Lead Privacy Counsel; AUS, NYC
Listed on 2025-12-16
-
IT/Tech
Data Security, Information Security
Base pay range
$/yr - $/yr
Inclusion at Bumble Inc.Bumble Inc. is an equal opportunity employer and we strongly encourage people of all ages, colour, lesbian, gay, bisexual, transgender, queer and non‑binary people, veterans, parents, people with disabilities, and neurodivergent people to apply. We're happy to make any reasonable adjustments that will help you feel more confident throughout the process, please don't hesitate to let us know how we can help.
In your application, please feel free to note which pronouns you use (For example: she/her, he/him, they/them, etc).
Job SummaryBumble’s mission is to foster healthy and equitable relationships across the globe. As a platform built on trust and integrity, we’re deeply committed to protecting our members’ data and privacy. We are seeking a strategic and solutions‑oriented Lead Privacy Counsel to help us build scalable, effective privacy programs that reflect our values and support our global growth.
As Lead Privacy Counsel, you will lead and implement privacy and data protection compliance programs across global jurisdictions, with a primary focus on data breach readiness and response, EU regulatory obligations, and U.S. privacy compliance. You will partner closely with Legal, Info Sec, Compliance, and cross‑functional teams to drive clarity, consistency, and accountability across all facets of data protection. This role is ideal for a privacy attorney who thrives in a fast‑paced, tech‑focused environment and wants to make a meaningful impact through program design, incident management, and regulatory documentation.
Whatyou will do
- Lead Bumble’s incident response and data breach management program, including investigation protocols, notification assessments, regulatory reporting, and post‑incident remediation.
- Build and scale efficient, cross‑functional privacy compliance programs aligned with global frameworks including GDPR, UK DPA, CCPA/CPRA, and other U.S. state‑level privacy laws.
- Own and maintain core GDPR compliance documentation, including Records of Processing Activities (ROPA), Data Protection Impact Assessments (DPIAs), Lawful Basis assessments and draft and negotiate Data Processing Agreements.
- Partner closely with Info Sec, Product, and Engineering teams to ensure security safeguards, privacy‑by‑design, and clear roles and responsibilities in incident preparedness.
- Partner closely with the member support function to respond to requests from members for access to or deletion of their data, and assist on (i) regulatory investigations from regulators in the US, UK and EU; and (ii) member claims in civil courts, in relation to Bumble’s response to members’ requests.
- Collaborate with internal Legal colleagues to ensure privacy compliance is integrated into wider compliance and regulatory strategies (e.g., marketing, consumer protection, international transfers), and advise other teams in the business on how to perform their functions in a manner that complies with data protection laws (e.g., marketing, advertising, communications and HR teams).
- Develop and lead a talented privacy advisor who plays a key role in ensuring the protection of our member’s data.
- Develop and deliver privacy policies, playbooks, templates, and training materials that promote awareness and enable operational consistency.
- Stay abreast of privacy and data security trends and regulatory changes, and assess their practical impact on Bumble’s global operations.
- Promote a member‑first approach to privacy that aligns with Bumble’s values and business priorities.
- J.D. degree and active bar membership in good standing.
- 10+ years of relevant privacy and data protection experience, including in‑house counsel roles with U.S.‑based global companies.
- Deep understanding of global privacy regulations, including GDPR, UK GDPR, CCPA/CPRA, biometric specific laws and other U.S. privacy and data security frameworks.
- Demonstrated experience leading data breach and incident response programs, including coordination with Info Sec, legal assessments, and notification requirements.
- Hands‑on experience preparing and managing ROPA, DPIAs, and other GDPR compliance artifacts.
- Practical,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).