- Company Name
- Lawrence Harvey
- Job Title
- Head of Privacy / Data Protection Officer
- Job Description
-
**Job Title**: Head of Privacy / Data Protection Officer
**Role Summary**
Responsible for creating, leading, and continuously improving a worldwide privacy and data protection program for a global tech/digital company. Acts as the chief privacy officer, liaising with regulators, embedding privacy by design, and overseeing all privacy compliance activities across more than 100 jurisdictions.
**Expectations**
- Serve as the company’s Data Protection Officer (DPO) and primary privacy lead.
- Develop and maintain a global privacy framework that satisfies GDPR, CCPA, and other regional regimes.
- Manage privacy governance programs, including DPIAs, ROPAs, data mapping, and vendor assessments.
- Collaborate with product, engineering, legal, and business units to embed privacy into product strategy and operations.
- Draft, review, and negotiate privacy clauses in contracts and partnership agreements.
- Represent the company to regulators, respond to inquiries, and coordinate investigations.
**Key Responsibilities**
1. Design, implement, and update the global privacy strategy and policies.
2. Lead privacy governance, risk assessment, and incident response processes.
3. Conduct and oversee DPIAs, ROPAs, data inventories, and vendor risk reviews.
4. Embed privacy by design with product, engineering, and design teams.
5. Draft and negotiate privacy-related contractual provisions and third‑party agreements.
6. Liaise with supervisory authorities on regulatory queries, investigations, and audits.
7. Provide privacy training and awareness programs for staff.
8. Monitor regulatory developments and advise on compliance implications.
**Required Skills**
- Legal expertise in privacy and data protection law, with deep knowledge of GDPR, CCPA, and other international regulations.
- Strong negotiation and drafting skills for contracts and agreements.
- Experience leading privacy governance, DPIAs, ROPAs, data mapping, and vendor assessments.
- Ability to translate legal requirements into actionable privacy-by-design practices.
- Excellent communication and stakeholder management, including interactions with regulators.
- Analytical mindset for risk assessment and compliance monitoring.
- Proven ability to work in a technology‑focused, product‑led environment.
**Required Education & Certifications**
- Qualified lawyer (qualified to practice law).
- Minimum 6 + years of post‑qualification experience (PQE).
- Preference for prior experience in private practice at an international law firm.
- Demonstrated knowledge of global data protection regulations.