Overview
An established global FinTech organization is seeking a Senior Privacy Counsel with expertise in UK and EU privacy laws to join their Legal, Regulatory & Compliance team. This role focuses on providing specialist privacy advice for the UK region within a complex, consumer-facing technology environment. The position reports to the Global Head of Privacy & DPO and involves leading privacy strategy development and implementation tailored to UK and EU regulatory requirements.
Responsibilities
- Act as the specialist privacy adviser for the UK region, collaborating closely with Product Counsel across the EU and UK on complex privacy matters, regulatory queries, and high-risk data processing activities.
- Develop and execute privacy and data protection strategies ensuring compliance with GDPR, UK GDPR, Data Protection Act 2018, ePrivacy Directive, and national data protection laws across EU member states.
- Provide in-depth privacy advice to resolve complex issues effectively.
- Implement and adapt the global privacy framework to meet EU and UK requirements in collaboration with the wider Privacy & DPO team.
- Conduct and oversee privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, features, and business initiatives.
- Provide privacy by design guidance to Product Counsel for integration into product and engineering workflows.
- Manage data subject rights requests and respond to data disclosure requests from law enforcement authorities in a timely and compliant manner.
- Lead privacy breach preparedness and incident response efforts, including developing incident response plans, coordinating investigations, and managing regulatory notifications.
- Monitor legislative and regulatory developments affecting privacy and data protection in the EU and UK, providing analysis and recommendations to senior leadership.
- Manage engagements with privacy regulators such as the Information Commissioner's Office (ICO), European Data Protection Board (EDPB), and national data protection authorities.
- Collaborate with the global Privacy & DPO team to align privacy strategies, share best practices, and coordinate cross-regional initiatives.
- Develop and maintain privacy documentation including data inventories, records of processing activities, and compliance registers.
Requirements
- Law degree (LLB, LLM, or equivalent) and qualified solicitor, barrister, or equivalent legal qualification in an EU member state or the UK.
- 7-10 years of experience as a privacy lawyer at a technology company, including strong training at a reputable law firm.
- Proven experience in a consumer-facing environment, preferably within FinTech or payment services, with deep understanding of consumer privacy expectations and regulatory requirements.
- Experience working as part of a global privacy team across multiple jurisdictions and time zones.
- Deep expertise in EU and UK privacy laws and regulations, including GDPR, UK GDPR, Data Protection Act 2018, ePrivacy Directive, and national data protection laws.
- Ability to advise on novel and complex privacy issues without external support.
- Experience advising on cross-border data transfers using standard contractual clauses, adequacy decisions, binding corporate rules, and other mechanisms.
- Experience handling data subject rights and law enforcement data disclosure requests.
- Experience implementing privacy by design and data protection by default principles, working closely with Product and Engineering teams.
- Excellent legal drafting skills for privacy policies, notices, consent mechanisms, data processing agreements, and controller-processor agreements.
- Entrepreneurial, creative, and action-oriented with strong project management skills to handle multiple complex initiatives.
- Practical, business-oriented privacy advice balancing legal compliance with business objectives.
- Exceptional interpersonal and communication skills, able to explain complex legal issues simply.
- Experience managing data breach incidents including regulatory notifications.
- Relevant professional privacy certifications (e.g., CIPP/E, CIPM, CIPT) are highly desirable.
- Willingness to work flexible hours to collaborate globally and occasional travel.
Preferred Qualifications
- Professional privacy certifications such as CIPP/E, CIPM, or CIPT.
Compensation & Benefits
- 20 to 30 days of holiday to support work-life balance.
- Monthly team outing allowance for social events.
- Parental leave top-up support.
- On-site perks to enhance the workday.
- Well-being support including health allowance covering gym memberships, massages, and more.
- Additional benefits designed to enhance work-life experience.
Location
This role requires collaboration across multiple time zones and occasional travel. Specific location details are flexible but must accommodate working hours overlapping with UK and EU regions.