Description:
Job Description:Essential Functions:
- Advise clients on website tracking technologies and digital marketing compliance in the U.S. and internationally, including pixels, cookies, session replay, and ad tech vendors; consent management platform configuration; opt-out mechanisms (including Global Privacy Control); and related exposure under the CCPA, state wiretapping laws (e.g., CIPA), the VPPA, and analogous state privacy statutes, as well as GDPR and ePrivacy requirements for international properties.
- Counsel employers on employee monitoring solutions, including telematics and dashcam programs, GPS tracking, productivity and communications monitoring, and workplace surveillance notice requirements under state and federal law.
- Advise on biometric data collection and processing—timekeeping, facial recognition, driver-facing cameras, and similar technologies—under BIPA and other state biometric privacy or electronic monitoring laws, including consent, retention, and vendor management requirements.
- Guide clients through data breach preparedness and incident response, including analysis under state and federal breach notification laws, coordination with forensic vendors, notification strategy, and post-incident remediation.
- Negotiate MSAs, data processing agreements, and privacy and security terms in vendor and service agreements, including independent contractor and staffing arrangements.
- Advise on international data transfers, including standard contractual clauses, the EU-U.S. Data Privacy Framework, transfer impact assessments, and cross-border HR data flows.
- Build and maintain CCPA compliance programs for employers, including HR data compliance (notices at collection, DSAR response processes for employees and applicants, data inventories and retention schedules), sale/share analysis for tracking technologies, and opt-out implementation.
- Counsel on emerging workplace technology issues, including AI-enabled hiring and monitoring tools and related state and local automated decision-making laws, background check and applicant data compliance, and employee health and safety data handling.
- Prepare client-facing deliverables, including privileged compliance assessments, remediation roadmaps, policies and notices, and training materials.
Requirements:
- J.D. and active bar membership in good standing.
- 3+ years of experience in privacy and data security counseling, ideally with employment law exposure.
- Working knowledge of the CCPA and other state comprehensive privacy laws, BIPA, state breach notification statutes, and GDPR.
- Comfort with the technical side of the practice—reading network traffic or tag manager configurations, evaluating tracking technology implementations, and translating technical findings into legal analysis and IT-actionable recommendations—or a demonstrated aptitude and interest in developing it.
- CIPP/US, CIPP/E, or similar certification a plus.
- Strong drafting skills and the ability to manage multiple client engagements independently.