Sr. Manager, Regional Privacy Lead - EMEA
Department: Legal
Employment Type: Full Time
Location: EMEA-Spain
Reporting To: Nate Hwang
Description
This position is ideal for senior privacy professionals to join the Privacy Office as the Sr. Manager, Regional Privacy Lead - EMEA. The main rule is to operationalize and scale the Privacy Program in EMEA, ensuring compliance with applicable privacy and data protection laws, including GDPR, UK GDPR, ePrivacy requirements, AI-related regulations, and emerging regional privacy legislation. You will partner with the Legal Regulatory and Quality department and business functions. This role is a strategic, influential role and you will leverage AI and digital automation to deliver process simplification and measurable impact to grow the business the right way.
This position may be based in Wroclaw, Poland or Madrid, Spain. The position will report to the Global Compliance and Privacy Officer, with a functional (dotted-line) reporting relationship to the Director, Global Privacy, Data Governance and AI.
Key Responsibilities
• Lead Regional Privacy Program: Serve as the lead privacy advisor and primary point of contact for all EMEA privacy matters. Translate global privacy strategy into region-specific implementation plans and operational priorities. Partner with business leaders to identify and proactively address privacy risks while enabling business growth and innovation, and build strong relationships with regional leadership teams and provide practical, risk-based guidance on privacy requirements.
• GDPR and Regulatory Compliance: Lead the implementation and ongoing maintenance of compliance with GDPR, UK GDPR, ePrivacy requirements, and other applicable EMEA privacy laws. Monitor evolving regulatory developments, enforcement trends, and guidance from supervisory authorities, and advise stakeholders on lawful bases for processing, consent requirements, transparency obligations, retention practices, and individual rights. Support audits, regulatory inquiries, inspections, and privacy-related investigations/inquiries.
• Policies, Procedures and Controls: Adapt and implement global compliance policies to reflect EMEA’s legal requirements and business operations. Draft supplemental regional SOPs or guidance where needed to address local regulatory needs.
• Privacy-by-Design and Risk Assessments: Lead and oversee privacy risk assessments, DPIAs, privacy reviews, AI assessments, transfer impact assessments and enterprise privacy reviews for new initiatives, technologies, products, systems, and AI-enabled use cases. Partner with business, security, legal, and technical teams to identify risks and implement appropriate mitigation measures, and champion privacy-by-design and privacy-by-default principles across the organization
• Data Governance and Accountability: Lead the regional oversight of Records of Processing Activities (RoPA), accountability documentation, and privacy governance reporting. Advise on cross-border data transfer mechanisms, including SCCs, BCRs, UK transfer requirements, and other international transfer frameworks. Partner with Global Privacy, Security, and Data Governance teams to strengthen accountability and oversight processes.
• Vendor and Third-Party Privacy Risk Management: Lead or oversee privacy assessments of third-party vendors, service providers, cloud solutions, and strategic business partners,, and assess third-party privacy risks and partner with Procurement, InfoSec, and Legal teams to implement appropriate controls. Provide guidance on data protection provisions in commercial agreements and data processing agreements.
• Customer and Commercial Privacy Support: Act as the primary privacy advisor for customer-related privacy matters across EMEA. Support sales, commercial, and legal team in responding to customer privacy inquiries, privacy due diligence requests, RFPs, tenders, audits, and contractual negotiations. Provide practical, risk-based guidance on privacy requirements to enable business growth while ensuring compliance with applicable privacy and data protection laws.
• Data Subject Rights and Incident Management: Oversee and support responses to data subject rights requests and regulatory inquiries involving EMEA data subjects. Lead privacy investigation and assessment of security incidents, determine notification obligations, and coordinate engagement with supervisory authorities where required, , in coordination with the Director, Global Privacy, Data Governance and AI. Partner with Cybersecurity, Legal, Compliance, and business stakeholders to assess notification obligations and regulatory reporting requirements.
• Training, Awareness, and Collaboration: Develop and deliver privacy training programs tailored to EMEA business functions. Promote a strong culture of privacy accountability and compliance, and create practical guidance materials and awareness initiatives to support business adoption of privacy requirements. Collaborate closely with regional counsel, compliance leaders, security professionals, and business stakeholders, and contribute to global privacy initiatives, program enhancements, operating model development, and strategic planning efforts
• AI Governance: Regionally develop and deploy of AI governance models and processes that are consistent with global AI governance strategies, but tailored for local application of AI laws, regulations and business strategies. Support AI governance training, oversight and monitoring, due diligence on models and use cases, and processes to ensure appropriate use of AI agents and tools.
• Ethical Leadership: Above all, model integrity and ethical leadership in all actions. Gain the trust of employees as an approachable, fair, and reliable leader on compliance matters. Champion our values and “do the right thing” philosophy, ensuring that business leaders in EMEA likewise embrace these principles and drive them into their teams’ daily activities.
Skills, Knowledge & Expertise
• Education: Bachelor’s degree required. Advanced degree strongly preferred (e.g. Juris Doctor, MBA or relevant master’s). Professional certifications (e.g. CIPP/E, CIPM, CIPT) are a plus, demonstrating commitment to the field.
• Experience: Minimum 10 years of professional experience, with at least 5 years in a dedicated privacy risk management role. Experience in the medical device, pharmaceutical, or healthcare industry is highly preferred, given the need for familiarity with industry-specific regulations and ethical standards. A track record of building or managing elements of a privacy program (e.g. policies, training, incident management, etc.) is required.
• Skills: Deep knowledge of GDPR, ePrivacy, EU AI Act, and emerging privacy and cybersecurity regulations across Europe; strong leadership and influencing skills, including stakeholder management, change management, executive communications, and regulatory engagement; experience with AI and digital automation; strong analytical and problem-solving abilities; excellent organizational skills; high sense of urgency; and experience managing external counsel.
• Communication: Strong written and verbal presentation and communication skills.
Teamwork: Ability to work both independently and collaboratively.