CrawlJobs Logo

Counsel, Privacy, Ai, And Data Protection

United States, Lexington Employment contract 150000.00 - 175000.00 USD / Year · Job Posted May 29, 2026
Apply Position
Job Link Share

Job Description

The Counsel for Privacy, AI, and Data Protection serves as the enterprise subject matter authority and accountable legal owner for Valvoline Global Operations' global privacy, data protection, and AI governance programs. This role is responsible for establishing and maintaining scalable, compliant, and business-enabling frameworks that govern the organization's use of data and artificial intelligence across all regions. Operating with significant independence, this role translates complex and evolving regulatory requirements into actionable enterprise policies, standards, and risk-based guidance. The position has direct accountability for the effectiveness, maturity, and continuous improvement of privacy and AI governance programs, influencing senior leadership decisions and enabling responsible innovation while protecting the organization from regulatory, legal, and reputational risk.

Job Responsibility

  • Accountable for the design, implementation, and ongoing effectiveness of Valvoline's global privacy program, including governance structure, policies, and operational processes
  • Owns enterprise interpretation and application of global privacy laws (e.g., GDPR, CCPA/CPRA), establishing company-wide standards and guidance
  • Accountable for core privacy program operations, including DPIAs/PIAs, DSAR processes, data mapping, and records of processing activities, ensuring they are scalable, auditable, and consistently executed
  • Establishes and monitors program KPIs and metrics to measure compliance, maturity, and operational effectiveness
  • drives remediation where gaps exist
  • Leads integration of privacy-by-design principles into business processes, systems, and product development, ensuring consistent adoption across functions
  • Accountable for the enterprise AI governance framework, including policy development, risk classification models, and required controls
  • Owns the legal review and risk determination framework for AI/ML use cases, including defining approval thresholds and escalation criteria
  • Ensures AI initiatives meet regulatory, ethical, and internal governance standards, providing final legal guidance on high-risk or ambiguous use cases
  • Translates global AI regulatory developments into enforceable internal requirements, ensuring timely adoption across the enterprise
  • Partners cross-functionally but retain accountability for the legal sufficiency and defensibility of AI governance practices
  • Accountable for identifying and assessing enterprise-level legal risks related to data protection, cybersecurity, and AI
  • Owns legal guidance on cross-border data transfers and data governance structures, including approval of compliant transfer mechanisms
  • Serves as the lead legal advisor during data incidents, accountable for legal risk assessment, privilege strategy, and notification obligations
  • Oversees legal support for regulatory inquiries, audits, and investigations, ensuring consistency and defensibility of the company's position
  • Drives alignment with Information Security and Compliance, while maintaining ownership of legal risk positions and interpretations
  • Accountable for establishing legal standards and required clauses for data protection and AI in commercial agreements
  • Provides final legal approval on complex or high-risk data-related contractual terms, including cross-border arrangements
  • Oversees third-party privacy and AI risk assessment frameworks, ensuring vendors meet company standards
  • Supports strategic initiatives and transactions, retaining accountability for privacy and AI risk positions
  • Acts as the primary legal authority and advisor to senior leadership on privacy, cybersecurity, and AI matters
  • Drives enterprise-wide understanding and adoption of privacy and AI requirements through training, frameworks, and practical tools
  • Influences decision-making at the leadership level, particularly where legal risk and business strategy intersect
  • Ensures alignment across Legal, Compliance, Risk, and business functions, while maintaining clear ownership of legal interpretations and positions

Requirements

  • Juris Doctor (JD) degree from an accredited law school and active license to practice law in at least one U.S. jurisdiction
  • Minimum of 8-12 years of legal experience, with significant focus on privacy, data protection, cybersecurity, and/or technology law
  • Demonstrated expertise in U.S. and global privacy laws and frameworks (e.g., GDPR, CCPA/CPRA) and strong familiarity with emerging AI regulatory requirements
  • Experience advising on AI/ML technologies, data-driven business models, or digital products, including governance and risk management considerations
  • Proven experience building or supporting global privacy programs and operationalizing compliance frameworks (e.g., DPIAs, DSARs, data mapping)
  • Strong experience partnering with Product, Engineering, IT, and Security teams to translate legal requirements into practical solutions
  • Demonstrated ability to operate independently, manage complex cross-functional initiatives, and provide strategic, risk-based legal advice
  • Excellent communication, negotiation, and stakeholder engagement skills, with the ability to influence senior leaders
  • Ability to travel (approximately 10-20%) to support global business initiatives and team engagement
  • Collaborate effectively across global time zones, providing support to regional stakeholders and participating in meetings outside standard business hours as needed to support a globally distributed organization

Nice to have

Relevant certifications (e.g., CIPP/US, CIPP/E, CIPM, AIGP) preferred

What we offer

  • Health insurance plans (medical, dental, vision)
  • Health Savings Account (with an employer-base deposit and match)
  • Flexible spending accounts
  • Competitive 401(k) with generous employer base deposit and match
  • Incentive opportunity
  • Life insurance
  • Short- and long-term disability insurance
  • Paid vacation and holidays
  • Employee Assistance Program
  • Employee discounts
  • PTO Buy/Sell Options
  • Tuition reimbursement
  • Adoption assistance

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Counsel, Privacy, Ai, And Data Protection

8 matching positions

Counsel, Privacy, AI, and Data Protection

Why Valvoline Global Operations? At Valvoline Global Operations, we're proud to ...
Location
Location
United States , Lexington
Salary
Salary:
150000.00 - 175000.00 USD / Year
valvoline.com Logo
Valvoline
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Juris Doctor (JD) degree from an accredited law school and active license to practice law in at least one U.S. jurisdiction
  • Minimum of 8–12 years of legal experience, with significant focus on privacy, data protection, cybersecurity, and/or technology law
  • Demonstrated expertise in U.S. and global privacy laws and frameworks (e.g., GDPR, CCPA/CPRA) and strong familiarity with emerging AI regulatory requirements
  • Experience advising on AI/ML technologies, data-driven business models, or digital products, including governance and risk management considerations
  • Proven experience building or supporting global privacy programs and operationalizing compliance frameworks (e.g., DPIAs, DSARs, data mapping)
  • Strong experience partnering with Product, Engineering, IT, and Security teams to translate legal requirements into practical solutions
  • Demonstrated ability to operate independently, manage complex cross-functional initiatives, and provide strategic, risk-based legal advice
  • Excellent communication, negotiation, and stakeholder engagement skills, with the ability to influence senior leaders
  • Ability to travel (approximately 10–20%) to support global business initiatives and team engagement
  • Collaborate effectively across global time zones, providing support to regional stakeholders and participating in meetings outside standard business hours as needed to support a globally distributed organization
Job Responsibility
Job Responsibility
  • Accountable for the design, implementation, and ongoing effectiveness of Valvoline's global privacy program, including governance structure, policies, and operational processes
  • Owns enterprise interpretation and application of global privacy laws (e.g., GDPR, CCPA/CPRA), establishing company-wide standards and guidance
  • Accountable for core privacy program operations, including DPIAs/PIAs, DSAR processes, data mapping, and records of processing activities, ensuring they are scalable, auditable, and consistently executed
  • Establishes and monitors program KPIs and metrics to measure compliance, maturity, and operational effectiveness
  • drives remediation where gaps exist
  • Leads integration of privacy-by-design principles into business processes, systems, and product development, ensuring consistent adoption across functions
  • Accountable for the enterprise AI governance framework, including policy development, risk classification models, and required controls
  • Owns the legal review and risk determination framework for AI/ML use cases, including defining approval thresholds and escalation criteria
  • Ensures AI initiatives meet regulatory, ethical, and internal governance standards, providing final legal guidance on high-risk or ambiguous use cases
  • Translates global AI regulatory developments into enforceable internal requirements, ensuring timely adoption across the enterprise
What we offer
What we offer
  • Health insurance plans (medical, dental, vision)
  • Health Savings Account (with an employer-base deposit and match)
  • Flexible spending accounts
  • Competitive 401(k) with generous employer base deposit and match
  • Incentive opportunity
  • Life insurance
  • Short- and long-term disability insurance
  • Paid vacation and holidays
  • Employee Assistance Program
  • Employee discounts
  • Fulltime
Read More
Arrow Right

Counsel – Privacy & Data Protection

Mastercard’s global Commercial and New Payment Flows (CNPF) Privacy team is seek...
Location
Location
United Kingdom , London
Salary
Salary:
Not provided
mastercard.com Logo
Mastercard
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Qualified lawyer with a strong academic foundation and solid legal training
  • Additional certifications (e.g., IAPP) are a plus
  • Keen interest in global data privacy developments and a working knowledge of privacy and data protection frameworks (e.g., GDPR
  • familiarity with others like CCPA is helpful but can be learned on the job) with some practical experience applying them, previous inhouse or technology/privacy exposure is beneficial
  • Familiarity with financial services, payments, or digital products is preferred, or a strong willingness to learn about these sectors
  • Experience with privacy platforms such as OneTrust is an advantage
  • Curiosity about digital technologies and an interest in how they intersect privacy and data governance
  • Proactive, practical, and eager to translate legal requirements into clear, usable guidance with support from senior team members
  • Strong verbal and written communication skills, with the ability to simplify complex information for non-legal audiences
  • Highly organized, detail-oriented, and able to manage multiple tasks in a fast-paced environment
Job Responsibility
Job Responsibility
  • Provide day to day privacy support to business teams, handling product queries and operational issues, and escalating complex matters where needed
  • Support the CNPF privacy team, including Move (Mastercard Send and Cross Border Services), by preparing guidance, assessments, and initial reviews for product initiatives and market expansion
  • Advise across the broader CNPF space (including B2B payments and SME solutions) on data use, AI enabled products, data flows, and controller/processor roles in multi party ecosystems
  • Embed Privacy by Design into the product lifecycle through initial impact assessments, risk screenings, and alignment with Mastercard’s privacy and AI governance frameworks
  • Assist with responses to government data requests, RFIs, and CDD inquiries by gathering inputs, preparing drafts, and ensuring compliance with internal and legal requirements
  • Support contracting by drafting and reviewing standard data protection terms, preparing for negotiations, and escalating higher risk issues
  • Monitor regulatory developments and contribute to legal scans, providing clear, practical summaries of key impacts
  • Help build privacy awareness across the business, including developing training materials and supporting capability building efforts
  • Collaborate across teams to ensure consistent application of privacy requirements and effective follow through on actions
  • Fulltime
Read More
Arrow Right

Senior Privacy Counsel & Data Protection Officer

Make online trading safer and privacy-first. As Senior Privacy Counsel & Data Pr...
Location
Location
Germany , Berlin
Salary
Salary:
Not provided
adevinta.com Logo
Adevinta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Relevant experience both in a law firm and in-house, preferably with online platforms and/or ad tech
  • German law degree (2. Staatsexamen or equivalent)
  • Multi-year experience in the data protection field
  • Have worked as a DPO
  • Have successfully engaged with data protection regulators
  • Proactive and a creative problem solver
  • High interest in networking and building social connections
  • Excellent collaborator with solid diplomacy, stakeholder management and strong presentation skills
  • Strong understanding of AI and data-driven technologies and their privacy implications
  • Know how to assess and mitigate privacy risks of AI systems
Job Responsibility
Job Responsibility
  • Act as a key contact for local regulators and officials in incidents, investigations or policy consultations
  • Monitor and interpret changes in legislation, industry standards and regulatory positions on privacy and data use
  • Develop and maintain a strong network with external privacy experts
  • Manage, monitor and report on privacy compliance topics
  • Identify data protection issues proactively and recommend pragmatic remedies
  • Co-shape and iterate the local privacy strategy and roadmap
  • Fulfill all DPO-related tasks under GDPR and local law
  • Run regular internal privacy compliance audits
  • Design and deliver training for business stakeholders
What we offer
What we offer
  • An attractive Base Salary
  • Participation in our Short Term Incentive plan (annual bonus)
  • Work From Anywhere: Enjoy up to 20 days a year of working from anywhere
  • A 24/7 Employee Assistance Program for you and your family
  • Fulltime
Read More
Arrow Right

Senior Privacy Counsel & Data Protection Officer

Make online trading safer and privacy-first. As Senior Privacy Counsel & Data Pr...
Location
Location
Germany , Berlin
Salary
Salary:
Not provided
adevinta.com Logo
Adevinta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Relevant experience both in a law firm and in-house, preferably with online platforms and/or ad tech
  • German law degree (2. Staatsexamen or equivalent)
  • Multi-year experience in the data protection field
  • Experience working as a DPO
  • Experience successfully engaging with data protection regulators
  • Proactive and a creative problem solver
  • High interest in networking and building social connections
  • Excellent collaborator with solid diplomacy, stakeholder management and strong presentation skills
  • Strong understanding of AI and data-driven technologies and their privacy implications
  • Know how to assess and mitigate privacy risks of AI systems
Job Responsibility
Job Responsibility
  • Act as a key contact for local regulators and officials in incidents, investigations or policy consultations
  • Monitor and interpret changes in legislation, industry standards and regulatory positions on privacy and data use
  • Develop and maintain a strong network with external privacy experts
  • Manage, monitor and report on privacy compliance topics, including records of processing activities, impact assessments and data retention
  • Identify data protection issues proactively and recommend pragmatic remedies
  • Co-shape and iterate the local privacy strategy and roadmap
  • Fulfill all DPO-related tasks under GDPR and local law, including reporting and governance structures
  • Run regular internal privacy compliance audits
  • Design and deliver training for business stakeholders
What we offer
What we offer
  • An attractive Base Salary
  • Participation in our Short Term Incentive plan (annual bonus)
  • Work From Anywhere: Enjoy up to 20 days a year of working from anywhere
  • A 24/7 Employee Assistance Program for you and your family
  • A collaborative environment with an opportunity to explore your potential and grow
  • A range of locally relevant benefits
  • Fulltime
Read More
Arrow Right

Privacy and AI Counsel

At Harvey, we’re transforming how legal and professional services operate — not ...
Location
Location
United States , San Francisco
Salary
Salary:
179000.00 - 241000.00 USD / Year
harvey.ai Logo
Harvey
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Qualified lawyer with 4+ years of post-qualification experience in privacy and data protection
  • Proven expertise in U.S. and E.U. data protection law, with familiarity across global compliance frameworks
  • Excellent drafting and negotiation skills, with the confidence to represent Harvey on matters relating to data privacy, AI, and security
  • Strong interpersonal skills, with the ability to collaborate effectively across legal and business teams
  • Highly responsive and detail-oriented, with the ability to balance strategic thinking and hands-on execution
Job Responsibility
Job Responsibility
  • Assist in drafting, reviewing, and negotiating Data Processing Agreements with our customers, subprocessors, service providers, and third-parties
  • Help develop, maintain, and scale global privacy programs. This includes preparing Data Protection Impact Assessments to identify and mitigate privacy risks and Records of Processing in accordance with regulatory requirements
  • Work cross functionally with talented product and engineering teams in evaluating the impact of privacy and data protection laws and regulatory guidance on exciting product developments
  • Monitor and respond to changes in privacy laws and regulations, including AI regulations
  • Support implementation and ongoing compliance with AI-specific regulation, including the CCPA governance framework, and related guidance
  • Assist in classification of AI systems, assessment of risk obligations, and development of internal AI governance controls, documentation, and processes
  • Partner with legal, product, and compliance stakeholders on AI principles such as transparency, accountability, and human-oversight
What we offer
What we offer
  • Offers Equity
  • Offers Bonus
  • Comprehensive health, dental and vision coverage
  • retirement benefits (401k match up to 4%)
  • flexible PTO
  • Fulltime
Read More
Arrow Right

Privacy and AI Counsel

At Harvey, we’re transforming how legal and professional services operate — not ...
Location
Location
United States , New York
Salary
Salary:
179000.00 - 241000.00 USD / Year
harvey.ai Logo
Harvey
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Qualified lawyer with 4+ years of post-qualification experience in privacy and data protection
  • Proven expertise in U.S. and E.U. data protection law, with familiarity across global compliance frameworks
  • Excellent drafting and negotiation skills, with the confidence to represent Harvey on matters relating to data privacy, AI, and security
  • Strong interpersonal skills, with the ability to collaborate effectively across legal and business teams
  • Highly responsive and detail-oriented, with the ability to balance strategic thinking and hands-on execution
Job Responsibility
Job Responsibility
  • Assist in drafting, reviewing, and negotiating Data Processing Agreements with our customers, subprocessors, service providers, and third-parties
  • Help develop, maintain, and scale global privacy programs. This includes preparing Data Protection Impact Assessments to identify and mitigate privacy risks and Records of Processing in accordance with regulatory requirements
  • Work cross functionally with talented product and engineering teams in evaluating the impact of privacy and data protection laws and regulatory guidance on exciting product developments
  • Monitor and respond to changes in privacy laws and regulations, including AI regulations
  • Support implementation and ongoing compliance with AI-specific regulation, including the CCPA governance framework, and related guidance
  • Assist in classification of AI systems, assessment of risk obligations, and development of internal AI governance controls, documentation, and processes
  • Partner with legal, product, and compliance stakeholders on AI principles such as transparency, accountability, and human-oversight
What we offer
What we offer
  • Offers Equity
  • Offers Bonus
  • Comprehensive health, dental and vision coverage
  • retirement benefits (401k match up to 4%)
  • flexible PTO
  • Fulltime
Read More
Arrow Right

Senior Privacy Counsel & Data Protection Officer

Make online trading safer and privacy-first. As Senior Privacy Counsel & Data Pr...
Location
Location
Germany , Berlin
Salary
Salary:
Not provided
adevinta.com Logo
Adevinta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Relevant experience both in a law firm and in-house, preferably with online platforms and/or ad tech
  • Hold a German law degree (2. Staatsexamen or equivalent)
  • Multi-year experience in the data protection field
  • Have worked as a DPO
  • Have successfully engaged with data protection regulators
  • Proactive and a creative problem solver
  • High interest in networking and building social connections
  • Excellent collaborator with solid diplomacy, stakeholder management and strong presentation skills
  • Strong understanding of AI and data-driven technologies and their privacy implications
  • Know how to assess and mitigate privacy risks of AI systems
Job Responsibility
Job Responsibility
  • Act as a key contact for local regulators and officials in incidents, investigations or policy consultations
  • Monitor and interpret changes in legislation, industry standards and regulatory positions on privacy and data use
  • Develop and maintain a strong network with external privacy experts
  • Manage, monitor and report on privacy compliance topics
  • Identify data protection issues proactively and recommend pragmatic remedies
  • Co-shape and iterate the local privacy strategy and roadmap
  • Fulfill all DPO-related tasks under GDPR and local law
  • Run regular internal privacy compliance audits
  • Design and deliver training for business stakeholders
What we offer
What we offer
  • An attractive Base Salary
  • Participation in our Short Term Incentive plan (annual bonus)
  • Work From Anywhere: Enjoy up to 20 days a year of working from anywhere
  • A 24/7 Employee Assistance Program for you and your family
  • A collaborative environment with an opportunity to explore your potential and grow
  • Fulltime
Read More
Arrow Right

Senior Counsel, Privacy, AI & Data Responsibility

Mastercard is committed to balancing innovation with legal compliance and has em...
Location
Location
United States of America , Purchase; Arlington
Salary
Salary:
204000.00 - 325000.00 USD / Year
mastercard.com Logo
Mastercard
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Law degree required
  • Membership to a Bar (if permitted by law)
  • Solid expertise in AI legal frameworks
  • Strong understanding of global data protection laws (e.g., GDPR, CCPA)
  • Track record dealing with Artificial Intelligence projects, products or solutions
  • Good understanding of AI technologies, incl. Generative and Agentic AI
  • Ability to translate complex technical concepts into practical legal solutions
  • Ability to collaborate across functions and influence stakeholders
  • Exceptional interpersonal skills with proven experience in relationship building and partnering
  • Superior time management, planning, and organizational skills
Job Responsibility
Job Responsibility
  • Partner with the AI and Data Office to enable AI efforts, including big bets from a privacy and AI legal perspective
  • Work with business stakeholders to implement legal, technical, operational and administrative requirements for Mastercard's AI solutions and uses stemming from evolving AI regulations globally
  • Provide AI legal and privacy expertise to key initiatives furthering Mastercard AI Governance
  • Develop and review documentation on Mastercard's Responsible AI
  • Monitor regulatory guidance and enforcement on AI laws to assess evolving impact on Mastercard’s AI Compliance Program
  • Collaborate with Public Policy and Government Affairs on engagement efforts on evolving AI regulatory and policy initiatives
What we offer
What we offer
  • Insurance (including medical, prescription drug, dental, vision, disability, life insurance)
  • Flexible spending account and health savings account
  • Paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave)
  • 80 hours of Paid Sick and Safe Time
  • 25 days of vacation time and 5 personal days, pro-rated based on date of hire
  • 10 annual paid U.S. observed holidays
  • 401k with a best-in-class company match
  • Deferred compensation for eligible roles
  • Fitness reimbursement or on-site fitness facilities
  • Eligibility for tuition reimbursement
  • Fulltime
Read More
Arrow Right