This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Senior Legal Counsel – Data Privacy & Compliance. This role combines data privacy leadership with a broader compliance and AI governance remit, offering real variety and the opportunity to build sustainable, practical frameworks that enable the business to move forward with confidence. Roughly 60% of the role focuses on data protection, with the remaining 40% covering wider legal compliance, governance, and AI related matters.
Job Responsibility:
Lead UK data protection compliance across the full consumer and employee data lifecycle
Develop, maintain, and embed clear, workable data protection policies and governance frameworks
Manage Whitbread’s relationship with its outsourced UK DPO
Provide guidance and support to our teams in Ireland and Germany
Oversee DPIAs, ROPAs, DSARs and data related disputes
Advise on CRM, digital marketing, cookies and consent
Draft and negotiate data processing and data sharing agreements
Work closely with IT and digital teams to ensure privacy by design is built into new initiatives from the outset
Acting as the legal subject matter expert on AI regulation and emerging legal developments
Playing an active role on Whitbread’s AI Governance Forum, supporting responsible and effective decision making
Advising on AI governance frameworks, including oversight of AI use by third party suppliers
Supporting the business to enable the safe, compliant, and ethical use of AI, balancing innovation with appropriate safeguards
Code of Conduct governance and communications
Competition law risk management and training
Anti bribery and corruption frameworks
Supporting compliance reporting to the Audit Committee
Requirements:
Qualification as a lawyer with around 5+ years’ PQE
Experience in UK data protection law (EU exposure helpful but not essential)
Experience working with significant volumes of consumer and/or employee data (B2C experience important)
An interest in, or exposure to, AI regulation and governance, and a willingness to stay close to emerging developments
The ability to write clear, practical policies and guidance
Confidence working with senior stakeholders in a complex organisation
A pragmatic, solutions focused approach
Private practice or in house backgrounds are welcome