- Location
- GB
- Workplace
- Remote
- Type
- Full-time
- Department
- Legal
- Seniority
- Senior
- Source
- Eightfold
Description
Strategic Privacy Advisor Serve as a trusted advisor to legal, business, product, security, and technical teams on privacy and data protection issues across EMEA and globally. Interpret and apply GDPR, UK GDPR, U.S. privacy laws, international data transfer requirements, and other global privacy frameworks. Provide strategic, practical guidance on lawful bases, transparency, data minimization, retention, data subject rights, consent, data sharing, and privacy risk management. Support privacy aspects of regulatory inquiries, audits, assessments, mergers and acquisitions, integrations, new market entries, restructurings, and other strategic initiatives. Serve as an escalation point for data protection provisions in customer, vendor, partner, outsourcing, and other commercial agreements. Advise on third-party privacy risks, procurement reviews, international processing arrangements, and cross-border data transfer strategies. Support the development and enhancement of privacy governance frameworks, policies, processes, training, and operational controls. Partner with security, IT, legal, and business teams on privacy incidents and breach response, including risk assessment, notification obligations, remediation, and process improvements. Monitor global privacy, AI, and data protection developments and translate legal and regulatory requirements into practical guidance for business teams. Technology and AI Fluency Lead privacy reviews for new products, features, technologies, data uses, and business initiatives. Partner with product, engineering, security, architecture, and AI governance teams to embed privacy-by-design and privacy-by-default principles into products, systems, and processes. Advise on privacy considerations related to AI, machine learning, analytics, automated decision-making, model training, testing, deployment, monitoring, and emerging technologies. Law degree and qualification to practice law in at least one jurisdiction. 7-10 years of relevant experience in privacy, data protection, technology, or related legal roles, either in-house or at a law firm. Deep knowledge of GDPR, UK GDPR, U.S. privacy laws, and global privacy frameworks. Experience conducting or advising on DPIAs, TIAs, LIAs, privacy reviews, and privacy risk assessments. Demonstrated ability to advise on complex SaaS, cloud, data analytics, AI, or other technology-related matters. Strong business judgment and ability to provide pragmatic, risk-calibrated legal advice. Excellent written and verbal communication skills in English. Proven ability to collaborate effectively with legal, technical, product, security, and business stakeholders. Experience at a multinational technology, SaaS, or cloud-based company, or advising similar clients at a leading law firm. Experience with privacy management platforms and governance tools such as OneTrust, TrustArc, or ServiceNow. Understanding of security and compliance frameworks such as ISO 27001, ISO 42001, SOC 2, NIST, or related standards. Professional privacy or AI certifications such as CIPP/E, CIPM, FIP, AIGP, or equivalent. Familiarity with AI governance frameworks and emerging AI regulations, including the EU AI Act. Experience with legal process automation and the use of technology to improve legal and privacy program effectiveness.