Responsibilities
- Providing strategic and commercially focused Data Privacy legal advice to support digital products, innovation projects, customer-facing platforms and strategic corporate initiatives;
- Advising on UK GDPR, the Data Protection Act 2018, PECR and related privacy legislation and regulatory developments;
- Reviewing, drafting and negotiating data privacy provisions within outsourcing agreements, data sharing agreements and wider technology and commercial contracts;
- Supporting the Bank’s use of AI, including advising on AI-specific contractual provisions and supporting implementation of AI initiatives alongside the Chief Data Officer function;
- Advising on international data transfers, including Standard Contractual Clauses, Binding Corporate Rules and other transfer mechanisms;
- Working closely with senior stakeholders across the Bank to deliver expert, accurate, concise, commercial and cost-effective legal advice that is readily understandable to non-lawyers;
- Collaborating closely with Data Privacy Compliance (including the DPO), Information Security, Data Privacy & Ethics and other business stakeholders to ensure a high standard of privacy compliance across Santander UK;
- Supporting Litigation, Retail, Business Banking and Santander Corporate Banking Legal teams on Data Privacy related queries;
- Keeping abreast of external developments in Data Privacy law and the financial services industry to enable Santander UK to react appropriately and in line with best practice, continuously seeking to improve processes, practices and policies;
- Sharing technical skills, experience and best practice with colleagues and the wider business and supporting other departments through training and the development of legal templates and checklists;
- Answering legal queries from internal customers as well as managing external suppliers/stakeholders to successfully deliver advice, projects and other outcomes on a timely basis.
Requirements
- Qualified solicitor in England & Wales, barrister or equivalent overseas qualified lawyer (Required)
- Excellent knowledge and experience of UK GDPR, the Data Protection Act 2018, PECR and wider Data Privacy regulatory frameworks (Required)
- Experience advising on Data Privacy issues within financial services, technology, digital or outsourcing environments (Required)
- Experience reviewing, drafting and negotiating data privacy terms within commercial contracts, outsourcing agreements and data sharing agreements (Required)
- Experience providing legal advice that is readily understandable to non-lawyers (Required)
- Strong stakeholder management and influencing skills with the ability to build trusted relationships across business and control functions (Required)
- A willingness to develop a working knowledge of Payments and Payments regulation (Preferred)
- Ability to provide pragmatic, commercial and risk-based legal advice in a fast-paced environment (Required)
- Strong communication skills with the ability to manage competing priorities and deadlines effectively (Required)
- Experience advising on AI governance and AI-related contractual or regulatory issues (Preferred)
- Knowledge of international data transfer mechanisms, including SCCs and BCRs (Preferred)
- Experience supporting Data Privacy governance frameworks, policies and procedures (Preferred)
- Experience dealing with a large volume of matters and competing demands (Preferred)
- Excellent project management skills, with an ability to manage multiple, conflicting interests and deadlines (Preferred)
#J-18808-Ljbffr…
