Digital Affairs & DPO Senior Specialist
Listed on 2026-05-19
-
IT/Tech
Data Security, Information Security, Cybersecurity
About The Role
As a Digital Affairs & DPO Senior Specialist based in the United States, you will play a senior role in Nubank’s global privacy function, acting as a key point of contact for complex privacy, data protection and AI topics in the US while supporting our global privacy governance program.
You will bridge high‑level legal strategy and day‑to‑day program execution, combining hands‑on product counseling with ownership of core privacy governance workflows (RoPA, DPIAs/PIAs, DSRs, incident response, third‑party risk, metrics) across multiple jurisdictions.
Protecting personal data is fundamental to maintaining the fanatical trust our customers place in us. This role ensures that as Nubank expands its footprint and launches data‑intensive products (including in the US), our privacy and AI governance remain compliant, scalable, business‑enabling and deeply embedded into our technology and product lifecycle.
You will respond to the Global DPO and work closely with Legal, Compliance, IT Security, Data, Risk, and Products teams to identify and close privacy and AI‑related gaps, design pragmatic controls, and translate complex regulatory expectations (e.g., US federal and state privacy laws, LGPD, GDPR) into simple, repeatable mechanisms that enable innovation.
You’ll Be Responsible For- Product Legal Counseling (Privacy, Data Protection & AI)
- Provide clear, fast and actionable legal guidance to product, engineering, data and business teams on US and global privacy, data protection, AI and cybersecurity questions, with focus on data‑intensive products and internal tools.
- Conduct legal risk assessments for new and existing products, features and AI/ML use cases (including automated decision‑making, profiling, biometrics, fraud/credit models), aligning recommendations with Nubank’s risk appetite and product strategy.
- Draft, review and negotiate privacy‑relevant documentation (e.g., DPAs, data sharing agreements, vendor addenda, privacy and AI notices, in‑product disclosures, terms of service and consent flows), including cross‑border data transfer mechanisms.
- Translate complex and evolving US and international privacy/AI requirements into simple, operational guidance and design patterns for squads, avoiding “legal black boxes” and enabling self‑service where possible.
- Privacy Governance & Program Management
- Work closely with the Global DPO to co‑lead the execution of the global privacy governance roadmap, ensuring clear ownership, milestones, and visibility to leadership.
- Own or co‑own key pillars of the Privacy Governance Program as they relate to the US and global scope, including:
- Record of Processing Activities (RoPA) and personal data mapping;
- Privacy and data protection risk management and controls;
- DPIAs/PIAs and other privacy risk assessments at scale;
- Global data subject rights (DSR) strategy and processes;
- Training, awareness and privacy metrics.
- Design and implement projects to simplify and automate privacy governance wherever possible (e.g., templates, workflows, playbooks, self‑service tools), balancing regulatory expectations with business velocity.
- Data Subject Rights, Transparency & US‑Focused Governance
- Maintain and enhance how Nubank handles data subject rights requests across geographies, with particular focus on US privacy rights (e.g., access, deletion, correction, portability, opt‑out mechanisms, sensitive data rules under state laws).
- Partner with CS/Ops and engineering teams to scale DSR handling, ensuring consistent identity verification, response quality and SLA adherence without increasing operational headcount.
- Support the design and continuous improvement of privacy notices, in‑product privacy UX and choice mechanisms for US users, ensuring alignment with global standards and local requirements.
- Third‑Party & Data Sharing Governance
- Assess third parties and new data‑sharing arrangements (including US vendors and cross‑border engagements) from a privacy and AI‑governance perspective, recommending proportionate controls and contractual protections.
- Enhance end‑to‑end third‑party due diligence and oversight flows together with Procurement, Security, Risk and Data, ensuring that privacy…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).