2026-09-01
Chief Compliance Officer AI SaaS, GDPR & EU AI Act Göteborg · MyFlow Learning AB
Annonsen kommer från Arbetsförmedlingens Platsbanken. Yrlo förmedlar den och rekryterar inte själv.
Din matchning
Med konto och CV står det här:
- hur nära annonsens yrke ligger din bakgrund
- vilka av dina kompetenser som återkommer i annonstexten
- en poäng av 100, och vad den bygger på
myflow gives solopreneurs and small teams an AI-powered business platform — CRM, marketing, sales, e-signing and automation, run either by the customer or by AI teammates working on their behalf. We launched in Sweden in 2024 and are now expanding internationally.
Shipping autonomous AI agents that handle customer data, send marketing, and find leads across multiple jurisdictions puts us in the middle of the fastest-moving area of tech regulation there is. We're hiring our first Chief Compliance Officer to own it.
About the role
You report to the CEO and you're building this function from nothing. There is no team beneath you on day one and no playbook to inherit — you will write the policies, run the assessments, sit in the customer calls, and decide what we can and cannot offer. If you want a large department and an established framework, this isn't it. If you want to define how an AI-native product company handles compliance while the rules are still being written, it is.
What you will do
Own our EU AI Act position: classify our AI systems, meet Article 50 transparency obligations, and manage our exposure downstream of the foundation models we build on.
Own our ISO 42001 practices ensuring we are a proven leader in demonstrating mature AI governance.
Own GDPR across the platform, with particular focus on our lead generation and outbound marketing features — lawful basis, notification duties, and the ePrivacy rules governing automated outreach.
Build our US privacy posture as we expand: HIPAA Business Associate obligations where healthcare practitioners use our platform, CAN-SPAM and TCPA for agent-driven outreach, and state privacy law compliance.
Take us through SOC 2, ISO 27001, ISO 27701 and stand behind them in customer security reviews.
Support our entry into US public-sector and Tribal markets — contracting with sovereign entities, sovereign immunity and limited waiver provisions, tribal business licensing, and where relevant federal procurement requirements.
Be the compliance voice in product decisions early, not the person who blocks a launch the week before it’s live.
We require
Senior compliance, privacy or regulatory experience at a SaaS or technology company, ideally one that has expanded across jurisdictions.
Deep working knowledge of GDPR in a product context — not policy administration, but decisions about what a feature is allowed to do.
Proven history with the EU AI Act and ISO 42001 guidelines, with direct experience in how it applies to agentic AI products.
Experience running or supporting a SOC 2, ISO 27001, ISO 27701 programme end to end.
Senior level experience in navigating Indigenous markets with a portfolio of successful implementation around sovereign immunity data laws, federal level tribal business licensing agreements, and cultural sensitivities.
HIPAA experience on the vendor or Business Associate side, including BAA.
Comfort operating alone, at pace, with incomplete information and unsettled law.
Fluent professional English.
CIPP/E, CIPP/US or CIPM certification.
Experience with US federal procurement, including FedRAMP.
Swedish language skills.
What we offer
Standard Swedish employment agreement. Hybrid arrangement. Negotiable salary.
Practical details
Location: Gothenburg, hybrid arrangement. Start: by agreement. We review applications 10 days after the listed date of the ad.
Questions: Oliver Hertzman Kraft Email: Oliver@myflow.io
Skickas till oliver@myflow.se