We are seeking a Privacy Compliance Professional (or junior-level contract attorney) to support privacy governance activities, primarily focused on GDPR and UK Data Protection Act compliance. This role supports Legal by drafting, documenting, and coordinating privacy compliance work under established guidance and escalation paths.
The role is hands-on and documentation-focused, supporting EMEA privacy operations, cross-border transfers, and assessment activities. Final legal decisions remain with internal Legal leadership.
Key Responsibilities
- Support privacy governance activities related to GDPR and UK Data Protection Act compliance, particularly for EMEA operations
- Draft and refresh privacy notices and disclosures (e.g., CCTV, biometrics, internal notices) using provided guidance
- Assist with preparation of training materials, FAQs, and internal guidance
- Support updates to cross-border data transfer documentation, including adequacy assessments and Transfer Impact Assessments (TIAs)
- Draft and document Data Protection Impact Assessments (DPIAs) in coordination with IT, HR, Operations, and Commercial teams
- Review technology agreements to identify privacy and data protection gaps and propose draft updates
- Support vendor privacy assessments, including tracking DPAs, subprocessors, and controller-processor alignment
- Assist with regulatory filings, registrations, and supporting documentation as required
- Escalate legal or risk questions to internal Legal leadership as appropriate
Qualifications
- JD, LLB, or equivalent legal qualification OR CIPP/E with 3+ years of hands-on privacy or data protection experience
- Strong drafting, documentation, and analytical skills
- Ability to synthesize incomplete or technical input into clear written materials
- Comfortable working from templates, examples, and defined processes
- Good judgment regarding when to proceed independently versus escalate issues
- Experience working with cross-functional and international teams
Preferred Skills
- CIPP/E or similar privacy certification
- Practical knowledge of GDPR, UK Data Protection Act, and cross-border transfer mechanisms
- Experience reviewing or drafting privacy and data protection clauses
- Familiarity with EMEA regulatory environments
- Exposure to AI governance, biometrics, surveillance, or workplace monitoring programs
This role supports privacy compliance execution and documentation. It does not serve as DPO, lead regulatory counsel, or final decision-maker.