Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm\’s work is distinguished by a unique combination of precision and vision.
Based in our London, Brussels, or Paris office, the Privacy Counsel will play a key role in all ongoing activities related to the development, implementation, maintenance of, and adherence to the Firm\’s privacy programme covering the protection of personal data in compliance with US federal and state, E.U., U.K., and other applicable privacy laws.
The Privacy Counsel will be a member of the Firm\’s Office of General Counsel (\”
OGC
\”) and will report to the Firm\’s Compliance Officer & Assistant General Counsel (\”
CO
\”). The Privacy Counsel will assist (and where requested or as required, deputize for) the CO in relation to all aspects of the continued operation and evolution of the Firm\’s privacy programme.
Responsibilities include:
- Assist and collaborate with the CO in the identification, implementation, and maintenance of organizational privacy/data protection policies, procedures, and all other aspects of the Firm\’s privacy programme, in coordination with the Firm\’s management and OGC.
- Support the activities of relevant committees, including, without limitation, the Firm\’s Cyber and Data Governance Committee and Artificial Intelligence (AI) and Technology Strategy Discussion group.
- Perform PRAs, DPIAs and other related compliance monitoring and risk assessment activities, in coordination as needed or appropriate with the Firm\’s other compliance and operational assessment functions.
- Work with relevant internal stakeholders to maintain appropriate privacy statements reflecting current organization and legal practices and requirements.
- Assist the CO in developing, overseeing, directing, delivering, or ensuring delivery of privacy training to all attorneys and professional staff, and others as needed or desired, on a cadence to be determined by the CO and/or other stakeholders.
- Participate in compliance monitoring and/or audits of, and/or attestation/verification activities with respect to, personal data processing practices of. and contractual compliance by, higher-risk Firm subcontractors, vendors, and other third parties who process personal data at the direction of or on behalf of the Firm.
- Assist with receiving, documenting, tracking, investigating and acting on all requests, queries, and complaints concerning the Firm\’s handling of personal data and/or the Firm\’s privacy-related policies, procedures, and practices (including data subject requests), in coordination and collaboration with other functions, any locally appointed data protection officers, and, when necessary, the OGC.
- Initiate, facilitate and promote activities to foster information privacy awareness and privacy by design/default within the Firm.
- Stay abreast of developments in applicable data protection / privacy laws, accreditation standards, and privacy enhancing technologies, and recommend any actions the Firm should take in response.
- Serve as the Firm\’s statutory privacy officer, data protection officer, or equivalent as required, and act as the Firm\’s primary point of contact and liaison for the relevant data protection authorities (excluding cases where another individual is appointed as a local statutory data protection officer, in which case, the Privacy Counsel will be available to advise, assist, and coordinate as needed).
- Assist with reviewing, and/or train others to perform reviews of, data protection clauses, data processing agreements, and related issues presented in client agreements on behalf of the Firm, and Firm vendor contracts.
- Collaborate with other of the Firm\’s professional services function(s) to maintain a personal data processing catalog (including an Article 30 register).
- Assisting with the investigation, containment, remediation, regulatory notification, and all other related activities pertaining to any data incident involving the unauthorized release of, or access to, personal data, including internal investigations and privacy impact assessments.
- Assist and collaborate with the Firm\’s information security, information services, data governance, and other functions in identifying and pursuing opportunities to improve the resilience and sustainability of the Firm\’s data-handling practices in general.
Qualifications:
Technical Skills
A successful candidate will have the following technical skills and experience:
- Strong understanding of how EU/UK GDPR is interpreted / applied / enforced in practice in the context of a global business, coupled with an understanding (or aptitude to develop such an understanding) of privacy laws of the USA, Middle East, and Asia.
- Experience working with or advising on privacy laws of one or more of the following jurisdictions preferred: USA, Hong Kong, Singapore, ADGM, DIFC, Saudi Arabia, PRC.
- Experience drafting and negotiating privacy-specific agreements such as data processing/
Contact Detail:
Gibson Dunn Recruiting Team