy Head of Compliance to build and lead team.blue’s central Compliance function within group legal. Regulation is expanding quickly (AI Act, DSA, Data Act, DORA, NIS2, GDPR) and we operate across a fragmented, multi-country footprint. meets a fragmented, multi-geography footprint. This role is to turn that regulatory load into something teams can act upon themselves, rather than something we chase reactively.Our operating philosophy is simple: enable, don’t gate — default to “how”, not “no”. Compliance is a growth lever, not a checkpoint. You will run a risk-based, pragmatic and scalable function: focus effort where likelihood × impact is highest, standardise and automate the routine, and reserve deep expertise for where it genuinely adds value. Good enough and fast beats perfect and late.Given the size and geographical diversity of the group, the ambition is not a separate compliance silo. The function is embedded in group legal and works through co-creation: we set the standard once at the centre, enable divisions to self-serve through shared tools, and co-create with divisional General Counsels and legal-on-the-ground, who own their product and commercial risk posture within that standard.Team & Leadership Scope:This is a people-leadership role. You will lead and develop a central compliance capability, with the following reporting into you:• Privacy Counsels — the group’s data-protection and GDPR specialists.• AI Counsels — the group’s AI Act and AI-governance specialists.• A general compliance risk-monitoring and assurance function — regulatory watch, continuous risk monitoring, the assurance loop and adoption tracking (AI-enabled).You steer this team to standardise once and scale everywhere, and you steer, rather than manage, local legal counsels to embed compliance in the business lines.You will also have access to the operational Legal Hub, headed by the legal ops lead, and act as a spoke to it: you deploy your standards, policies and playbooks as self-serve templates and automation through the Hub, and draw on its shared tooling, regulatory-watch and risk analytics.You set and steer the standard; the Hub is the delivery layer that scales it.Key Responsibilities:Compliance Advisory & Implementation• Act as a first-line (1LOD) advisory function embedded in group legal, working alongside legal and the business rather than at arm’s length — enabling delivery, not blocking it.• Drive the practical implementation of regulatory requirements into the business lines — translating obligations into operational change and self-serve readiness, not just written guidance.• Apply a risk-based approach to set priorities across the group’s brands and jurisdictions, as a joint call with the business, not a legal veto.Regulatory Scope — Data & Technology• Own the group compliance agenda on data- and technology-driven legislation, which forms the core of the remit: GDPR, the AI Act, the Data Act, DORA and NIS2.• Coordinate the group’s Digital Services Act (DSA) standard centrally — setting a single approach to avoid fragmented entity-level reporting — while the operational abuse-report handling is executed by the divisions (see Scope Boundaries).• Set the group standard, policies and playbooks on these topics, and deploy them as self-serve templates and automation through the Legal Hub.• Anticipate incoming EU digital regulation and assess its operational impact across the portfolio.Broader Compliance Topics• Own or coordinate the wider compliance agenda, including sanctions, AML, conflicts of interest, third-party risk management (TPRM), fraud, consumer protection and business integrity.• Safeguard independence of judgement on topics that require it — notably whistleblowing, conflicts of interest and TPRM — and provide independent oversight on escalation.Risk Monitoring & Assurance• Own the group’s compliance risk-monitoring and assurance loop — continuous monitoring, not point-in-time assurances — so our controls are demonstrable and our register stays current.• Run regulatory watch and translate change into prioritised, register-driven action.• Steer the function by clear KPIs (maturity and awareness, self-serve adoption, response time, residual risk).Co-Creation with Divisional General Counsels• Partner with divisional GCs as co-owners of compliance, not recipients of policy — they steer their own product and commercial risk posture within the group standard you set.• Foster a genuine compliance culture across the divisions, enabling local counsels and non-legal teams to self-serve and apply standards, escalating only true exceptions.• Act as a trusted advisor to senior leadership and divisional GCs on compliance risk and regulatory exposure.• Work closely with the Sustainability Director to advance team.blue’s digital-trust agenda — connecting data protection, AI governance and platform integrity to the group’s ESG and responsible-technology commitments, so trust is treated as both a compliance and a sustainability outcome.Scope Boundaries — What This Role Does Not OwnOur operating model deliberately places certain matters elsewhere. This role sets the standard and owns the compliance decision and monitoring; it does not own the execution or the domains below (confirmed at the July 2026 legal strategy offsite):• Product, commercial and licence-to-operate risk — owned by divisional legal on the ground, who apply the standard and escalate breaches.• Operational security execution (NIS2 / DORA) — executed by divisional CISOs, with the Group General Counsel accountable; Compliance sets the standard and monitors.• Technical build and remediation of data/technology obligations (e.g. Data Act) — executed by the relevant platform and build owners; Compliance owns the decision and the monitoring, not the build.• DSA operational abuse-report handling — executed by the divisional teams with hosting and domain-name capacity (Digital Foundation and Digital Infrastructure); Compliance sets and centrally coordinates the standard only.• Litigation and active claims — owned by the relevant divisional General Counsel.• M&A and corporate transactions — owned by the Corporate Transactions CoE; employment matters — owned by the Employment Counsel.• Statutory and corporate housekeeping — externalised to external providers / corporate secretarial, not compliance.• The Legal Hub is the automated self-serve execution layer; Compliance sets and steers the standard, it does not staff or run the Hub case-by-case.Skills & Qualifications:Education & Professional Background• Qualified lawyer.• Proven seniority at manager level, with the standing to promote compliance culture while operationally driving implementation forward — not only thinking, but doing.• Demonstrated experience in an internal compliance role, preferably in the non-financial (1LOD advisory) sector rather than a regulated financial-services 2LOD control function.• Not a transactional lawyer — this is an operational, implementation-led compliance leadership role.• Experience in an international or multi-jurisdictional environment is a strong advantage.Technical Skills• Knowledge of IT- and data-driven legislation (GDPR, AI Act, Data Act, DSA, DORA, NIS2).• Genuinely tech-savvy from an operational point of view — comfortable in a fast-moving digital environment (a hard requirement, not a nice-to-have).• Fluent with a risk-based, self-serve and automation-first way of working — build it once so it is reused, not redone.• Ability to prioritise and lead a broad, multi-topic compliance agenda across a decentralised group.Language Requirements• Fluent in English (group working language).• Additional European language skills are an advantage.Core Competencies• Enabler, not gatekeeper — you default to “how”, not “no”, and treat legal confidence as a growth lever.• Hands-on and operational — you both think and do; you move topics from policy to implementation.• Pragmatic and risk-based — you focus effort where the exposure is greatest and accept that good enough and fast beats perfect and late.• A co-creator — you build with divisional GCs and the business, not around them.• Good communicator, credible and convincing across legal, business and leadership audiences.• High personal integrity — integer, and trusted to hold an independent line where required.• Able to lead through influence, steering counsels you do not directly manage.What We Offer• A senior, high-impact role building and leading the group compliance function from within, with direct access to the Group General Counsel and group leadership.• Ownership of the EU digital-regulation agenda• A team to lead — privacy, AI and compliance risk-monitoring specialists — and the mandate to shape the function.• A collaborative, international environment where legal and compliance are seen as strategic partners.• Competitive compensation package, including participation in group incentive plans.• Remote or Hybrid working arrangements."Come as you are"Everyone is welcome here. Diversity & Inclusion are at our core. Far above any technical competence, we value respect, openness, and trusted collaboration. We do not tolerate intolerance.ESG"At team.blue, our commitment to caring for the environment and each other is at the heart of everything we do. Our latest impact report showcases our ongoing ESG efforts and ambitious sustainability goals. Interested in learning more about our dedication to making a positive impact? Check it out here.”