Skip to content
AGJ, the AI governance job board
Menu

Job description template

Privacy Counsel

The Privacy Counsel is the organization's legal advisor on privacy and data protection, guiding how personal data is collected, used, shared, and protected across the business. This template reflects how the role is scoped at organizations with active privacy programs, including the privacy questions raised by AI and automated decisions. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitlePrivacy Counsel
DepartmentLegal / Privacy & Data Protection
Reports to[General Counsel / Chief Privacy Officer / Deputy General Counsel]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Privacy Counsel provides legal advice on privacy and data protection for [Company], advising the business on how personal data may be collected, used, shared, transferred, and protected in line with applicable law. This attorney role sits at the intersection of legal, privacy, security, and product.

The Privacy Counsel interprets laws such as the GDPR, CCPA and CPRA, HIPAA where applicable, and emerging AI regulation, drafts and negotiates data-related contract terms, supports privacy impact assessments, and advises on new products and technologies. As AI and automated decisions use personal data, this role advises on the privacy and data protection questions they raise.

This is a legal role for a licensed attorney with strong privacy expertise and the judgment to give practical advice in a fast-moving regulatory environment.

Key responsibilities

Privacy legal advice

Regulatory interpretation

Translate a complex and changing legal landscape into practical guidance:

Contracts and transactions

Assessments and program support

Support privacy impact and data protection assessments, advise on data subject rights and breach obligations, and help maintain records of processing and privacy documentation.

AI and emerging technology

Advise on the privacy and data protection implications of AI and automated decision systems, including the use of personal data to train and run models, and support responsible AI review.

Incident and regulator response

Advise on privacy incidents and breach notification obligations, and support responses to regulators, data subject inquiries, and privacy-related disputes.

Required qualifications

Preferred certifications

One or more of: CIPP/US, CIPP/E, CIPM, CIPT, alongside active bar admission.

Technical knowledge

Privacy law and data protection, GDPR, CCPA and CPRA, HIPAA, cross-border data transfers, data processing agreements, privacy impact assessments, data subject rights, breach notification, and the privacy and data protection dimensions of AI and automated decisions.

Essential competencies

Legal judgment, regulatory interpretation, contract negotiation, clear counsel to business leaders, risk-based advice, and the ability to translate complex law into practical guidance.

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in privacy law and data protection rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC jobs

Stay close to the market

Frequently asked questions

What does a Privacy Counsel do?

A Privacy Counsel is an attorney who advises an organization on privacy and data protection law. They interpret privacy regulations, draft and negotiate data terms, support privacy assessments and breach response, and advise on the privacy questions raised by AI.

What qualifications and certifications does a Privacy Counsel need?

A Privacy Counsel needs a JD and active bar admission, plus 5 to 8 or more years of legal experience focused on privacy. Common certifications include CIPP/US, CIPP/E, and CIPM from the IAPP, alongside bar membership.

Who does a Privacy Counsel report to?

A Privacy Counsel typically reports to the General Counsel, a Chief Privacy Officer, or a Deputy General Counsel, and works closely with privacy, security, and product teams.

How does AI affect the Privacy Counsel role?

AI systems often use personal data to train and run models and can drive automated decisions. Privacy Counsel advise on the resulting privacy and data protection questions under laws such as the GDPR, CCPA and CPRA, and emerging AI regulation like the EU AI Act.