Privacy Counsel

Xero

Xero

Legal
Melbourne, VIC, Australia
Posted on Jul 5, 2024
The successful candidate will play a key role in supporting Xero’s privacy and AI strategies. You’ll be responsible for partnering with the business and providing legal advice and support in relation to a range of complex privacy, AI, cyber and spam related legal, regulatory, and compliance matters across all regions in which Xero operates. This role will report to Xero’s GM - Global Privacy and work closely with the Privacy team, wider Legal team, key business partners and external advisors.

What you'll do...

  • Support legal and business teams in identifying and resolving privacy, AI, cyber and spam marketing related legal matters, including both business-led and privacy team-led initiatives, and including both global and region-specific matters.
  • Work closely with varied stakeholders from product, technology and data services teams - including security, data governance and data science - on existing and new data use cases and product features to ensure compliance with Xero’s approach to responsible data use, including working through data protection impact assessments (DPIAs) where appropriate.
  • Working with the GM - Global Privacy), drive and support the further development and maturation of internal privacy, data, and AI governance programmes.
  • Support data incident management, including taking “on-call” shifts to respond to urgent incidents.
  • With the GM - Global Privacy, support Xero’s response to enquiries from privacy, cyber, and AI regulators.
  • Work closely with CX to ensure compliance with data subjects’ rights obligations.
  • Help evaluate the impact of evolving legislative and regulatory environments for privacy, AI, and cyber on Xero’s various business units, ensuring the business is informed.
  • Collaborate and build relationships with key internal stakeholders to champion privacy, AI, and cyber across the business while continuing to enable commercial opportunities in a fast-paced environment.
  • Support and facilitate key governance forums (including DUGG, SGG, and the Data Privacy Group), and advise as required on privacy, AI, cyber and spam marketing topics.
  • Review and advise on data processing addenda and data protection/privacy related clauses.
  • Contribute to internal privacy, data protection, AI, and cyber policy and process development (including training).
  • Liaise with and manage Xero’s external legal advisors as required.
  • Support your own development by undergoing appropriate training courses in privacy, AI, cyber, and spam marketing (as agreed with the GM - Global Privacy).
  • Drive and support operational legal team projects, for example to manage workflow, improve operational efficiencies, knowledge management.

Experience

  • 2-5 years PQE (in-house legal experience desirable).
  • Demonstrated ability to be a commercially minded business partner to busy business teams in a fast-paced environment.
  • Knowledge and experience of global privacy and data protection law.
  • Current legal practicing certificate in NZ or AU.
  • Experience or strong demonstrated interest in global approaches to data governance frameworks, including AI governance (desirable).
  • Experience providing legal advice to companies in the technology sector (desirable).

Critical Competencies

  • Strong legal drafting, analytical, research and interpretation skills.
  • Strong commercial acumen and a pragmatic approach.
  • Excellent written and verbal communication skills.
  • High level of attention to detail.
  • A great sense of humour.
  • Ability to prioritise work according to multiple stakeholder needs.
  • Ability to work autonomously where appropriate.
  • Ability to take a proactive and creative approach to managing/solving legal issues.
  • Collaborative, growth and innovation mindset.
  • Ability to convey complex legal matters in a digestible, plain-english format.
  • Ability to develop meaningful relationships across the business with a variety of stakeholder, to understand their priorities and concerns