Senior Counsel, Privacy and Regulatory
Job description
About the role
Fastly is actively seeking a Senior Counsel to join the legal team and provide strategic guidance on privacy and regulatory matters affecting the company's global operations. The successful candidate will own the development and execution of privacy strategies that align with Fastly's business objectives and technical roadmap. This role requires advising internal stakeholders on compliance with a complex matrix of data protection laws across multiple jurisdictions where Fastly operates. You will be responsible for ensuring that Fastly's products, services, and internal practices are designed and operated in accordance with applicable legal requirements. A core part of this position involves partnering closely with engineering and product teams to embed privacy principles into the fabric of Fastly's offerings from the earliest stages of development. The Senior Counsel will also play a key role in shaping the company's response to regulatory inquiries and investigations. This position demands a proactive approach to identifying emerging risks and translating complex regulatory language into actionable guidance for the business. You will be a critical bridge between the technical infrastructure of the edge cloud and the legal frameworks that govern data privacy.
Key facts
What you'll do
- Conduct in-depth legal analysis and provide clear, practical advice on the application of privacy and data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other global regulatory frameworks impacting Fastly's services.
- Draft, review, and negotiate a wide range of commercial contracts, ensuring that data processing agreements, data protection clauses, and privacy-related terms are robust, compliant, and aligned with Fastly's business needs.
- Develop, implement, and maintain comprehensive privacy policies, notices, and internal procedures to ensure transparency and accountability in Fastly's data processing activities.
- Partner with product managers and engineering teams to integrate privacy-by-design and privacy-by-default principles into new products, features, and infrastructure changes before they are launched.
- Lead or coordinate data protection impact assessments (DPIAs) and other privacy risk evaluations to identify and mitigate potential privacy harms associated with new initiatives.
- Monitor and analyze legislative, regulatory, and enforcement trends in privacy and data security on a global scale, and advise the organization on necessary strategic adjustments and compliance measures.
- Serve as the primary point of contact for responding to regulatory inquiries, investigations, and requests from data protection authorities and other supervisory bodies.
- Manage and coordinate responses to data subject access requests and other privacy-related inquiries from customers, partners, and employees in a timely and compliant manner.
- Investigate and lead the internal response to privacy incidents or potential violations, coordinating with relevant stakeholders to implement remediation and prevent future occurrences.
- Provide training and guidance to cross-functional teams on privacy policies, procedures, and best practices to foster a culture of compliance within the organization.
- Collaborate with security, product, and operations teams to ensure that technical and organizational measures are sufficient to meet privacy and data protection obligations.
- Contribute to the development and maintenance of Fastly's internal privacy governance framework, including oversight of third-party risk management related to data privacy.
Requirements
- Must possess a Juris Doctor (JD) degree from an accredited law school located in the United States or an equivalent qualification recognized in a relevant jurisdiction.
- Must be currently admitted to practice law in at least one US state or possess equivalent legal authorization in another relevant jurisdiction.
- Must have a minimum of 6 years of prior experience practicing privacy law, with a demonstrated history of working either in-house within a corporate environment or at a law firm specializing in technology and privacy matters.
- Must have a deep and practical understanding of major global privacy regulations, including the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Lei Geral de Proteção de Dados (LGPD) in Brazil.
- Must have direct experience advising organizations on privacy issues specific to cloud-based services, software-as-a-service (SaaS) models, or internet infrastructure and content delivery networks.
- Must be able to analyze complex technical documentation and translate legal requirements into concrete instructions for technical teams.
- Must have strong written and oral communication skills, with the ability to articulate nuanced legal concepts to both specialized and non-specialized audiences.
- Must demonstrate sound judgment and the ability to manage multiple priorities in a fast-paced, dynamic, and growing technology company.
Nice to have
- Possession of CIPP/US or CIPP/E certification is viewed as a preferred qualification for this role.
- Prior experience addressing privacy implications specific to artificial intelligence (AI) and machine learning (ML) systems is considered a beneficial asset.
Practical notes
This position offers competitive benefits as part of a comprehensive compensation package. Fastly is committed to supporting a hybrid work model that allows for flexibility in how and where team members choose to work. The role is based in one of the specified locations but may require travel to other offices or business functions as operational needs dictate. Employment is contingent upon the satisfaction of standard background check and verification requirements.