Privacy Counsel

Nova Biomedical

Waltham (MA)

On-site

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Nova Biomedical is seeking a Privacy Counsel to provide legal oversight, risk assessment, and strategic guidance on privacy, data‑protection, and data‑management matters across Nova Biomedical Corporation and its subsidiaries.

The Privacy Counsel will help ensure compliance with applicable global privacy laws and regulations by developing and implementing privacy policies and procedures, reviewing contracts from a privacy perspective, conducting training, and advising business and technology

Responsibilities

  • Provide legal oversight and strategic guidance for Nova Biomedical’s privacy, data-management, and information-security programs in accordance with applicable U.S. and global privacy laws.
  • Advise business, technology, and legal stakeholders on privacy, data protection, security, and compliance matters.
  • Interpret and apply privacy requirements under the General Data Protection Regulation and applicable U.S. federal and state laws.
  • Implement, maintain, and enforce internal and external privacy policies, procedures, data-protection agreements, and related legal documentation.
  • Ensure privacy policies and procedures reflect evolving legal requirements and relevant industry practices.
  • Draft, review, negotiate, and manage privacy-related legal documents, including Records of Processing Activities, Data Protection Impact Assessments, Privacy Impact Assessments, Privacy notices, Data Processing Agreements, Data-transfer agreements, Business Associate Agreements, Inter-Affiliate Data Transfer Agreements.
  • Analyze products, services, technologies, projects, and business initiatives for privacy and data-protection risks.
  • Conduct privacy impact assessments and recommend appropriate measures to mitigate identified risks.
  • Develop, deliver, and lead privacy and data-protection training programs.
  • Establish role-based privacy training, new-hire training, annual refreshers, and appropriate completion records.
  • Support enterprise risk-management activities by identifying, assessing, documenting, and escalating material privacy and data-protection risks.
  • Contribute to risk assessments, risk registers, executive reporting, and related governance activities.
  • Serve as a liaison among IT, InfoSec, Legal, Governance, Risk and Compliance, and relevant business functions on privacy and information-security matters.
  • Monitor changes in privacy, data-protection, and information-security laws and regulations.
  • Evaluate and communicate the potential impact of legal and regulatory developments on Nova Biomedical.
  • Collaborate with global team members, particularly stakeholders in the EU, to promote consistent privacy practices and risk-mitigation strategies.
  • Research complex privacy and data-protection matters and provide practical legal advice and recommendations.
  • Serve as the primary legal point of contact for personal data breaches.
  • Lead the legal aspects of Nova Biomedical’s Personal Data Breach process in coordination with IT, InfoSec, and other stakeholders.
  • Establish breach-determination criteria, jurisdiction-specific notification requirements, escalation paths, defined responsibilities, and a centralized breach register.
  • Serve as the primary interface with the Data Protection Officer.
  • Support interactions with regulators and outside counsel when required.
  • Provide privacy-related legal support for strategic transactions and other mission-critical initiatives.
  • Support privacy due diligence and integration activities associated with mergers, acquisitions, and other strategic transactions.
  • Provide legal guidance regarding commercial agreements, compliance programs, healthcare-industry requirements as needed.

Job description

Nova Biomedical: One Global Brand. One Vision. Together under one name. Advanced Instruments and Nova Biomedical are now united under one brand, Nova Biomedical, marking a major milestone in our journey to deliver greater value to our customers. By combining our strengths, we're accelerating innovation, supporting critical workflows, and delivering world-class service across the biopharmaceutical and clinical markets.

Job Summary

Nova Biomedical is seeking a Privacy Counsel to provide legal oversight, risk assessment, and strategic guidance on privacy, data protection, and data‑management matters across Nova Biomedical Corporation and its subsidiaries.

The Privacy Counsel will help ensure compliance with applicable global privacy laws and regulations by developing and implementing privacy policies and procedures, reviewing contracts from a privacy perspective, conducting training, and advising business and technology teams on privacy and data‑protection risks. This role will work closely with Governance, Risk and Compliance, Information Technology, Information Security, Legal, and business functions to protect Nova Biomedical from legal and compliance risks related to privacy, security, and data management.

In partnership with the Vice President of Governance, Risk and Compliance, the Privacy Counsel will develop short‑ and long‑term plans for managing privacy‑related legal matters and minimizing risk to the business. A key near‑term priority will be operationalizing and maturing Nova Biomedical’s global privacy program following its combination with Advanced Instruments.

Responsibilities
  • Provide legal oversight and strategic guidance for Nova Biomedical’s privacy, data‑management, and information‑security programs in accordance with applicable U.S. and global privacy laws.
  • Advise business, technology, and legal stakeholders on privacy, data protection, security, and compliance matters.
  • Interpret and apply privacy requirements under the General Data Protection Regulation and applicable U.S. federal and state laws.
  • Implement, maintain, and enforce internal and external privacy policies, procedures, data‑protection agreements, and related legal documentation.
  • Ensure privacy policies and procedures reflect evolving legal requirements and relevant industry practices.
  • Draft, review, negotiate, and manage privacy‑related legal documents, including:
    • Records of Processing Activities
    • Data Protection Impact Assessments
    • Privacy Impact Assessments
    • Privacy notices
    • Data Processing Agreements
    • Data‑transfer agreements
    • Business Associate Agreements
    • Inter‑Affiliate Data Transfer Agreements
  • Analyze products, services, technologies, projects, and business initiatives for privacy and data‑protection risks.
  • Conduct privacy impact assessments and recommend appropriate measures to mitigate identified risks.
  • Develop, deliver, and lead privacy and data‑protection training programs.
  • Establish role‑based privacy training, new‑hire training, annual refreshers, and appropriate completion records.
  • Support enterprise risk‑management activities by identifying, assessing, documenting, and escalating material privacy and data‑protection risks.
  • Contribute to risk assessments, risk registers, executive reporting, and related governance activities.
  • Serve as a liaison among Information Technology, Information Security, Legal, Governance, Risk and Compliance, and relevant business functions on privacy and information‑security matters.
  • Monitor changes in privacy, data‑protection, and information‑security laws and regulations.
  • Evaluate and communicate the potential impact of legal and regulatory developments on Nova Biomedical.
  • Collaborate with global team members, particularly stakeholders in the European Union, to promote consistent privacy practices and risk‑mitigation strategies.
  • Research complex privacy and data‑protection matters and provide practical legal advice and recommendations.
  • Serve as the primary legal point of contact for personal data breaches.
  • Lead the legal aspects of Nova Biomedical’s Personal Data Breach process in coordination with Information Technology, Information Security, and other stakeholders.
  • Establish breach‑determination criteria, jurisdiction‑specific notification requirements, escalation paths, defined responsibilities, and a centralized breach register.
  • Serve as the primary interface with the Data Protection Officer.
  • Support interactions with regulators and outside counsel when required.
  • Provide privacy‑related legal support for strategic transactions and other mission‑critical initiatives.
  • Support privacy due diligence and integration activities associated with mergers, acquisitions, and other strategic transactions.
  • Provide legal guidance regarding commercial agreements, compliance programs, healthcare‑industry requirements as needed.
Global Privacy Program Development
  • Own and operationalize an enterprise‑wide data‑subject‑rights program.
  • Establish standardized processes for access, rectification, erasure, restriction, objection, portability, consent withdrawal, and opt‑out requests involving the sale or sharing of personal data.
  • Develop standardized request‑intake channels, response procedures, documentation requirements, and a centralized data‑subject‑rights log.
  • Ensure the data‑subject‑rights program addresses applicable requirements under the General Data Protection Regulation, United Kingdom privacy law, Swiss Federal Act on Data Protection, applicable U.S. state privacy laws, Brazil’s General Data Protection Law, China’s Personal Information Protection Law, Canada’s Personal Information Protection and Electronic Documents Act, and Quebec Law 25.
  • Build and maintain an external‑facing privacy‑notice framework.
  • Develop and maintain an appropriate U.S. employee privacy notice.
  • Maintain streamlined website and California privacy policies with clearly defined ownership and review cycles.
  • Bring applicable consumer‑facing channels into compliance with U.S. consumer health‑data laws, including the Washington My Health My Data Act, Nevada Senate Bill 370, and the Connecticut Data Privacy Act.
  • Develop and publish a standalone Consumer Health Data Privacy Policy where required.
  • Establish appropriate consent processes for collecting and processing consumer health data.
  • Establish recurring cookie‑governance processes across Nova Biomedical web properties.
  • Implement periodic cookie scanning and inventory practices.
  • Establish region‑appropriate cookie and tracking‑technology consent configurations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Privacy Counsel
Privacy Counsel

NOVA Biomedical GmbH • Waltham (MA)

On-site
USD 150,000 - 250,000
Global Privacy Counsel — Data Protection & Compliance
Global Privacy Counsel — Data Protection & Compliance

Nova Biomedical Corporation • Waltham (MA)

Hybrid
USD 175,000 - 215,000
Hybrid and flexible work arrangements
Generous PTO and paid holidays
401k company match
+2
Global Privacy Counsel — Lead Privacy & Compliance
Global Privacy Counsel — Lead Privacy & Compliance

novabio • Waltham (MA)

Hybrid
USD 175,000 - 215,000
Hybrid work arrangements
401k company match
Tuition reimbursement
+1
Global Privacy Counsel: Data Protection & Compliance
Global Privacy Counsel: Data Protection & Compliance

Nova Biomedical • Waltham (MA)

On-site
USD 180,000 - 240,000
Global Privacy Counsel & Data Protection Lead
Global Privacy Counsel & Data Protection Lead

NOVA Biomedical GmbH • Waltham (MA)

On-site
USD 150,000 - 250,000
Privacy Counsel
Privacy Counsel

Nova Biomedical Corporation • Waltham (MA)

Hybrid
USD 175,000 - 215,000
Hybrid and flexible work arrangements
Generous PTO and paid holidays
401k company match
+2
Privacy Counsel
Privacy Counsel

novabio • Waltham (MA)

Hybrid
USD 175,000 - 215,000
Hybrid work arrangements
401k company match
Tuition reimbursement
+1
Head of Compliance and Data Privacy
Head of Compliance and Data Privacy

Taleo • Northern (KY)

Hybrid
USD 140,000 - 200,000
Compliance Counsel - Data Privacy
Compliance Counsel - Data Privacy

Larson Maddox • Atlanta (GA)

On-site
USD 120,000 - 160,000
Associate General Counsel, Privacy – Remote (USA) (993-SLS)
Associate General Counsel, Privacy – Remote (USA) (993-SLS)

Solutuslegal • United States

Remote
USD 260,000 - 295,000
Equity
Generous benefits