Lead Privacy Counsel | London (Hybrid) 2/3 days a week in the office
Data compliance isn’t a peripheral function at this business, it sits at the heart of the product and the business model.
We’re working with a fast-growing, VC-backed B2B SaaS company that builds a leading sales intelligence and data platform for revenue teams across Europe and the US. Headquartered in one of London’s most iconic office buildings, with several hundred employees across multiple continents, the business has scaled rapidly since its founding roughly a decade ago and continues to grow at pace, recently strengthening its leadership team as it enters its next phase of growth.
As the company matures and invests further in its legal and governance infrastructure, this newly created role will lead and embed a privacy function that is genuinely robust, not just defensible on paper.
The Role
Reporting to the superb CLO, this is a hands‑on leadership role with real scope and immediate impact. You will be the primary privacy resource in‑house, leading core privacy workstreams across the business from policy and governance through to privacy by design, AI governance, and training.
This is an opportunity to build something. You will shape the privacy function around genuine business need, working directly with product, engineering, sales, marketing and HR. You will be expected to lead workstreams, not just support them. For the right candidate there is the opportunity to travel across Europe and US.
What You Will Do
- Privacy governance and policy own the full suite of privacy policies, frameworks and governance documentation; build and operationalise a data retention framework; maintain the ROPA and privacy notices; support internal and external audits; manage the subject rights process and privacy incidents end‑to‑end.
- Privacy by design embed a privacy by design programme across product and engineering; develop practical frameworks that allow fast‑moving teams to build compliantly; act as the primary legal voice in product development cycles.
- AI strategy and implementation lead development of an AI governance framework; advise on privacy implications of AI tools and features; lead DPIAs for AI‑related processing; keep the business ahead of regulatory change.
- Global data complexity progress Transfer Impact Assessments for non‑EEA transfers; support jurisdiction‑specific compliance requirements; work with engineering on data mapping.
- Vendor governance refine the DDQ process; manage vendor audit cadence; review and negotiate DPAs.
- Training and engagement design and deliver a refreshed privacy training programme; build genuine privacy literacy, not tick‑box compliance.
- Commercial support advise on data protection aspects of contracts and supplier arrangements.
- Senior stakeholder engagement advise and influence senior leadership, including at C‑suite level, on privacy risk, strategy and business impact.
About You
You are a qualified solicitor with 5–8 years’ PQE and a strong privacy specialism. You have genuine in‑house experience and have owned and delivered privacy workstreams, not just advised on them. You’re ready to lead a function and want the platform to build something properly, rather than inherit someone else’s structure.
- Qualified solicitor (England & Wales or equivalent)
- 5–8 years’ PQE in data protection / privacy law
- In‑house experience owning and delivering privacy programmes end‑to‑end
- Practical grounding in UK GDPR, EU GDPR, CCPA, EU AI Act and international transfers
- Experience working directly with engineering or product teams
- Background in B2B data, adtech, or a business where data is the product
- Experience with DSAR automation tooling
- International privacy experience beyond UK/EU
#J-18808-Ljbffr…
