Privacy, Data & Cyber Regulatory Counsel

Nokia

Espoo

On-site

EUR 120,000 - 180,000

Full time

12 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Nokia is seeking an experienced lawyer to join the GPDCRO team in a role that spans EU/UK data protection, cybersecurity regulation, and AI governance. You will advise on privacy and security matters, interface with engineering and procurement, and help embed legal requirements into technical controls across the Nokia ecosystem.

This AI-first legal team emphasizes scalable, AI-assisted workflows, cross‑jurisdictional collaboration, and proactive legal risk management to shape Nokia's privacy and

Qualifications

  • Must have extensive post-qualification experience in data protection, cybersecurity or technology law.
  • Strong knowledge of GDPR/UK GDPR and related regulatory regimes.
  • Experience advising on privacy, security and AI clauses in commercial contracts.
  • Able to translate complex regulatory requirements to technical and commercial audiences.
  • Excellent written and verbal English with stakeholder influencing skills.

Responsibilities

  • Provide expert legal advice across EU and UK data protection and cybersecurity regulations including GDPR, UK GDPR/DPA 2018, NIS2, EU AI Act.
  • Lead Nokia's legal engagement with cyber resilience and open‑source software obligations for network products.
  • Own the supplier security documentation workstream and data processing agreements.
  • Advise on privacy, data use, and cyber law in customer contracts and procurement processes.
  • Conduct horizon scanning and prepare concise briefings for senior leadership.

Job description

Job Description As part of Nokia's Legal job family, this role sits within the Global Privacy, Data and Cyber Regulatory Office (GPDCRO) — Nokia's centre of excellence for data protection, cybersecurity regulation, and emerging data-related law — reporting to the Head of Privacy and Data Trust. It applies deep specialist expertise across data protection, cybersecurity law, AI governance, commercial contracting, and incident response, acting as the primary legal interface between Nokia's European and UK business operations and the rapidly evolving regulatory landscape.

Job Description As part of Nokia's Legal job family, this role sits within the Global Privacy, Data and Cyber Regulatory Office (GPDCRO) — Nokia's centre of excellence for data protection, cybersecurity regulation, and emerging data-related law — reporting to the Head of Privacy and Data Trust. It applies deep specialist expertise across data protection, cybersecurity law, AI governance, commercial contracting, and incident response, acting as the primary legal interface between Nokia's European and UK business operations and the rapidly evolving regulatory landscape. This is an AI-first legal team. We actively build and use AI-assisted workflows — from agentic legal research to automated regulatory horizon scanning — and expect everyone in the team to engage seriously with what AI can do for legal work. The role works alongside counterparts covering the Americas, Middle East and Africa, and Asia Pacific, with genuine opportunity to collaborate on cross-jurisdictional matters. If you are excited by building the legal function of the future rather than maintaining the legal function of the past, you will fit in here.

How You Will Contribute And What You Will Learn
  • Provide expert legal advice across the full EU and UK data protection and cybersecurity regulatory landscape, including GDPR, UK GDPR/DPA 2018, NIS2, the EU Cyber Resilience Act, the EU Data Act, the EU AI Act, and applicable national implementing legislation.
  • Lead Nokia's legal engagement with the Cyber Resilience Act, including the legal track for open-source software obligations in network products, conformity requirements, and evolving delegated acts.
  • Own the legal workstream for Nokia's supplier security documentation, including the modular security appendix applied across Nokia's global supply chain.
  • Advise on privacy and cybersecurity requirements in customer contracts and procurement processes, including data processing agreements, security appendices, and data localisation requirements.
  • Conduct horizon scanning across EU and UK regulatory developments, triaging legal risk and preparing clear, actionable briefings for senior stakeholders and governance forums.
  • Lead legal review of Nokia's use of regulated data types — telecom subscriber data, network data, employee data — advising on permissible use cases, anonymisation standards, and access controls.
  • Conduct and review Data Protection Impact Assessments for high-risk processing activities, including AI-driven use cases and network analytics.
  • Actively identify opportunities to move Nokia's compliance posture from paper-based to demonstrable — working with engineering, security, and data teams to embed legal requirements as technical controls into systems and workflows. In practice: data minimisation enforced at the API layer, purpose restrictions implemented as access controls, anonymisation validated against re-identification risk rather than assumed.
  • Play a central role in cyber and privacy incident response — making timely, legally sound decisions on notification obligations under NIS2, GDPR Articles 33/34, and applicable national legislation, and maintaining Nokia's incident response legal playbook.
  • Provide privacy, data use, and cyber law input into Nokia's AI governance programme and internal AI deployment — ensuring legal requirements are embedded at design stage.
  • Deliver training and legal briefings to internal teams, leveraging AI tools to create scalable, repeatable guidance — building legal capability across the organisation rather than creating dependency on the legal team.
  • Manage external legal counsel on EU and UK matters, with accountability for scope, quality, and cost.
  • Build trusted, collaborative relationships across Information Security, Product Security, Procurement, Business Groups, CTO, and Human Resources — acting as a proactive legal partner and handling matters end-to-end, enabling the Head of Privacy and Data Trust to focus on global strategy and executive engagement.
Key Skills And Experience
Skills and experience

We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.

Must Have
  • Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
  • Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
  • Substantive familiarity with EU cybersecurity regulation — particularly the Cyber Resilience Act, NIS2, and the EU AI Act — and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
  • Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer — you do need to be genuinely interested in how the technology works.
  • A working familiarity with AI tools — including large language models and agentic workflows — and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
  • Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
  • Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships — able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
  • Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
  • Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
  • Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.
Nice to Have
  • Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
  • Experience designing modular contractual frameworks — such as security appendices or DPA templates — applied across a global supply chain.
  • Experience with privacy management platforms such as OneTrust.
  • A relevant qualification — CIPP/E, CIPM, or equivalent — is desirable but not essential; we are more interested in demonstrated capability than credentials.
  • External visibility or a professional network in EU/UK data protection or cybersecurity law.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Legal Counsel
Legal Counsel

Nokia • Espoo

Hybrid
EUR 120,000 - 160,000
Flexible/hybrid working
Maternity/Paternity leave
Annual bonus
+4
Privacy and Security Lawyer
Privacy and Security Lawyer

DNV • Espoo

Hybrid
EUR 85,000 - 120,000
Group Legal and Privacy Manager
Group Legal and Privacy Manager

Nomentia • Espoo

Hybrid
EUR 71,000 - 85,000
Annual bonus up to 10%
Hybrid work in Finland (Espoo)
Finance, Legal, Government and Geopolitical Relations Executive Communications Lead
Finance, Legal, Government and Geopolitical Relations Executive Communications Lead

Nokia Oyj • Espoo

On-site
EUR 120,000 - 180,000
Senior Manager, Partnering, Technology Standards Finland (Hybrid) Posted on 04/24/2026 Hot Job
Senior Manager, Partnering, Technology Standards Finland (Hybrid) Posted on 04/24/2026 Hot Job

Nokia • Espoo

On-site
EUR 80,000 - 100,000
Flexible working arrangements
Maternity and Paternity Leave
Edenred benefit voucher - 400€ per year
+7
Senior SW Engineer, Network Management
Senior SW Engineer, Network Management

Nokia • Oulu

On-site
EUR 90,000 - 120,000
Flexible and hybrid working
90 days of parental leave
Annual bonus
+3
Senior SW Engineer, Network Management
Senior SW Engineer, Network Management

Nokia • Espoo

Hybrid
EUR 90,000 - 120,000
Flexible hybrid working
90 days maternity/paternity leave
Annual bonus
+4
(Senior) Patent Counsel
(Senior) Patent Counsel

Nokia • Tampere

On-site
EUR 90,000 - 130,000
Flexible work
Hybrid work model
Life insurance
+5
(Senior) Patent Counsel
(Senior) Patent Counsel

Nokia • Oulu

Hybrid
EUR 90,000 - 130,000
Flexible and hybrid working schemes
90+ days maternity/paternity leave
Life insurance for employees
+4
(Senior) Patent Counsel
(Senior) Patent Counsel

Nokia • Espoo

On-site
EUR 85,000 - 130,000
Flexible work options
Life insurance
Well-being programs
+2