About
Our talented and experienced teams grow our customers’ businesses 365 days a year with products that create connections, deliver content, and drive commerce. We produce over 140 annual events, create and deliver content through print and digital channels, and power commerce through our seamlessly integrated in-person and digital platforms and channels.
We are looking for a seasoned Director of Privacy & Compliance to serve as the company's expert on global data privacy and as a trusted partner to our business and commercial teams. Reporting directly to the Deputy General Counsel, this role is the operational owner of our end-to-end privacy program and carries shared accountability for regulatory compliance, legal operations excellence, and commercial contract support.
CORE RESPONSIBILITIES
1. Privacy Program Ownership
- Own and continuously mature the global privacy program, including program strategy, roadmap, and governance framework.
- Manage the full cookie consent management lifecycle using OneTrust including cookie banner configuration, geolocation-based consent logic, template and category management.
- Administer the end-to-end Data Subject Request (DSR) workflow: intake, identity verification, response orchestration, and fulfillment tracking within statutory deadlines across all applicable jurisdictions.
- Lead Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new products, features, third-party integrations, and high-risk processing activities; embed privacy-by-design into the product development lifecycle.
- Advise on privacy considerations for AI and machine learning initiatives, including lawful basis for automated decision-making, data minimization in model training, and compliance with emerging AI regulations (EU AI Act, CCPA/GDPR AI requirements); partner with Product to embed privacy-by-design into AI development
- Draft, negotiate, manage, and maintain Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs) with vendors, partners, and customers.
- Oversee and maintain the company's Records of Processing Activities (RoPA) and ensure accuracy across all business units.
- Manage relationships with Data Protection Authorities (DPAs) and serve as or coordinate with the company's Data Protection Officer (DPO) as applicable.
2. Legal & Regulatory Compliance
- Monitor the global privacy and data protection regulatory landscape; translate emerging requirements (new laws, guidance, enforcement actions) into actionable compliance obligations and internal policy updates.
- Own privacy-related policies, notices, and internal standards — including the external Privacy Notice, Cookie Policy, and internal data handling standards — ensuring they remain accurate and audit-ready.
- Partner with Information Security on data breach response plans, ensuring privacy obligations are embedded in incident response procedures.
- Advise on AI/ML governance from a privacy lens, including requirements under emerging AI regulations.
3. Legal Operations Management
- Directly manage the Legal Operations Manager, setting priorities, driving professional development, and ensuring operational excellence across the legal department.
- Oversee legal operations functions including matter management, outside counsel management, legal spend tracking, contract lifecycle management (CLM) tooling, and legal department reporting.
4. Commercial Contract Support
- Support commercial and enterprise contract negotiations particularly where privacy, data use, or data security provisions are in scope.
- Review, redline, and advise on customer and vendor agreements including MSAs, SaaS agreements, NDAs, and data-related addenda.
- Develop and maintain standard contract templates, playbooks, and fallback positions to accelerate deal cycles.
- Act as a trusted legal partner to Sales, Procurement, and Partnerships teams on time-sensitive commercial matters.
QUALIFICATIONS
Required
- 8+ years of privacy, data protection, or related legal experience, with at least 3 years in a senior or lead privacy role at a global company or top-tier law firm.
- Deep, hands-on expertise with GDPR and at least one other major global privacy regime (CCPA/CPRA, LGPD, PIPL, etc.).
- Hands-on OneTrust experience is required — including cookie banner deployment and configuration, DSR workflow automation, assessment management (PIAs/DPIAs), and vendor risk management modules.
- Track record of drafting and negotiating commercial contracts, data processing agreements, and SCCs.
- Experience managing or mentoring legal professionals; comfort with hybrid IC/manager responsibilities.
- Exceptional written and verbal communication skills — able to distill complex legal and technical concepts for executive and non-legal audiences.
Preferred
- CIPP/E, CIPP/US, CIPM, or equivalent privacy certification.
- Experience with legal operations technology (CLM platforms, e-billing, matter management tools).
- Background in SaaS, technology, or other data-intensive industries.
- Familiarity with AI governance frameworks and emerging AI regulation
- ISO27001 or SOC2 certification experience
About Emerald
At Emerald, we strive to foster a diverse and inclusive community. We actively recruit and champion candidates who bring new perspectives from varied professional backgrounds and experiences, and we are intentional about ensuring a positive hiring experience for everyone. Our job postings don’t contain experience inflation, and most don’t require college degrees. Instead, they’re crafted to focus on outcomes and transferable experiences that are assessed in a structured interview process carried out by trained hiring teams.
COMPENSATION & BENEFITS
Target Compensation: $120,000 - $135,000 plus Bonus eligible
Please note that this range reflects a reasonable estimate of the target compensation for this position. This range may ultimately vary based on a candidate’s qualifications and may be higher where required by applicable law.
We offer a competitive benefits package designed to strengthen our employees’ physical and mental health, including unlimited vacation for exempt employees, flexible working locations, 401(k) plan with a company match, medical/dental/vision coverage with inclusive provisions including transgender services and fertility benefits, parental and caregiver leave, dependent, commuter and FSA benefits, professional development programs like Toastmasters, and mental wellness tools.
If you need accommodation in our application process or have questions about our posted salary range, please email our Talent Acquisition team at [email protected].
Skills Required
- 8+ years of privacy, data protection, or related legal experience
- At least 3 years in a senior or lead privacy role at a global company or top-tier law firm
- Deep, hands-on expertise with GDPR and at least one other major global privacy regime, such as CCPA/CPRA, LGPD, or PIPL
- Hands-on OneTrust experience, including cookie banner deployment and configuration, DSR workflow automation, PIAs/DPIAs, and vendor risk management modules
- Experience drafting and negotiating commercial contracts, data processing agreements, and Standard Contractual Clauses
- Experience managing or mentoring legal professionals
- Exceptional written and verbal communication skills for executive and non-legal audiences
- CIPP/E, CIPP/US, CIPM, or equivalent privacy certification
- Experience with legal operations technology, including CLM platforms, e-billing, or matter management tools
- Background in SaaS, technology, or other data-intensive industries
- Familiarity with AI governance frameworks and emerging AI regulation
- ISO 27001 or SOC 2 certification experience
What We Do
Emerald’s talented and experienced team grows our customers’ businesses 365 days a year through connections, content, and commerce. We expand connections that drive new business opportunities, product discovery, and relationships with over 140 annual events, matchmaking, and lead-gen services. We create content to ensure that our customers are on the cutting edge of their industries and are continually developing their skills. And we power commerce through efficient year-round buying and selling. We do all this by seamlessly integrating in-person and digital platforms and channels. Emerald is immersed in the industries we serve and committed to supporting the communities in which we operate. As true partners, we create experiences that inspire, amaze, and deliver breakthrough results. Emerald has offices in California, Colorado, New York, and New Hampshire, as well as remote employees throughout the US. When you’re part of a team of industry experts, creators, innovators, and advisors, the possibilities for growth are endless. At Emerald, we push beyond business-as-usual to help clients exceed their goals, while accomplishing yours too. If you’re ready to join a dynamic team of creative thinkers at a company that values talent and innovation, explore our options now and consider joining our team. https://careers.emeraldx.com/careers-home








