About this role
About the Role The in-house Data Privacy Lawyer will advise and support the Data Protection Officer and the Office of General Counsel on data protection, cybersecurity and e-privacy compliance across the global firm. This 12-month fixed-term contract role focuses on UK/EU GDPR, complex international data transfers, vendor due diligence, DPIAs, HR privacy issues, training, and governance to meet DP obligations globally. What You'll Do
- Advise on issues arising under the UK and EU General Data Protection Regulations (UK and EU GDPR), including complex international data transfers.
- Support DP and security due diligence assessments on third party vendors, including contract reviews, and contribute to data protection impact assessments.
- Provide pragmatic advice/legal guidance on HR-related DP issues; advise on training and awareness programs, and build tools and resources to support good data governance and the firm's DP obligations under the GDPR and other privacy regulations.
- Identify and address privacy compliance gaps as part of the annual policy review cycle; support the firm's employees involved in DP compliance across all business functions and practice groups with pragmatic and commercially aware guidance.
- Work with the firm's global privacy legal team to incorporate compliance requirements in other jurisdictions, including CCPA and China PIPL, into the firm's compliance regime.
- Participate in regular discussions with the global privacy legal team and the global privacy steering committee.
- Provide advice/guidance in relation to e-privacy compliance in the marketing area.
- Support the firm's response to data subject requests and other DP-related compliance initiatives.
- There may also be opportunities to leverage your work as in-house privacy counsel to support the Data Protection, Cybersecurity & Digital Assets practice group, e.g., by contributing to precedents and knowledge management systems. What We're Looking For
- Experience as Data Protection & Privacy Counsel or in-house privacy counsel.
- Strong knowledge of UK GDPR and EU GDPR; ability to advise on complex international data transfers.
- Experience with DP and security due diligence on third-party vendors, contract reviews, and data protection impact assessments.
- Ability to provide pragmatic advice and guidance; training and awareness programs; governance and data governance tools.
- Experience handling HR-related DP issues and advising on related policies.
- Willingness to collaborate with global privacy legal team and incorporate requirements across jurisdictions (CCPA, China PIPL).
- Ability to respond to data subject requests and support DP-related compliance initiatives.
- Leadership qualities and commercial mindset; able to work across functions and practice groups.
- Based in the UK with options for flexible/remote work. Nice to Have
- Experience contributing to precedents and knowledge management systems.
- Exposure to marketing/e-privacy considerations. Compensation & Benefits