| Title | Privacy Counsel |
|---|---|
| Department | Legal / Privacy & Data Protection |
| Reports to | [General Counsel / Chief Privacy Officer / Deputy General Counsel] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Privacy Counsel provides legal advice on privacy and data protection for [Company], advising the business on how personal data may be collected, used, shared, transferred, and protected in line with applicable law. This attorney role sits at the intersection of legal, privacy, security, and product.
The Privacy Counsel interprets laws such as the GDPR, CCPA and CPRA, HIPAA where applicable, and emerging AI regulation, drafts and negotiates data-related contract terms, supports privacy impact assessments, and advises on new products and technologies. As AI and automated decisions use personal data, this role advises on the privacy and data protection questions they raise.
This is a legal role for a licensed attorney with strong privacy expertise and the judgment to give practical advice in a fast-moving regulatory environment.
Key responsibilities
Privacy legal advice
- Advise the business on privacy and data protection law.
- Interpret privacy obligations for new products and initiatives.
- Provide guidance on data collection, use, sharing, and transfers.
- Advise on privacy questions raised by AI and automated decisions.
Regulatory interpretation
Translate a complex and changing legal landscape into practical guidance:
- Track and interpret GDPR, CCPA and CPRA, and other privacy laws.
- Advise on HIPAA and sector-specific requirements where applicable.
- Monitor emerging AI and data regulation such as the EU AI Act.
- Assess the legal impact of regulatory change on the business.
Contracts and transactions
- Draft and negotiate data processing and privacy terms.
- Review vendor, partner, and customer data agreements.
- Advise on cross-border data transfer mechanisms.
- Support privacy aspects of transactions and diligence.
Assessments and program support
Support privacy impact and data protection assessments, advise on data subject rights and breach obligations, and help maintain records of processing and privacy documentation.
AI and emerging technology
Advise on the privacy and data protection implications of AI and automated decision systems, including the use of personal data to train and run models, and support responsible AI review.
Incident and regulator response
Advise on privacy incidents and breach notification obligations, and support responses to regulators, data subject inquiries, and privacy-related disputes.
Required qualifications
- Juris Doctor (JD) and active admission to at least one U.S. state bar in good standing.
- 5 to 8+ years of legal experience, with substantial focus on privacy and data protection.
- Strong knowledge of GDPR, CCPA and CPRA, and other privacy laws.
- Experience drafting and negotiating data processing and privacy terms.
- Experience advising on privacy impact assessments and breach response.
- Excellent legal analysis, drafting, and communication skills.
Preferred certifications
One or more of: CIPP/US, CIPP/E, CIPM, CIPT, alongside active bar admission.
Technical knowledge
Privacy law and data protection, GDPR, CCPA and CPRA, HIPAA, cross-border data transfers, data processing agreements, privacy impact assessments, data subject rights, breach notification, and the privacy and data protection dimensions of AI and automated decisions.
Essential competencies
Legal judgment, regulatory interpretation, contract negotiation, clear counsel to business leaders, risk-based advice, and the ability to translate complex law into practical guidance.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in privacy law and data protection rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Privacy Counsel do?
A Privacy Counsel is an attorney who advises an organization on privacy and data protection law. They interpret privacy regulations, draft and negotiate data terms, support privacy assessments and breach response, and advise on the privacy questions raised by AI.
What qualifications and certifications does a Privacy Counsel need?
A Privacy Counsel needs a JD and active bar admission, plus 5 to 8 or more years of legal experience focused on privacy. Common certifications include CIPP/US, CIPP/E, and CIPM from the IAPP, alongside bar membership.
Who does a Privacy Counsel report to?
A Privacy Counsel typically reports to the General Counsel, a Chief Privacy Officer, or a Deputy General Counsel, and works closely with privacy, security, and product teams.
How does AI affect the Privacy Counsel role?
AI systems often use personal data to train and run models and can drive automated decisions. Privacy Counsel advise on the resulting privacy and data protection questions under laws such as the GDPR, CCPA and CPRA, and emerging AI regulation like the EU AI Act.