Description:

Job Description:
Essential Functions:
  • Advise clients on website tracking technologies and digital marketing compliance in the U.S. and internationally, including pixels, cookies, session replay, and ad tech vendors; consent management platform configuration; opt-out mechanisms (including Global Privacy Control); and related exposure under the CCPA, state wiretapping laws (e.g., CIPA), the VPPA, and analogous state privacy statutes, as well as GDPR and ePrivacy requirements for international properties.
  • Counsel employers on employee monitoring solutions, including telematics and dashcam programs, GPS tracking, productivity and communications monitoring, and workplace surveillance notice requirements under state and federal law.
  • Advise on biometric data collection and processing—timekeeping, facial recognition, driver-facing cameras, and similar technologies—under BIPA and other state biometric privacy or electronic monitoring laws, including consent, retention, and vendor management requirements.
  • Guide clients through data breach preparedness and incident response, including analysis under state and federal breach notification laws, coordination with forensic vendors, notification strategy, and post-incident remediation.
  • Negotiate MSAs, data processing agreements, and privacy and security terms in vendor and service agreements, including independent contractor and staffing arrangements.
  • Advise on international data transfers, including standard contractual clauses, the EU-U.S. Data Privacy Framework, transfer impact assessments, and cross-border HR data flows.
  • Build and maintain CCPA compliance programs for employers, including HR data compliance (notices at collection, DSAR response processes for employees and applicants, data inventories and retention schedules), sale/share analysis for tracking technologies, and opt-out implementation.
  • Counsel on emerging workplace technology issues, including AI-enabled hiring and monitoring tools and related state and local automated decision-making laws, background check and applicant data compliance, and employee health and safety data handling.
  • Prepare client-facing deliverables, including privileged compliance assessments, remediation roadmaps, policies and notices, and training materials.

Requirements:
  • J.D. and active bar membership in good standing.
  • 3+ years of experience in privacy and data security counseling, ideally with employment law exposure.
  • Working knowledge of the CCPA and other state comprehensive privacy laws, BIPA, state breach notification statutes, and GDPR.
  • Comfort with the technical side of the practice—reading network traffic or tag manager configurations, evaluating tracking technology implementations, and translating technical findings into legal analysis and IT-actionable recommendations—or a demonstrated aptitude and interest in developing it.
  • CIPP/US, CIPP/E, or similar certification a plus.
  • Strong drafting skills and the ability to manage multiple client engagements independently.

Please note, we are not working with outside recruiters for this position.