Privacy & Data Protection Analyst

King & Spalding

Atlanta (GA)

On-site

USD 90,000 - 120,000

Full time

46 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health and wellness plan
Life and disability insurance
Flexible spending accounts
Health savings account
401(k) plan
Profit sharing plan
Paid Time Off

Job summary

King & Spalding is seeking a Privacy & Data Protection Analyst to mature the firm’s privacy program. You will work with Information Security, Legal, and business stakeholders to govern, protect, and responsibly use personal information including client data, employee HR data, PHI, and CUI.

You will coordinate Privacy Committee activities, review DPAs and data transfer terms, and support third-party risk management.

Qualifications

  • Bachelor’s degree or equivalent professional experience.
  • 3+ years supporting privacy, data protection, or regulated data governance programs.
  • Knowledge of privacy concepts: personal data, PHI, DPAs, data transfers, notices, and data flow docs.
  • Experience reviewing privacy or security terms in vendor/client contracts.
  • Familiarity with HIPAA, GDPR/UK GDPR, U.S. state privacy laws, NIST, ISO 27001, NIST 800-171, or CMMC.
  • Strong writing, organization, and stakeholder management skills.
  • Privacy/security/risk certifications (e.g., CIPP/US, CISSP) preferred.
  • Experience in a law firm or professional services environment preferred.

Responsibilities

  • Support the privacy program, including committee coordination, materials, and governance documentation.
  • Review and negotiate DPAs, data transfer terms, client agreements, and AI-related data protection provisions.
  • Assess how vendors collect, use, store, and protect sensitive information for third-party risk management.
  • Complete client privacy and AI assessments with internal stakeholders to demonstrate controls.
  • Manage data subject access requests, cookie/consent management, and privacy notice updates.
  • Lead governance for HIPAA PHI and CUI, coordinating risk assessments and remediation efforts.
  • Advise engagement teams on data handling for high-risk matters and sensitive data.
  • Translate evolving privacy requirements into practical guidance for internal stakeholders.
  • Own core privacy governance in OneTrust: ROPAs, PIAs/DPIAs, TIAs, and data flow docs.

Skills

Privacy knowledge
Stakeholder management
Writing
Attention to detail
Law firm experience

Education

Bachelor’s degree
3+ years privacy experience

Tools

OneTrust

Job description

King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape.


We are seeking a Privacy & Data Protection Analyst to support and mature the firm’s privacy program. This role will work closely with Information Security, Legal, Information Governance, Procurement, HR, the Privacy Committee, and other business stakeholders to help the firm govern, protect, and responsibly use personal information, including client information, employee HR data, PHI, Controlled Unclassified Information (CUI), and other regulated or sensitive data types.


Key Responsibilities


  • Support the firm’s privacy program, including Privacy Committee meeting coordination, agenda and materials preparation, follow-up tracking, privacy program updates, and governance documentation.

  • Support the review and negotiation of vendor and client privacy requirements, including Data Processing Agreements (DPAs), data transfer terms, privacy provisions within client agreements and Outside Counsel Guidelines, AI-related requirements, and other contractual data protection obligations.

  • Assess how vendors and software tools collect, use, store, share, and protect sensitive privacy-related information as part of the firm’s third-party risk management program

  • Complete client privacy and AI assessments and questionnaires, working with internal stakeholders to demonstrate the firm’s controls and help ensure clients remain confident that their sensitive information is appropriately protected.

  • Manage and improve operational privacy processes, including data subject access request intake, tracking, and coordination; cookie and consent management; privacy notice updates; and privacy-related policy maintenance.

  • Lead governance activities for regulated and controlled information types, such as HIPAA-regulated PHI and Controlled Unclassified Information (CUI), including advising teams on the handling of especially sensitive matters, by coordinating compliance assessments, supporting initiatives such as HIPAA Security Risk Assessments and CMMC audits, and driving remediation and program maturity efforts.

  • Analyze highly sensitive or high-risk matters (e.g., significant PII, PHI, or sensitive government/regulatory matters) and advise engagement teams on appropriate data handling, access, and protection measures.

  • Maintain awareness of relevant privacy, data protection, AI, and regulated data requirements in jurisdictions where the firm operates, and translate changes into practical guidance for internal stakeholders.

  • Own core privacy governance activities in OneTrust, including ROPAs, PIAs/DPIAs, TIAs, vendor and application privacy assessments, data flow documentation, privacy risk tracking, remediation coordination, and stakeholder guidance.


Qualifications


  • Bachelor’s degree in a related field or equivalent professional experience.

  • 3+ years of experience supporting privacy, data protection, or regulated data governance programs.

  • Working knowledge of privacy and data protection concepts, including personal information, protected health information, data processing agreements, data transfers, data subject rights, privacy notices, and records of processing or data flow documentation.

  • Experience reviewing privacy or security terms in vendor agreements, client contracts, or similar contractual documents.

  • Familiarity with privacy and security frameworks or requirements such as HIPAA, GDPR/UK GDPR, U.S. state privacy laws, NIST, ISO 27001, NIST 800-171, or CMMC.

  • Strong writing, organization, and stakeholder management skills, with the ability to keep work moving across legal, technical, and business teams.

  • Sound judgment, attention to detail, and the ability to apply privacy and security requirements in a practical, business-aware manner.

  • Privacy, security, or risk certifications such as CIPP/US, CIPP/E, CIPM, CIPT, CISSP, CISA, CISM, CRISC, or related credentials preferred.

  • Experience in a law firm, professional services, regulated industry, or client-service environment preferred.


The firm offers a generous total compensation package with bonuses and raises awarded in recognition of individual merit-based performance.


All full‑time Business Services employees may participate in King & Spalding’s comprehensive benefit program



  • health and wellness plan

  • life and disability insurance

  • flexible spending accounts and a health savings account

  • a 401(k) plan

  • profit sharing plan

  • a substantial Paid Time Off (PTO) program


King & Spalding LLP (K&S) is committed to providing equal employment opportunity to all applicants and employees in full compliance with all state, federal, and local laws prohibiting discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, age, disability or any other status protected by applicable law.


We are proud of our remarkably cohesive culture, which now encompasses more than 2,500 lawyers and business professionals worldwide. We seek to attract and develop the very best talent to work with us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Development Coordinator
Business Development Coordinator

King & Spalding • Denver (CO)

On-site
USD 65,000 - 89,000
Senior Talent Acquisition Coordinator
Senior Talent Acquisition Coordinator

King & Spalding LLP • Atlanta (GA)

On-site
USD 70,000 - 90,000
Health plan
Life insurance
Disability insurance
+4
Business Development Coordinator
Business Development Coordinator

King & Spalding • New York (NY)

On-site
USD 70,000 - 80,000
Health and wellness plan
401(k) plan
Paid Time Off (PTO)
Business Change Analyst
Business Change Analyst

King & Spalding • Atlanta (GA)

On-site
USD 85,000 - 110,000
Business Development Coordinator
Business Development Coordinator

King & Spalding • Atlanta (GA)

On-site
USD 68,000 - 80,000
Health and wellness plan
Life and disability insurance
Flexible spending accounts
+4
Office Manager
Office Manager

King & Spalding • Austin (TX)

On-site
USD 60,000 - 85,000
Health and wellness plan
Life and disability insurance
Flexible spending accounts
+4
Business Development Coordinator
Business Development Coordinator

King & Spalding LLP • New York (NY)

On-site
USD 70,000 - 80,000
Health and wellness plan
Life and disability insurance
401(k) plan
+1
Innovation Attorney - Regulatory
Innovation Attorney - Regulatory

Legal Tech Consultants LLC • Washington, Northern (KY)

Hybrid
USD 160,000 - 250,000
Health and wellness plan
Life and disability insurance
Flexible spending accounts
+4
Innovation Attorney - Regulatory
Innovation Attorney - Regulatory

King & Spalding • Atlanta (GA)

On-site
USD 160,000 - 250,000
Health benefits
401(k) plan
Paid time off
Senior Legal Project Manager
Senior Legal Project Manager

King & Spalding LLP • New York (NY)

On-site
USD 205,000 - 250,000