Overview
An established global leader in Open Banking Payments is seeking an experienced Privacy Counsel to join their Legal, Compliance & Risk team. This role focuses on supporting the implementation and adaptation of the organization's global privacy framework across the Americas (US, Brazil, and Canada). The Privacy Counsel will provide expert advice on data protection matters and ensure compliance with the highest privacy standards.
Responsibilities
- Support execution of the privacy strategy for the Americas region, ensuring compliance with US federal and state privacy laws (including CCPA/CPRA, applicable state laws, GLBA, and FCRA), Canadian privacy laws (including PIPEDA and Quebec Law 25), and Brazilian privacy law (LGPD).
- Conduct privacy impact assessments for new products, services, features, and business initiatives.
- Provide practical, business-focused legal advice on privacy matters to internal stakeholders.
- Advise on data subject rights requests such as rights to access and opt-out.
- Support privacy breach preparedness and incident response efforts, including contributing to incident response plans, coordinating breach investigations, and managing notifications to supervisory authorities and communications to data subjects.
- Advise on and support negotiation of data processing agreements, data transfer mechanisms (including standard contractual clauses, adequacy decisions, and other transfer tools), and privacy terms with vendors, partners, and customers.
- Monitor legislative and regulatory developments affecting privacy and data protection in the Americas, providing timely analysis and recommendations to senior leadership.
- Collaborate closely with the global Privacy & DPO team to ensure alignment on privacy strategies, share best practices, and coordinate cross-regional privacy initiatives.
- Develop and maintain privacy documentation, including records of processing activities, legal advice notes, and privacy compliance registers.
- Support privacy-related audits, assessments, and due diligence activities.
Requirements
- Juris Doctor (JD) degree from an accredited law school and active bar admission in at least one US jurisdiction.
- Minimum of 3-5 years of experience as a privacy attorney, including demonstrated experience advising on GLBA, CCPA, and state data protection laws.
- Experience in the FinTech or payment services sector is a plus, with knowledge of privacy challenges and regulatory landscape affecting payments and financial technology companies.
- Experience working as part of a global privacy team with the ability to collaborate across multiple jurisdictions and time zones.
- Demonstrated experience handling data subject rights requests and data disclosure requests from law enforcement authorities.
- Strong knowledge of US privacy laws such as CCPA/CPRA, major state privacy laws, and federal sector-specific regulations like GLBA and FCRA.
- Familiarity with Canadian privacy laws (including PIPEDA and Quebec Law 25) and Brazilian privacy law (LGPD) sufficient to identify relevant issues and support engagement with local counsel.
- Experience advising on cross-border data transfers, including standard contractual clauses, adequacy decisions, and other transfer mechanisms.
- Relevant professional privacy certifications (e.g., CIPP/US, CIPM, CIPT) are highly desirable.
- Strong interpersonal and communication skills with the ability to explain complex legal issues clearly.
- Entrepreneurial and creative mindset with a bias for action.
- Strong legal drafting skills, including development of privacy policies, notices, consent mechanisms, data processing agreements, and controller-processor agreements.
- Strong project management skills with the ability to manage multiple complex privacy initiatives simultaneously.
- Proven ability to provide practical, business-oriented privacy advice balancing legal compliance with business objectives.
- Experience managing data breach incidents, including regulatory notifications and communications with affected data subjects.
- Strong analytical and problem-solving skills.
- Willingness to work flexible hours to collaborate with global privacy team members across different time zones.
Compensation & Benefits
- Salary ranges vary by role, level, and location within the US. Individual pay is determined by work location, skills, experience, and education.
- Compensation details listed reflect base salary only and do not include additional perks and benefits.
- Benefits include flexible paid time off and generous PTO accrual plans, comprehensive medical, dental, vision, and other insurances.
- FSA & HSA plans for medical and dependent care.
- Home office setup allowance and internet stipend.
- Retirement plan match for 401k and RRSP.
- Gender-neutral paid parental leave.
Location
This role supports the Americas region, including the US, Brazil, and Canada, and requires flexibility to collaborate across multiple time zones.
Applications for this role are accepted on an ongoing basis.