Overview
This Senior Director, Data Privacy role is a newly created attorney-held position responsible for developing and owning a global data privacy program covering GDPR, UK GDPR, and U.S. federal and state privacy laws including CCPA/CPRA, HIPAA, and other relevant regulations. Reporting to the Chief Legal Officer, the role serves as the primary privacy counsel and program owner, collaborating with multiple departments such as IT, Clinical Operations, Pharmacovigilance, Patient Advocacy, HR, Finance, and Commercial. The position supports the organization's transition from clinical-stage to commercial-stage biopharmaceutical operations.
Responsibilities
- Lead and enhance the global privacy program, acting as the primary legal advisor on GDPR, UK GDPR, and applicable U.S. privacy laws.
- Conduct enterprise-wide Data Protection Impact Assessments (DPIAs) and maintain Records of Processing Activities (ROPAs) in partnership with the external Data Protection Officer.
- Develop, implement, and update core privacy policies and procedures ensuring legal compliance and internal consistency.
- Manage the data subject/consumer rights program, including intake, identity verification, deadline tracking, and coordination with processors and vendors.
- Establish and maintain a vendor privacy compliance program, including a vendor register, risk-based due diligence, questionnaires, and Data Processing Agreements or Business Associate Agreements.
- Review and negotiate privacy and data protection terms in contracts such as DPAs, clinical trial agreements, master services agreements, and vendor agreements.
- Evaluate and document controller, joint-controller, and processor relationships, implementing Article 26-compliant joint-controller arrangements as needed.
- Map cross-border data transfers and implement appropriate transfer mechanisms, including Transfer Impact Assessments and remediation of legacy documentation.
- Oversee the incident and breach response program, ensuring compliance with GDPR/UK GDPR, HIPAA, FTC, and state law timelines, and lead breach investigations and regulatory notifications.
- Advise Clinical Operations and Pharmacovigilance on privacy aspects of trials, expanded access programs, and safety data flows.
- Provide privacy guidance for Commercial, Marketing, and Patient Services on digital properties, patient-support programs, CRM/analytics platforms, and real-world data initiatives.
- Manage privacy readiness for healthcare professional transfers-of-value reporting (Sunshine Act/Open Payments).
- Design and implement role-based data protection training and awareness programs for employees and contractors.
- Coordinate with IT and Managed Service Providers on privacy-relevant security controls.
- Monitor emerging privacy obligations and update the data protection gap analysis and remediation roadmap accordingly.
- Prepare periodic privacy program metrics and status reports for senior leadership and the Audit Committee.
- Foster a culture of privacy, ethics, and accountability across all locations.
- Manage contractors, vendors, and outside counsel supporting the privacy program.
- Perform other duties and projects as assigned.
Required Qualifications
- Juris Doctor (JD) from an accredited law school.
- Admission to a state bar with an active license to practice law.
- At least 8 years of relevant legal experience, including substantial hands-on experience building or managing privacy programs, preferably in-house at life sciences, pharmaceutical, or biotechnology companies, or in law firms/consultancies serving these sectors.
- Deep expertise in GDPR and UK GDPR, including practical experience with ROPAs, DPIAs, cross-border transfers, and data subject rights.
- Strong knowledge of U.S. privacy laws applicable to biopharmaceutical companies, including HIPAA, FTC Act, Health Breach Notification Rule, and state privacy laws such as CCPA/CPRA, Washington MHMDA, Connecticut CTDPA, and Nevada SB 370.
- Familiarity with clinical trial and pharmacovigilance data flows and regulatory frameworks (ICH-GCP, EU Clinical Trials Regulation, FDA regulations), and life sciences transparency reporting (Sunshine Act/Open Payments).
- Privacy certifications such as CIPP/E and/or CIPP/US are strongly preferred.
- Proven ability to translate legal requirements into practical, risk-based operational programs and drive remediation efforts to completion.
- Excellent verbal and written communication skills, capable of engaging both technical and non-technical stakeholders.
- Strong project management skills with the ability to prioritize and manage multi-year remediation roadmaps.
- Proactive, self-directed, and able to operate with minimal supervision in a fast-paced environment.
- High professional judgment, integrity, and ability to build collaborative relationships at all organizational levels.
- Adaptable to changing business needs during the transition from clinical-stage to commercial-stage operations.
Location and Travel
- This is a remote position within the United States requiring availability to work during U.S. Eastern Time Zone hours.
- Periodic overnight travel within the U.S. is required, including visits to corporate headquarters in Yardley, PA.
- Occasional international travel may be necessary to engage with European stakeholders.
Compensation and Benefits
Details regarding compensation and benefits will be provided during the recruitment process.