Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Senior Data Privacy & AI Lawyer / Senior Data Privacy & AI Manager

nrf
Companynrf
CategoryData & Analytics
Location2 Locations
Remote
EmploymentNot stated
LevelManager
SalaryNot stated by the employer
Posted4 Jul 2026
Last verified11 Aug 2026
SourceEmployer ATS (workday)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Praxisgruppe / Abteilung: Head of Regulatory Risk, General Counsel & Risk Stellenbeschreibung Wir sind Norton Rose Fulbright – eine globale Wirtschaftskanzlei mit über 50 Büros und 7.000 Mitarbeiterinnen und Mitarbeitern weltweit. Wir beraten führende Unternehmen und Finanzinstitute umfassend zu allen Fragen des Wirtschaftsrechts. Bei Norton Rose Fulbright sind Strategie und Unternehmenskultur eng miteinander verknüpft. Wir wissen, dass für unser Wachstum die internationale Zusammenarbeit entscheidend ist. Denn Pionierarbeit entsteht, wenn unsere Mitarbeiterinnen und Mitarbeiter über Grenzen hinweg innovativ denken und unternehmerisch handeln – und sich mit Wertschätzung für ihre eigene Arbeit dabei frei entfalten können. The Team Part of the Regulatory Risk team within the General Counsel & Risk function, working closely with the Data Protection Officer (DPO) and Legal Transformation and Technology teams, collaborating with GC & Risk colleagues and wider legal and business services teams to deliver a coordinated approach to privacy and AI governance across the firm’s operations in Europe, Middle East, Asia and the Pacific (EMEAPAC). The Role We are seeking a senior in-house privacy professional to work within the Regulatory Risk team of our General Counsel & Risk function. The individual will work with the Head of Regulatory alongside our  Data Protection Officer (DPO) to deliver and embed the firm’s data protection compliance frameworks across its Europe, Middle East, Asia and the Pacific (EMEAPAC) region. In equal measure, the individual will engage with key stakeholders and senior management to drive the firm’s AI strategy across EMEAPAC, while also ensuring development of, and adherence with, the firm’s governance strategy, legal, regulatory and client requirements and risk management processes. The individual will act as a key adviser and operational lead, helping to ensure the firm meets its obligations under applicable data protection and emerging AI regulation in EMEAPAC, by maintaining a consistent compliance framework tailored to local legal requirements. Key Responsibilities • Support the execution and continuous improvement of the privacy and AI governance programme • Monitor and interpret global data protection and AI regulatory developments (including the EU AI Act) • Develop and maintain policies, frameworks and governance standards • Manage core operational processes (e.g. RoPAs, DPIAs, DSARs, etc) • Embed Privacy by Design and oversee AI risk and impact assessments • Provide clear, practical advice to business and technical teams • Deliver training and promote awareness of privacy and responsible AI usage • Support incident response, breach management and regulatory engagement • Draft and negotiate data protection terms in supplier contracts and oversee vendor risk assessments • Collaborate across legal and business services to ensure consistent governance and delivery • Support and deputise for the Head of Regulatory Risk and the DPO in delivering the firm’s privacy programme • Acting as subject matter expert on legal and regulatory risks in respect of the firm’s AI governance programme, with a solutions-focused mindset • Translate strategy into operational execution across EMEAPAC • Act as a trusted adviser to business and technical stakeholders • Negotiate with suppliers and liaise with clients in relation to AI and privacy requirements, as required • Embed privacy and responsible AI principles across projects, systems and processes Key Skills and Experience • Degree required; legal qualification preferred • Recognised certification in data privacy • 4–7 years’ experience in privacy/data protection (ideally advising on multi-jurisdictional issues) • Strong knowledge of global data protection laws and emerging AI regulation • Experience delivering privacy programmes • Hands-on experience with DPIAs, RoPAs and data subject rights processes • Confidence in use of AI and familiarity with the development of AI governance, risk assessment and regulatory frameworks • Experience handling complex and time sensitive incidents, client facing and internal audits and regulatory enquiries and investigations preferable • Strong analytical, communication and stakeholder management skills • Collaborative, proactive and adaptable approach LI-JC1 #LI-Hybrid Vielfalt, Gleichberechtigung und Integration Um die besten Mitarbeiter zu gewinnen, bemühen wir uns, ein vielfältiges und integratives Umfeld zu schaffen, in dem sich jeder mit seiner ganzen Person in die Arbeit einbringen, sich zugehörig fühlen und sein berufliches Potenzial voll ausschöpfen kann. Unser neues Arbeitsmodell ermöglicht unseren Mitarbeitern mehr Flexibilität; sie können nach Rücksprache mit Manager /Partner und unter Abwägung geschäftlicher Anforderungen entscheiden, ob Sie im Büro oder an einem anderen Standort arbeiten möchten – bei gleichbleibend höchster Qualität Ihrer Dienstleistungen. Wir bieten familienfreundliche und integrative Arbeitsbedingungen und ermöglichen den Zugang zu Programmen und Dienstleistungen, die die Gesundheit und das allgemeine Wohlbefinden unserer Mitarbeiter fördern. Erfahren Sie mehr über Vielfalt, Gleichberechtigung und Integration Wir sind ein Arbeitgeber, der Chancengleichheit praktiziert. Wir können individuelle Anpassungen an unserem Bewerbungsverfahren vornehmen, um Ihnen die besten Erfolgsaussichten zu ermöglichen, indem wir eng mit Ihnen zusammenarbeiten und so ein besseres Verständnis für Ihre Bedürfnisse entwickeln. Bitte kontaktieren Sie unser Recruitment-Team unter EMEARecruitment@nortonrosefulbright.com