Sr. Counsel, Privacy ComplianceActive$220K
The opportunity
Databricks is at the forefront of data and AI innovation, and our Legal team plays a vital role in supporting this mission. We are dedicated to navigating complex legal landscapes and ensuring compliance within the rapidly evolving technology sector.
What you'll do
Legal advice and regulatory interpretation. Advise on compliance with global: privacy and data protection laws (e.g., GDPR, CCPA/CPRA, ADMT, and other U.S. state laws, Monitor legal and regulatory developments, and translate them into actionable guidance for the business.
Privacy Program & Governance Leadership: Build and mature Databricks’ privacy program to continue meeting evolving regulatory expectations, including contributions to AI governance. Develop core program components for compliance with new regulations, including data subject rights requests, privacy notices, consent management, PIA/DPIAs, and policy management.
Risk assessments. Conduct gap analysis and risk assessments, including Data: Protection Impact Assessments (DPIAs), Privacy Impact Assessments (PIAs), and transfer impact assessments to identify, assess, and help mitigate privacy risk, and support the organization's records of processing activities (RoPA) .
Contract Negotiation and Transactions: Draft and update form agreements, and counsel on and negotiate data protection provisions in commercial contracts, including data processing addendums (DPAs), standard contractual clauses (SCCs), and related data-transfer instruments.
Policies, training, and governance. Develop and maintain internal privacy: policies, external privacy notices, and standards. Design and deliver privacy training and awareness programs, and help operationalize privacy and AI governance frameworks and cross-functional privacy committees.
Cross-Functional Collaboration & Legal Partnership: Build deep cross-functional relationships and collaborate with other legal leaders in commercial, go-to-market, compliance, corporate, and public affairs on privacy issues.
What they're looking for
- Business and Legal Judgment: Exercise practical judgment about when to approve, approve with conditions, decline, or escalate.
- Team Contribution: Provide general legal support on a flexible, as-needed basis across other areas of the business, and contribute as a team player to further the legal department's reputation as an effective, respected, and valued resource within the company.
- + years of relevant legal experience at a top law firm and/or in-house (a: combination of both is a plus), with 5+ years focused on privacy and demonstrated experience building, operating, or leading a privacy compliance program (not solely advisory work)
- Deep, current knowledge of global privacy and AI frameworks, including the: GDPR/UK GDPR, CCPA/CPRA, EU AI Act, and the growing patchwork of U.S. state comprehensive privacy and AI laws, and familiarity with cross-border data transfer mechanisms (SCCs, IDTA, adequacy, EU-U.S. Data Privacy Framework).