Live opening · Posted 2 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Privacy & Product Counsel | AI | Global Role
UK-based & Remote-first (No Sponsorship Offered) | £100K - £115,000 + equity
I’m working with a well-backed, San Francisco-headquartered AI company to hire its first dedicated Privacy & Product Counsel.
You’ll build the privacy programme, work directly with product and engineering on how agentic AI systems use data, negotiate with major enterprise customers, and become the internal authority on privacy across the US, UK and Europe.
It’s a great and rare opportunity.
The company moves extremely quickly, operates across US and European time zones, and wants someone who actively enjoys that, and wants to build in a frontier environment. The role is remote-first in the UK, there will be occasions where you need to cover US hours, or travel for customer meetings.
If you want clearly defined boundaries, a large legal team around you and, a more traditional 9–5 working pattern, this isn’t the right role.
If you want to build something, value equity, work very closely with a founding team, a great GC, and have significant influence over how a frontier AI product develops, this is the role for you.
The role
The core of the position is privacy.
You’ll own the privacy programme across a business whose technology processes significant volumes of consumer data within major enterprise environments.
That means:
Building and running the privacy programme from the ground up: data mapping, policies, retention, vendor and subprocessor management.
Advising product and engineering on privacy-by-design for agentic AI systems — including what an agent can access, retain, infer and act upon.
Owning the company's approach to GDPR, UK GDPR, CCPA/CPRA and the wider US state privacy landscape.
Keeping ahead of developing AI regulation across the US, UK and EU.
Building scalable approaches to DPAs, SCCs, the UK IDTA/Addendum and international data transfers.
Working with security on incident response, breach notification and customer-facing security commitments.
Acting as a senior privacy SME with enterprise customers who want to understand exactly how their information is being handled.
There is also a meaningful product and commercial counsel element.
You’ll negotiate enterprise agreements, DPAs and security schedules and work closely with the commercial team to get deals completed without making commitments the product cannot support.
And because this is a startup, occasionally something will land on your desk that does not fit neatly inside the job description.
You need to be comfortable picking it up.
They do not want a generalist with a bit of privacy experience, though. Privacy expertise is the foundation of the hire.
Who they are looking for
The sweet spot is likely someone around 6 - 8 years' PQE mark, but we’re more looking for the right kind of person and attitude to the challenge. Do not let the PQE mark above put you off applying, if you feel you would thrive in this enviroment.
The most important requirement is genuine depth across European privacy law.
You therefore need to be genuinely comfortable across:
EU GDPR / UK GDPR / DPA 2018 + CCPA/CPRA and US state privacy laws.
Beyond that, the strongest candidates are likely to have:
Worked in-house in a technology, data-heavy or AI business.
Sat alongside product and engineering teams rather than operating purely as an advisory function.
Negotiated enterprise DPAs, security schedules and international transfer arrangements.
Experience dealing directly with sophisticated customer legal, procurement and security teams.
Enough commercial breadth to help outside the privacy lane when required.
The confidence to make decisions where there may not yet be a perfect regulatory answer.
Your training route is much less important than what you have actually done and why.
Someone who deliberately moved into privacy, built genuine subject-matter expertise and can explain the thinking behind their career decisions will be taken seriously.
The working environment
They want someone with a “let’s build it and get moving” mentality.
You will not inherit a mature privacy department with established processes for everything. Some things will need to be built manually, some automated quickly, and some solved pragmatically.
The company wants rigour, but not bureaucracy for its own sake.
You will work closely with founders, engineering, product and commercial leadership. The role is customer-facing and you will be involved in areas such as board-level privacy and risk reporting.
The business is operating at the sharp end of AI and machine learning, working with very large datasets and sophisticated and high profile enterprise customers.
For somebody who genuinely wants to build their career around privacy + AI + product, there is significant scope here.
Compensation
The UK salary banding is £100K - £115K, depending on experience + Bonus & Equity from day one.
Interview process (After an in-depth call with the recruiter)
Stage one: an initial conversation focused on your background, motivations and relevant experience with the GC.
Stage two: conversation with a Co-Founder, with a significant focus on fit, ambition and how you operate in a startup environment.
Neither stage is intended to become an academic privacy-law examination.
They will want to understand whether you genuinely know your subject, but they are equally interested in how you communicate, why you have made the career decisions you have made, and why you want this particular type of role now.
They also need somebody who can move relatively quickly. A long notice period is likely to be difficult for this search.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.