Description:

Job Summary:
Compass Group USA is seeking a qualified attorney to serve as Privacy Counsel within our Legal & Compliance team. This role will provide legal guidance on privacy and data protection matters, ensuring compliance with applicable state privacy laws governing the collection, processing, and use of employee/associate personal information. The ideal candidate will have experience advising diverse business units and navigating complex regulatory environments.

Responsibilities:
Regulatory Compliance:
  • Monitor and interpret state privacy and Artificial Intelligence laws (e.g., CCPA, CPRA, VCDPA, and similar) impacting employee personal information.
  • Advise business units on compliance obligations related to personal information collection, processing, and sharing.
  • Help build and maintain strong privacy controls and systems to maintain privacy compliance.
  • Manage the company DSAR process and tooling.

Policy Development & Implementation:
  • Draft, review, and maintain privacy policies, notices, and consent mechanisms across websites and mobile applications.
  • Embed privacy-by-design principles into marketing and technology initiatives and applications purchased and created by the company.

Risk Management:
  • Conduct Privacy Impact Assessments (PIAs) and maintain Records of Processing Activities (RoPA).
  • Support incident response and breach management in collaboration with IT and cybersecurity teams.

Training & Awareness:
  • Deliver privacy training to human resources, talent acquisition, benefits, and other teams, and educate the company around core privacy principles.
  • Promote a culture of compliance across diverse business units.

Qualifications:
Education & Experience:
  • A JD from an accredited US law school.
  • Minimum 3–5 years of experience advising US entities on topics of privacy, data protection, or similar compliance roles at a company governed by state and federal US privacy laws.

Privacy Expertise:
  • Required: Strong knowledge of U.S. state privacy laws.
  • Preferred: Experience with HIPAA compliance.
  • CIPP/US, CIPM, or similar privacy certification.

Skills:
  • Excellent analytical, communication, and project management skills.
  • The ability to translate complex privacy laws into business-applicable advice and controls.
  • Ability to work in fast-paced environments with diverse industry exposure.