J.D. degree or equivalent degree (such as a master in law) with strong academic performance
3+ years experience practicing law in a relevant field
Licensed to practice law in the US, UK, or a member state of the European Union
Deep subject matter expertise with at least one major data privacy framework such as the General Data Protection Regulation (GDPR), Gramm-Leach-Bliley Act (GLBA), or the California Privacy Rights Act (CPRA)
Experience interpreting regulatory guidance and drafting relevant privacy notices, policies, and procedures
Flexibility and willingness to work on a broad variety of legal matters
Excellent oral and written communication skills
Ability to work collaboratively with business partners across levels and show leadership
Responsibilities
Advise business teams (including marketing, sales, IT, and operations) regarding compliance with privacy, AI, and related laws and work collaboratively with Privacy Office peers to provide advice for projects with both regional and global scope
Advise on data protection terms in agreements including license, vendor, SaaS, technology, master services, confidentiality and other agreements
Advise and provide guidance on product strategy, considering data protection laws, customer and partner relationships, consumer rights, third-party rights and obligations, and business needs
Draft privacy policies, notices, related disclosures, disclaimers, FAQs and communications to support and enable business unit compliance
Perform privacy impact assessments, responsible AI assessments, and other governance tasks, and contribute to the maintenance of records of processing and the satisfaction of privacy-by-design and privacy-by-default requirements
Advise sales and marketing teams on compliance implications of various marketing initiatives including online advertising, behavioral advertising, affiliate marketing, mobile applications, social networking, email, SMS/text, and other consumer-facing communications
Work closely with Information Security, Data Governance, Risk, and Audit teams to identify and mitigate data protection compliance risks including issue-spotting and advising related to cybersecurity and data incidents