Privacy Counsel – Retail/E-commerce
About the Company
Our client is a leading global technology-driven supply chain, logistics and e-commerce platform, operating across Europe, the Americas, the Middle East and Asia.
The company is listed on NASDAQ and ranked among the Fortune Global 500, serving hundreds of millions of customers worldwide. As part of its long-term international growth strategy, the business continues to make significant investments across Europe and is rapidly expanding its e-commerce, retail, technology and supply chain capabilities across the region.
The company has established teams across the UK, the Netherlands, Germany, France, Spain and other European markets, with continued expansion planned across the region.
The Opportunity
This is a newly created and highly visible Privacy Counsel position supporting the company’s rapidly expanding UK and European operations.
Based in London, the role will act as a senior legal adviser on UK and EU data protection, privacy and digital regulation, supporting the development and launch of customer-facing products, e-commerce services, digital platforms, marketing initiatives and internal technology solutions.
The successful candidate will work closely with legal, compliance, technology, product, cybersecurity, marketing, HR, commercial and operational teams. The role offers significant scope to shape the company’s European privacy framework and embed practical, scalable privacy controls into a fast-growing international business.
Key Responsibilities
- Provide practical legal advice on the UK GDPR, EU GDPR, Data Protection Act 2018, PECR, ePrivacy requirements and related UK and European digital regulation.
- Serve as a key privacy adviser for the development and launch of e-commerce platforms, customer-facing products, mobile applications, digital services and internal technology solutions.
- Embed privacy by design and by default throughout the product development lifecycle, advising product, technology and business teams from initial concept through launch and ongoing operation.
- Conduct and oversee Data Protection Impact Assessments (DPIAs), Legitimate Interests Assessments (LIAs), privacy risk reviews and related compliance documentation.
- Advise on the lawful collection, use, sharing, retention and deletion of customer, seller, employee, supplier and business-partner data.
- Review and negotiate data-processing agreements, data-sharing agreements, controller arrangements, technology agreements and privacy provisions in commercial contracts.
- Advise on international data transfers, including Standard Contractual Clauses, UK International Data Transfer Agreements, Transfer Risk Assessments and supplementary safeguards.
- Support privacy compliance relating to digital marketing, cookies, tracking technologies, online advertising, customer profiling, personalisation and consent management.
- Advise on the use of artificial intelligence, automated decision-making, analytics and emerging technologies, including their implications for data protection and digital regulation.
- Develop, maintain and improve the company’s European privacy framework, including policies, procedures, guidance, governance structures and accountability records.
- Support the maintenance of Records of Processing Activities (RoPAs), data-retention standards, privacy notices and internal privacy controls.
- Advise on the management of data-subject rights requests, including access, deletion, objection, restriction, portability and automated decision-making requests.
- Work closely with cybersecurity and operational teams on personal data breaches, incident response, investigations, remediation and regulatory notification requirements.
- Support engagement with the Information Commissioner’s Office (ICO) and other UK or European data protection authorities, including regulatory enquiries, investigations and audits.
- Monitor developments in UK and European privacy, AI and digital regulation, translating new legal requirements into practical business actions.
- Design and deliver privacy training for legal, product, technology, marketing, HR, commercial and operational stakeholders.
- Help build a consistent and scalable privacy model that can support continued expansion across multiple European markets.
Ideal Background
- Approximately 5 –12 years of relevant legal experience, with strong expertise in UK and European privacy and data protection law.
- Qualified solicitor in England and Wales, another UK jurisdiction or an EU member state. Other relevant legal qualifications may also be considered depending on experience.
- Strong working knowledge of the UK GDPR, EU GDPR, Data Protection Act 2018, PECR, ePrivacy rules and international data-transfer requirements.
- Experience advising a technology company, e-commerce platform, online marketplace, retailer, consumer-facing digital business, telecommunications company or similarly data-intensive organisation.
- Demonstrable experience supporting digital products and technology launches, applying privacy-by-design principles and translating complex legal requirements into practical solutions.
- Hands-on experience with DPIAs, LIAs, RoPAs, privacy notices, data-retention frameworks, data-subject rights and personal data breaches.
- Experience reviewing and negotiating data-processing, data-sharing, technology, SaaS and cross-border transfer agreements.
- Practical knowledge of privacy issues relating to cookies, digital advertising, direct marketing, profiling, analytics and consent management.
- Familiarity with privacy and governance considerations arising from AI, machine learning, automated decision-making and emerging technologies would be advantageous.
- Experience engaging with the ICO or other European data protection authorities would be highly valued.
- A combination of leading law firm and in-house experience is preferred, although candidates with strong relevant experience from either environment will be considered.
- Comfortable operating as a senior individual contributor, influencing senior stakeholders and cross-functional teams without relying on direct line-management authority.
- Commercial, pragmatic and able to provide clear, risk-based advice in a fast-moving and evolving business environment.
- Excellent written and spoken English. Additional European language skills would be an advantage.
Why Consider This Opportunity
- Join a NASDAQ-listed Fortune Global 500 organisation during a major phase of European expansion.
- Take a leading role in shaping the company’s UK and European privacy framework.
- Advise on innovative e-commerce, digital platform, technology and AI-enabled products.
- Work closely with senior legal, compliance, product, technology, cybersecurity and business stakeholders.
- Build scalable privacy processes for a business expanding across multiple European markets.
- Join a newly developing European legal and compliance organisation with meaningful opportunity to influence its future operating model.
Location
London, United Kingdom
Compensation
The compensation package is highly competitive and will be tailored to the successful candidate’s experience and seniority.