As part of Nokia's Legal job family, this role sits within the Global Privacy, Data and Cyber Regulatory Office (GPDCRO) — Nokia's centre of excellence for data protection, cybersecurity regulation, and emerging data-related law — reporting to the Head of Privacy and Data Trust. It applies deep specialist expertise across data protection, cybersecurity law, AI governance, commercial contracting, and incident response, acting as the primary legal interface between Nokia's European and UK business operations and the rapidly evolving regulatory landscape.
This is an AI-first legal team. We actively build and use AI-assisted workflows — from agentic legal research to automated regulatory horizon scanning — and expect everyone in the team to engage seriously with what AI can do for legal work. The role works alongside counterparts covering the Americas, Middle East and Africa, and Asia Pacific, with genuine opportunity to collaborate on cross-jurisdictional matters. If you are excited by building the legal function of the future rather than maintaining the legal function of the past, you will fit in here.
- Provide expert legal advice across the full EU and UK data protection and cybersecurity regulatory landscape, including GDPR, UK GDPR/DPA 2018, NIS2, the EU Cyber Resilience Act, the EU Data Act, the EU AI Act, and applicable national implementing legislation.
- Lead Nokia's legal engagement with the Cyber Resilience Act, including the legal track for open-source software obligations in network products, conformity requirements, and evolving delegated acts.
- Own the legal workstream for Nokia's supplier security documentation, including the modular security appendix applied across Nokia's global supply chain.
- Advise on privacy and cybersecurity requirements in customer contracts and procurement processes, including data processing agreements, security appendices, and data localisation requirements.
- Conduct horizon scanning across EU and UK regulatory developments, triaging legal risk and preparing clear, actionable briefings for senior stakeholders and governance forums.
- Lead legal review of Nokia's use of regulated data types — telecom subscriber data, network data, employee data — advising on permissible use cases, anonymisation standards, and access controls.
- Conduct and review Data Protection Impact Assessments for high-risk processing activities, including AI-driven use cases and network analytics.
- Actively identify opportunities to move Nokia's compliance posture from paper-based to demonstrable — working with engineering, security, and data teams to embed legal requirements as technical controls into systems and workflows. In practice: data minimisation enforced at the API layer, purpose restrictions implemented as access controls, anonymisation validated against re-identification risk rather than assumed.
- Play a central role in cyber and privacy incident response — making timely, legally sound decisions on notification obligations under NIS2, GDPR Articles 33/34, and applicable national legislation, and maintaining Nokia's incident response legal playbook.
- Provide privacy, data use, and cyber law input into Nokia's AI governance programme and internal AI deployment — ensuring legal requirements are embedded at design stage.
- Deliver training and legal briefings to internal teams, leveraging AI tools to create scalable, repeatable guidance — building legal capability across the organisation rather than creating dependency on the legal team.
- Manage external legal counsel on EU and UK matters, with accountability for scope, quality, and cost.
- Build trusted, collaborative relationships across Information Security, Product Security, Procurement, Business Groups, CTO, and Human Resources — acting as a proactive legal partner and handling matters end-to-end, enabling the Head of Privacy and Data Trust to focus on global strategy and executive engagement.
Skills and experience
We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.
Must Have
- Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
- Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
- Substantive familiarity with EU cybersecurity regulation — particularly the Cyber Resilience Act, NIS2, and the EU AI Act — and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
- Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer — you do need to be genuinely interested in how the technology works.
- A working familiarity with AI tools — including large language models and agentic workflows — and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
- Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
- Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships — able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
- Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
- Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
- Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.
Nice to Have
- Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
- Experience designing modular contractual frameworks — such as security appendices or DPA templates — applied across a global supply chain.
- Experience with privacy management platforms such as OneTrust.
- A relevant qualification — CIPP/E, CIPM, or equivalent — is desirable but not essential; we are more interested in demonstrated capability than credentials.
- External visibility or a professional network in EU/UK data protection or cybersecurity law.
Skills Required
- Qualified lawyer admitted to practice in at least one EU member state or in England and Wales
- Minimum 10 years of post-qualification experience in data protection, cybersecurity law, or a related technology law specialization
- Hands-on knowledge of GDPR and UK GDPR, including multinational compliance programs, incident response, and supervisory authority engagement
- Substantive familiarity with the Cyber Resilience Act, NIS2, and EU AI Act
- Ability to engage with engineers and architects and identify legal risks in technically complex environments
- Working familiarity with AI tools, large language models, and agentic workflows
- Experience advising on privacy, security, and AI clauses in commercial, supplier, and customer data processing agreements
- Strong commercial awareness and ability to frame legal risk for commercial and operational audiences
- Ability to independently manage a varied, high-volume portfolio and prioritize by materiality
- Legal incident and crisis response experience, including NIS2 and GDPR notification obligations and privilege management
- Excellent written and spoken English
- Experience in telecommunications, technology, or critical infrastructure
- Experience designing modular contractual frameworks for global supply chains
- Experience with privacy management platforms such as OneTrust
- CIPP/E, CIPM, or equivalent qualification
- External visibility or professional network in EU or UK data protection or cybersecurity law
Nokia Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Nokia and has not been reviewed or approved by Nokia.
-
Equity Value & Accessibility — Equity programs include a global employee share purchase plan with company matching and multi‑year share awards. These mechanisms broaden participation and tie rewards to long‑term outcomes.
-
Healthcare Strength — Health coverage includes major medical plans with supplementary options such as vision, legal services, and care navigation. The range of offerings indicates comprehensive support for medical needs.
-
Parental & Family Support — A global policy grants paid leave for new parents regardless of gender and provides structured return‑to‑work support. Company‑paid life insurance further strengthens family protection across regions.
Nokia Insights
What We Do
At Nokia, we create technology that helps the world act together. As a trusted partner for critical networks, we are committed to innovation and technology leadership across mobile, fixed and cloud networks. We create value with intellectual property and long-term research, led by the award-winning Nokia Bell Labs. Adhering to the highest standards of integrity and security, we help build the capabilities needed for a more productive, sustainable and inclusive world.








