To provide expert legal counsel to the Glory group on all data and technology matters, supporting the Group General Counsel – Data and Technology, Group DPO and AI Officer, and external advisers to enable top-line growth and bottom-line efficiencies. The role focuses on data protection and privacy, artificial intelligence governance and compliance, and software, SaaS and technology contracting, helping the business to innovate and grow while identifying and managing the associated legal risks. The role is also responsible for developing, implementing and maintaining data protection, AI governance and technology-use policies, standards and training; advising cross-functional teams on privacy-by-design and the responsible use of technology and AI; and helping to embed a strong culture of data protection and technology compliance across the Group. Key Responsibilities Managing drafting, evaluation & negotiation through to execution of a variety of commercial agreements, review of customer proposed terms and conditions working closely with the commercial teams and Group General Counsel – Data and Technology, Group DPO and AI Officer to provide comprehensive legal support across the region. Perform data protection and technology-related risk assessments, including Data Protection Impact Assessments (DPIAs) and legitimate interest assessments, to ensure compliance with applicable data protection and technology laws. Monitor developments in data protection, privacy, AI and technology law (including the UK GDPR, the EU GDPR and the EU AI Act) and advise management of necessary compliance measures. Develop, implement and review data protection, AI governance and technology-use policies and procedures to ensure compliance with relevant laws and standards. Liaise with relevant supervisory authorities and external advisers on data protection and technology matters. Exercise oversight over data governance, information security and AI governance, risk and control arrangements, working closely with the Group Data Protection Officer and AI Officer and information security teams. Provide training to staff on data protection, privacy and the responsible use of technology and AI. Monitor adherence to data protection and technology policies across the business to identify areas of recurrent risk or friction and opportunities for improvement. General support including compiling and distributing a variety of high-level reports, both internally and externally. Handle on-going commercial issues and change management, monitor transaction compliance (milestones, deliverables, invoicing etc) and support contract close-out, extension or renewal. Software and data focus is a large part of the role and a candidate will be expected to have SaaS, IaaS and general licensing experience. Support Data Protection matters (GDPR standard) across the Group to ensure robust compliance. Support on data protection and privacy compliance across the Group, including the UK GDPR and EU GDPR, data subject requests, records of processing, international data transfers and personal data breach response. Advise on the governance and responsible deployment of artificial intelligence, including AI risk assessments, model and vendor due diligence, and compliance with emerging AI regulation such as the EU AI Act. Draft, review and negotiate technology and data agreements, including SaaS, IaaS, cloud, software licensing, data processing agreements (DPAs), reseller and professional services agreements. Support information security and cyber-resilience initiatives from a legal perspective, including incident response, acting as legal liaison to the information security team. Skills, Knowledge & Expertise Excellent knowledge of data protection and privacy laws (UK GDPR / EU GDPR), as well as EU AI Act and a strong working understanding of technology and software licensing. Excellent written and spoken communication skills, proven ability to manage external counsel and internal clients. Strong legal and commercial awareness and the ability to deal with problems in a pragmatic and logical way. Have a broad understanding of all aspects of commercial law, and compliance experience. Excellent written and spoken communication skills. Strong commercial awareness and the ability to deal with problems in a pragmatic and logical way. Ability to take responsibility and act autonomously including an ability to take difficult decisions and provide substantiated arguments. Licensed lawyer with a minimum of 3 years’ PQE from major firms / brands and relevant in-house experience, ideally with a focus on data protection and/or technology law. Practical experience advising on data protection compliance, including DPIAs, data subject requests, international data transfers and personal data breach management. Familiarity with AI governance frameworks and emerging AI regulation (e.g. the EU AI Act). Experience drafting and negotiating SaaS, IaaS, cloud and software licensing agreements and data processing agreements. Awareness of information security standards and their legal implications (e.g. ISO 27001). Job Benefits This role offers 50% hybrid working.
Global Project Manager - Data/Technology
Havas
Sr Legal Counsel, EMEA Privacy
Dexcom
Transport Planner
Brenntag
DevOps Engineer
Kyndryl
AI Systems Architect
Kyndryl
Lead Integration Architect
Tecdata Engineering