Senior Privacy Counsel - APACActive

The opportunity

The Global DPO Office is expanding its presence across regions, with team members currently based in Amsterdam and New York and plans to grow in APAC. We own Adyen’s global privacy program and AI governance, and support incident response and data governance across the business.

What you'll do

  • Act as the senior privacy advisor for Adyen's APAC operations, providing: pragmatic, business-aligned guidance to regional product, engineering, commercial, HR, and corporate teams.

  • Adapt and extend Adyen's global privacy framework, standards, and policies to: meet regional requirements, establishing a consistent and scalable privacy baseline across APAC jurisdictions.

  • Advise on and help operationalize privacy compliance across the APAC region,: spanning major regimes such as Singapore's PDPA, India's DPDPA, Japan's APPI, Australia's Privacy Act, and Hong Kong's PDPO, as well as navigating cross-border data flows, localization requirements, and the extraterritorial reach of regional privacy laws..

  • Advise on cross-border data transfers, data localization, and localized: consent flows across the region, in close coordination with regional product and engineering hubs.

  • Conduct and review privacy impact assessments, data protection impact: assessments, and records of processing activities for APAC-specific initiatives and entities.

  • Anticipate and identify data protection obligations and risks, and help: address them in a practical, scalable, and privacy-by-design manner.

What they're looking for

  • You are a qualified lawyer in a Commonwealth jurisdiction.
  • You have 7+ years of relevant data privacy experience, including GDPR and a: strong command of APAC privacy regimes.
  • You have deep, hands-on expertise in two or more APAC privacy frameworks: (e.g., PDPA, DPDPA, APPI, PIPA, PDPO, PIPL) and a strong grasp of the wider regional landscape, including cross-border data-transfer and localization requirements.
  • You have experience setting up or scaling a privacy program in-house, and you: know how to build a baseline that works across many different countries; law firm experience is also valued.
  • You are a generalist comfortable across commercial negotiations, compliance: frameworks, vendor assessments, incident management, data transfers, data protection impact assessments, and privacy by design.
  • You are experienced at cross-functional partnering across engineering,: product, legal, compliance, and enterprise risk, and confident engaging with regional stakeholders and, at times, local regulators.
  • Experience in payments, financial services, or fintech is strongly preferred, though not essential.
  • Knowledge of emerging AI regulation and AI governance frameworks (such as the: EU AI Act and IMDA's Model AI Governance Framework) is a plus.