About this role
About the Role The In-House Data Privacy Lawyer will advise and support the Data Protection Officer and the Office of General Counsel on data protection (DP), cybersecurity and e-privacy compliance across the global firm. This 12-month fixed-term role focuses on UK/EU GDPR issues, international data transfers, third-party due diligence, DPIAs, HR privacy, training, and governance. What You'll Do
- Advise the Data Protection Officer and Office of General Counsel on data protection (DP), cybersecurity and e-privacy compliance across the global firm.
- Provide guidance on UK and EU GDPR issues, including complex international data transfers.
- Support DP and security due diligence assessments on third party vendors, including contract reviews, and contribute to data protection impact assessments.
- Provide pragmatic advice/legal guidance on HR-related DP issues; advise on training and awareness programs, and build tools/resources to support data governance and the firm's DP obligations.
- Identify and address privacy compliance gaps as part of the annual policy review cycle.
- Support the firm's employees involved in DP compliance across all business functions and practice groups with pragmatic and commercially aware advice/guidance.
- Work with the firm's global privacy legal team to incorporate compliance requirements in other jurisdictions, including CCPA, China PIPL, into the firm's compliance regime.
- Participate in regular discussions with the global privacy legal team and the global privacy steering committee.
- Provide advice/guidance in relation to e-privacy compliance in the marketing area.
- Support the firm's response to data subject requests and other DP-related compliance initiatives.
- There may also be opportunities to leverage your work as in-house privacy counsel to support the Data Protection, Cybersecurity & Digital Assets practice group, for example, by contributing to the development of precedents and knowledge management systems.
- Candidate should expect excellent quality of work in a culture that encourages leadership and involvement with the business.
- The successful candidate can be based in any UK locations, with options to work flexibly and/or remotely if required. What We're Looking For
- Substantial experience as a Data Protection & Privacy Counsel or in-house privacy counsel.
- Strong knowledge of UK and EU GDPR, and experience advising on complex international data transfers.
- Experience supporting DP and security due diligence assessments on third-party vendors, including contract reviews and DPIAs.
- Ability to provide pragmatic, commercially aware advice to multiple business functions; strong communication and training skills.
- Experience advising on HR-related DP issues and building training/awareness programs; ability to develop tools and resources for data governance.
- Experience collaborating with a global privacy legal team and steering committee.
- Willingness to work from UK locations with flexibility/remotely as needed.
- Knowledge of e-privacy issues in marketing and familiarity with cross-jurisdictional privacy regimes (e.g., CCPA, China PIPL). Nice to Have
- Experience with CCPA and China PIPL compliance.
- Experience contributing to precedents and knowledge management systems within a privacy practice group.