Director of Privacy & Compliance

Emerald Holding, Inc.
United States
7 days ago
Apply on ats.rippling.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$120,000.0 - $135,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Software as a Service Cyber Security Data Security Data Processing Data Management

Job description

We are looking for a seasoned Director of Privacy & Compliance to serve as the company’s expert on global data privacy and as a trusted partner to our business and commercial teams. Reporting directly to the Deputy General Counsel, this role is the operational owner of our end-to-end privacy program and carries shared accountability for regulatory compliance, legal operations excellence, and commercial contract support., 1. Privacy Program Ownership

  • Own and continuously mature the global privacy program, including program strategy, roadmap, and governance framework.

  • Manage the full cookie consent management lifecycle using OneTrust including cookie banner configuration, geolocation-based consent logic, template and category management.

  • Administer the end-to-end Data Subject Request (DSR) workflow: intake, identity verification, response orchestration, and fulfillment tracking within statutory deadlines across all applicable jurisdictions.

  • Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new products, features, third-party integrations, and high-risk processing activities; embed privacy-by-design into the product development lifecycle.

  • Advise on privacy considerations for AI and machine learning initiatives, including lawful basis for automated decision-making, data minimization in model training, and compliance with emerging AI regulations (EU AI Act, CCPA/GDPR AI requirements); partner with Product to embed privacy-by-design into AI development

  • Draft, negotiate, manage, and maintain Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs) with vendors, partners, and customers.

  • Oversee and maintain the company’s Records of Processing Activities (RoPA) and ensure accuracy across all business units.

  • Manage relationships with Data Protection Authorities (DPAs) and serve as or coordinate with the company’s Data Protection Officer (DPO) as applicable.

  1. Legal & Regulatory Compliance * Monitor the global privacy and data protection regulatory landscape; translate emerging requirements (new laws, guidance, enforcement actions) into actionable compliance obligations and internal policy updates.
  • Own privacy-related policies, notices, and internal standards - including the external Privacy Notice, Cookie Policy, and internal data handling standards - ensuring they remain accurate and audit-ready.

  • Partner with Information Security on data breach response plans, ensuring privacy obligations are embedded in incident response procedures.

  • Advise on AI/ML governance from a privacy lens, including requirements under emerging AI regulations.

  1. Legal Operations Management * Directly manage the Legal Operations Manager, setting priorities, driving professional development, and ensuring operational excellence across the legal department.
  • Oversee legal operations functions including matter management, outside counsel management, legal spend tracking, contract lifecycle management (CLM) tooling, and legal department reporting.
  1. Commercial Contract Support * Support commercial and enterprise contract negotiations particularly where privacy, data use, or data security provisions are in scope.
  • Review, redline, and advise on customer and vendor agreements including MSAs, SaaS agreements, NDAs, and data-related addenda.

  • Develop and maintain standard contract templates, playbooks, and fallback positions to accelerate deal cycles.

  • Act as a trusted legal partner to Sales, Procurement, and Partnerships teams on time-sensitive commercial matters.

Requirements

Required

  • 8+ years of privacy, data protection, or related legal experience, with at least 3 years in a senior or lead privacy role at a global company or top-tier law firm.

  • Deep, hands-on expertise with GDPR and at least one other major global privacy regime (CCPA/CPRA, LGPD, PIPL, etc.).

  • Hands-on OneTrust experience is required - including cookie banner deployment and configuration, DSR workflow automation, assessment management (PIAs/DPIAs), and vendor risk management modules.

  • Track record of drafting and negotiating commercial contracts, data processing agreements, and SCCs.

  • Experience managing or mentoring legal professionals; comfort with hybrid IC/manager responsibilities.

  • Exceptional written and verbal communication skills - able to distill complex legal and technical concepts for executive and non-legal audiences.

Preferred

  • CIPP/E, CIPP/US, CIPM, or equivalent privacy certification.

  • Experience with legal operations technology (CLM platforms, e-billing, matter management tools).

  • Background in SaaS, technology, or other data-intensive industries.

  • Familiarity with AI governance frameworks and emerging AI regulation

  • ISO27001 or SOC2 certification experience

Benefits & conditions

We offer a competitive benefits package designed to strengthen our employees’ physical and mental health, including unlimited vacation for exempt employees, flexible working locations, 401(k) plan with a company match, medical/dental/vision coverage with inclusive provisions including transgender services and fertility benefits, parental and caregiver leave, dependent, commuter and FSA benefits, professional development programs like Toastmasters, and mental wellness tools.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on ats.rippling.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 ¡ World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

2:10 min

Defining stream data processing versus standard event processing

Soroosh Khodami Soroosh Khodami ¡ World Congress 2024

1:47 min

Navigating regulatory compliance and data sovereignty in enterprise AI

Florian Deter Florian Deter +4 ¡ World Congress 2026 Europe

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 ¡ LIVE

3:10 min

Balancing rapid artificial intelligence development with strict compliance regulations

Videos

See all

Related articles

See all