Description:

Primary Purpose of Organizational Unit
The Institutional Privacy Office engages in a challenging, wide-ranging data and privacy practice that requires knowledge of digital risk and data governance issues. The department consolidates digital risk management and privacy laws to develop, implement, and maintain privacy-focused policies, procedures and guidelines, keeping the University in compliance with Federal, State and International regulations. The department coordinates senior leaders across the academic medical center, including clinical research, clinical care, and information security platforms, as well as knowledge of international privacy laws to assist the institution's global programs. The Institutional Privacy Office partners with information technology professionals who have knowledge of information security and data governance principles to assist in improving the institution's approach to managing digital risk across dispersed units, committees, and systems while also advising institutional leaders on data and privacy issues.

Position Summary:
This position is a 100% remote work arrangement, consistent with System Office policy. UNC Chapel Hill employees are generally required to reside in North Carolina, within a reasonable commuting distance of their assigned duty station.

The Senior Digital Technology Contracts Counsel provides legal advice and transactional support related to data privacy, information security, and technology procurement. The position is responsible for drafting, reviewing, updating, and negotiating data privacy and information security provisions contained in the University's standard terms and conditions and a wide range of technology-related agreements.

Reporting to the Associate Vice Chancellor, Chief Privacy Officer, and Special Counsel, this position supports the University's digital risk, data privacy, information security, data governance, and technology acquisition activities by providing specialized legal advice related to technology licensing, data privacy, and information security provisions contained in University technology agreements. The Senior Digital Technology Contracts Counsel partners closely with the Office of University Counsel, Finance & Operations, Purchasing Services, the Information Security Office, research administration, and other administrative units to ensure appropriate contractual protections for institutional data and information systems.

Responsibilities of the Senior Digital Technology Contracts Counsel include:
  • Draft, review, and negotiate high-value and high-risk data privacy and information security provisions in technology-related agreements, including Software-as-a-Service (SaaS), software licensing agreements, cloud service agreements, software development agreements, non-disclosure and confidentiality agreements, data processing agreements, cybersecurity services, managed services agreements and other complex technology provisions contained in University contracts.
  • Partner with Information Technology Services (ITS), Institutional Privacy Office (IPO), Information Security Office (ISO), the Office of University Counsel, Finance and Operations, Research Administration, and other administrative units to support compliant technology procurement.
  • Assist in developing and maintaining contract templates, negotiation playbooks, and institutional guidance for technology and data-related agreements.
  • Provide training and guidance to University units regarding contracting practices involving data privacy, information security, and technology procurement.
  • Assist with resolution of contractual issues or disputes involving technology vendors.
  • Lead contract and legal review of high-value and high-risk data technology procurement negotiations and escalations to ensure compliance with applicable federal and state laws, regulations, and University policies.
  • Mentor Junior Digital Technology Contracts Counsel position
  • Other duties as assigned.

Minimum Education and Experience Requirements:
Relevant post-baccalaureate degree: relevant undergraduate degree with 7-10 years of related professional experience may be substituted for the advanced degree.

Required Qualifications, Competencies, and Experience
  • Admission to practice law in at least one U.S. jurisdiction. Ability to obtain admission to the North Carolina State Bar within a reasonable time if not already admitted.
  • Experience negotiating technology transactions, commercial contracting, or related practice areas.
  • Experience drafting and negotiating technology-related agreements, including Software-as-a-Service (SaaS) agreements and cloud services agreements.
  • Experience drafting and negotiating non-disclosure agreements and confidentiality provisions.
  • Knowledge of HIPAA, FERPA, the GDPR, NIST, and other data privacy and information security concepts as applied to contract negotiations.

Preferred Qualifications, Competencies, and Experience

  • Seven (7) to ten (10) years of legal experience in technology transactions, privacy, cybersecurity, or related areas.
  • Experience advising public universities, higher education institutions, or other public sector organizations.
  • Experience supporting procurement operations or vendor risk management programs.
  • Working knowledge of cloud computing services, cybersecurity standards, and data processing agreements.
  • Experience developing contract templates, negotiation playbooks, or institutional guidance materials.