Legal Counsel (Data Privacy & Compliance) (m/f/d)
Allow us to introduce ourselves. Hello there! We’re Appinio, a global market research company that combines an AI-powered insights platform with expert consultancy. On a mission to make the world a little more fact-based, we help companies understand how consumers think and make smarter decisions.
We started out in Hamburg in 2014 and are now a remote‑first global company with over 260 employees across 13 countries, 2600+ international clients, delivering research from over +190 markets worldwide.
Want to be a part of the Appinio movement? We value transparency in our recruitment process, and we’ve created a blog to share what to expect during each step of the journey.
Your Mission
Your mission as a Legal Counsel (Data Protection & Compliance):
- Data Protection Compliance
- Advise on EU GDPR and other privacy laws across the UK, US, and LATAM
- Draft, review, and negotiate Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs)
- Manage Data Subject Rights Requests within statutory deadlines
- Oversee Data Protection Impact Assessments (DPIAs) and ensure privacy‑by‑design in product and research processes
- Monitor cross‑border data transfers and manage Transfer Impact Assessments (TIAs)
- Internal Governance & Compliance Frameworks
- Maintain and enhance Appinio’s internal privacy policies and compliance frameworks
- Conduct internal audits and risk reviews, driving continuous improvement
- Track new regulatory developments and translate them into actionable business guidance
- Contracting & Commercial Support
- Partner with commercial legal to ensure contracts align with privacy obligations
- Support due diligence processes and respond to client security and privacy questionnaires
- Advise on lawful use of personal data in marketing, research, and product innovation
- Incident & Risk Management
- Act as the contact point for data breach response and regulator communications
- Identify and mitigate privacy and compliance risks across departments
- Coordinate with external advisors and DPOs on high‑risk or complex matters
- Product & AI Enablement
- Collaborate with Product and Data teams to ensure responsible data and AI use
- Review new tools and APIs
Profil
This role if You are a fully qualified German lawyer (Volljurist) who has completed both state examinations (Zweites Staatsexamen)
- You bring 3+ years of experience in privacy and data protection, ideally gained in-house
- You have strong knowledge of EU and German data protection law (GDPR, BDSG, TTDSG)
- You’re experienced in commercial contracting and general corporate compliance
- You’re confident advising on both EU and international level
- You’re confident advising internal stakeholders across Product, Research, Tech, and Commercial
- You have excellent legal drafting skills in German and English
- You’re proactive, analytical, and comfortable working independently
- You’re curious about the intersection of privacy, technology, and AI
- You are based in Europe (ideally in Germany, Spain)
Wir bieten for you
Flexibility Policy with no hard cap on vacation days; Temporary work from abroad up to 180 days per year if based in EU; All hardware you need and your own MacBook; Mobility benefits for employees in Hamburg, Berlin, Germany or Spain; Subsidised Urban SportsClub membership for Germany or Spain; Access to coworking spaces for those located in Hamburg, Berlin, Munich, London, Madrid, Barcelona, or New York.
Kind reminder: please ensure that your application is submitted in English.
This post not only outlines our ideal candidate but also serves as an inspiration for what this role can evolve into. Even if you consider yourself an 80% fit but have a genuine passion for this position, we encourage you to apply. We’re eager to hear from individuals who share our enthusiasm.
Appinio is an equal‑opportunity employer. All applicants will be considered for employment without attention to race, colour, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.
Please read our privacy policy.
Important note: a valid work permit for Germany is required for non‑EU citizens. Unfortunately, applications without a valid work permit and sufficient German language skills may not be considered.