Overview
This role is part of a Regulatory and Privacy Legal team that addresses regulatory, privacy, and data protection issues affecting a large commerce platform. The team advises product and engineering groups on compliance with evolving laws across multiple jurisdictions, manages regulator inquiries, handles privacy incidents, negotiates data practices with partners, and develops scalable internal frameworks. The position reports to the Director of Privacy Legal.
Responsibilities
- Provide privacy legal counsel on complex product launches, new features, and strategic partnerships involving merchant and buyer data.
- Manage regulatory relationships and respond to privacy-specific inquiries from data protection authorities and US state enforcement agencies.
- Lead cross-functional privacy initiatives to advance the privacy program, including building resources, frameworks, and playbooks.
- Advise on data protection aspects of commercial agreements with merchants, vendors, and partners.
- Collaborate with Privacy Engineering and Trust teams on incident response, data governance, and compliance infrastructure.
- Maintain expertise in global privacy laws such as GDPR, CCPA, UK data protection laws, EU AI Act privacy implications, and emerging regulatory frameworks.
Requirements
- Juris Doctor (J.D.) or LL.B. degree with a license to practice law in the United States or Canada.
- Minimum of 8 years of relevant legal experience, ideally including law firm, government, and/or in-house roles.
- Substantial experience advising on privacy and data protection matters, including GDPR and CCPA.
- Strong technical curiosity and understanding of data flows and their compliance implications.
- Experience managing outside counsel.
- Ability to communicate complex privacy concepts clearly to diverse audiences including engineers and regulators.
- Strong judgment and comfort making decisions under uncertainty.
- Proven ability to build trust and collaborate across multiple teams such as product, engineering, legal, trust & safety, and finance.
- Pragmatic approach to regulatory risk, distinguishing between legal requirements and regulatory priorities.
Preferred Qualifications
- Experience engaging with regulators or enforcement agencies on privacy matters.
- Experience advising on AI and data governance issues.
- Experience building or shipping products using AI tools.
- Privacy certifications such as CIPP/US, CIPP/E, or CIPM are a plus but not required.
Skills and Attributes
- Comfortable working in a fast-paced, ambiguous, and rapidly changing environment.
- Ability to embrace and leverage AI tools for drafting, research, and legal work.
- Resilient, resourceful, and able to thrive amid complexity and change.
- Strong critical thinking and ability to express informed opinions.
- Collaborative mindset that values diverse perspectives and constructive disagreement.
- Digital-first work approach.
Compensation & Benefits
Details about compensation and benefits are not provided in this description.
Location
Location details are not specified in this description.