- Company Name
- Tourism Marketing Agency
- Job Title
- Privacy Counsel / Manager
- Job Description
-
**Job Title:** Privacy Counsel / Manager
**Role Summary**
Assume a senior legal/compliance function providing end‑to‑end privacy & data protection support across product, ops, revenue and security functions in a fast‑paced, technology‑focused business. Report directly to the Senior Legal Counsel and DPO, collaborating with UK/EU teams and EU‑based colleagues to ensure statutory and regulatory compliance, including data transfers, AI governance and market‑specific obligations.
**Expectations**
- Deliver independent, risk‑based privacy advice in a short lead‑time environment.
- Build and scale privacy processes, supporting data‑subject rights, law‑enforcement requests and data‑transfer mechanisms.
- Serve as a trusted advisor to product and business units, enabling responsible data product commercialization.
- Maintain up‑to‑date privacy policy, procedure, ROPA and retention regimes.
- Work cross‑functionally to embed privacy considerations into product, marketing and operational initiatives.
**Key Responsibilities**
- Provide day‑to‑day privacy compliance and risk management support to multiple internal stakeholders (product, customer service, revenue, people, data and security).
- Conduct Data Protection Impact Assessments (DPIAs) on novel data uses and support product teams through the commercialization lifecycle.
- Advise on and negotiate data protection agreements, standard contractual clauses, and international data‑transfer arrangements.
- Enhance and operationalize processes for data‑subject rights and law‑enforcement requests compliance.
- Maintain the record of processing activities, retention schedules, and internal privacy policies.
- Partner with EU‑based team on EU data‑protection law compliance, direct‑marketing obligations, and market‑specific compliance activities.
- Coordinate AI governance tasks, developing risk assessments, model‑risk oversight and compliance frameworks.
**Required Skills**
- 2–4 years of post‑qualification experience (PQE) in data‑privacy law (private practice, in‑house or secondment).
- Alternatively, a privacy practitioner with IAPP qualifications and equivalent business‑industry experience (technology or fintech).
- Strong knowledge of UK GDPR, EU data‑protection law, and cross‑border transfer mechanisms.
- Practical, risk‑based approach to applying privacy law with commercial sensitivity.
- Experience advising on AI regulation, or willingness to learn.
- Ability to translate complex legal concepts into clear, actionable guidance.
- Excellent stakeholder engagement, communication and negotiation skills.
- Self‑starter with analytical rigor, creativity, and a collaborative mindset.
**Required Education & Certifications**
- Qualified lawyer (UK/counsel) with 2–4 years PQE in privacy/data protection.
- OR privacy professional holding an IAPP credential (e.g., CIPM, CSSLP, or comparable).
- Bachelor’s degree in law, computer science, business, or related discipline (for privacy professionals).
- Ongoing professional development in data protection, privacy law, and AI governance preferred.