Senior Data Privacy & AI Lawyer / Senior Data Privacy & AI Manager
Practice Group / Department:Head of Regulatory Risk, General Counsel & RiskJob DescriptionNorton Rose Fulbright is a global law firm with more than 3,000 lawyers advising clients across locations in the United States, Europe, Canada, Latin America, Asia, Australia, Africa and the Middle East. We provide the world's preeminent corporations and financial institutions with a full business law service. With over 50 offices and 7,000 employees worldwide, our culture is the thread that connects us, as well as our values of unity, quality and integrity. Our strategy and culture are connected – defined by shared ambition, global collaboration and a one-team mindset. We believe pioneering work happens when people are empowered to think beyond boundaries, explore new opportunities and grow through diverse experiences. Alongside the right skills and experience, we look for people who are innovative, commercially minded, and motivated by the impact of the work they do – ready to share in our ambition and help shape what comes next. Because while individuals can do well, together we achieve something extraordinary.The TeamPart of the Regulatory Risk team within the General Counsel & Risk function, working closely with the Data Protection Officer (DPO) and Legal Transformation and Technology teams, collaborating with GC & Risk colleagues and wider legal and business services teams to deliver a coordinated approach to privacy and AI governance across the firm’s operations in Europe, Middle East, Asia and the Pacific (EMEAPAC).The RoleWe are seeking a senior in-house privacy professional to work within the Regulatory Risk team of our General Counsel & Risk function. The individual will work with the Head of Regulatory alongside our Data Protection Officer (DPO) to deliver and embed the firm’s data protection compliance frameworks across its Europe, Middle East, Asia and the Pacific (EMEAPAC) region. In equal measure, the individual will engage with key stakeholders and senior management to drive the firm’s AI strategy across EMEAPAC, while also ensuring development of, and adherence with, the firm’s governance strategy, legal, regulatory and client requirements and risk management processes. The individual will act as a key adviser and operational lead, helping to ensure the firm meets its obligations under applicable data protection and emerging AI regulation in EMEAPAC, by maintaining a consistent compliance framework tailored to local legal requirements.Key Responsibilities Support the execution and continuous improvement of the privacy and AI governance programmeMonitor and interpret global data protection and AI regulatory developments (including the EU AI Act)Develop and maintain policies, frameworks and governance standardsManage core operational processes (e.g. RoPAs, DPIAs, DSARs, etc)Embed Privacy by Design and oversee AI risk and impact assessmentsProvide clear, practical advice to business and technical teamsDeliver...