ForgeApply · Job listing
Privacy & Data Protection Analyst
Kslaw
See all 37 open roles at Kslaw →
Tailor your resume for this Kslaw job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Kslaw's site. Free trial, no card required.
About this role
King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape.
We are seeking a Privacy & Data Protection Analyst to support and mature the firm’s privacy program. This role will work closely with Information Security, Legal, Information Governance, Procurement, HR, the Privacy Committee, and other business stakeholders to help the firm govern, protect, and responsibly use personal information, including client information, employee HR data, PHI, Controlled Unclassified Information (CUI), and other regulated or sensitive data types.
KEY RESPONSIBILITIES: • Support the firm’s privacy program, including Privacy Committee meeting coordination, agenda and materials preparation, follow-up tracking, privacy program updates, and governance documentation.
• Support the review and negotiation of vendor and client privacy requirements, including Data Processing Agreements (DPAs), data transfer terms, privacy provisions within client agreements and Outside Counsel Guidelines, AI-related requirements, and other contractual data protection obligations.
• Assess how vendors and software tools collect, use, store, share, and protect sensitive privacy-related information as part of the firm’s third-party risk management program
• Complete client privacy and AI assessments and questionnaires, working with internal stakeholders to demonstrate the firm’s controls and help ensure clients remain confident that their sensitive information is appropriately protected.
• Manage and improve operational privacy processes, including data subject access request intake, tracking, and coordination; cookie and consent management; privacy notice updates; and privacy-related policy maintenance.
• Lead governance activities for regulated and controlled information types, such as HIPAA-regulated PHI and Controlled Unclassified Information (CUI), including advising teams on the handling of especially sensitive matters, by coordinating compliance assessments, supporting initiatives such as HIPAA Security Risk Assessments and CMMC audits, and driving remediation and program maturity efforts.
• Analyze highly sensitive or high-risk matters (e.g., significant PII, PHI, or sensitive government/regulatory matters) and advise engagement teams on appropriate data handling, access, and protection measures.
• Maintain awareness of relevant privacy, data protection, AI, and regulated data requirements in jurisdictions where the firm operates, and translate changes into practical guidance for internal stakeholders.
• Own core privacy governance activities in OneTrust, including ROPAs, PIAs/DPIAs, TIAs, vendor and application privacy assessments, data flow documentation, privacy risk tracking, remediation coordination, and stakeholder guidance.
QUALIFICATIONS: • Bachelor’s degree in a related field or equivalent professional experience.
• 3+ years of experience supporting privacy, data protection, or regulated data governance programs.
• Working knowledge of privacy and data protection concepts, including personal information, protected health information, data processing agreements, data transfers, data subject rights, privacy notices, and records of processing or data flow documentation.
• Experience reviewing privacy or security terms in vendor agreements, client contracts, or similar contractual documents.
• Familiarity with privacy and security frameworks or requirements such as HIPAA, GDPR/UK GDPR, U.S. state privacy laws, NIST, ISO 27001, NIST 800-171, or CMMC.
• Strong writing, organization, and stakeholder management skills, with the ability to keep work moving across legal, technical, and business teams.
• Sound judgment, attention to detail, and the ability to apply privacy and security requirements in a practical, business-aware manner.
• Privacy, security, or risk certifications such as CIPP/US, CIPP/E, CIPM, CIPT, CISSP, CISA, CISM, CRISC, or related credentials preferred.
• Experience in a law firm, professional services, regulated industry, or client-service environment preferred.
The firm offers a generous total compensation package with bonuses and raises awarded in recognition of individual merit-based performance. All full-time Business Services employees may participate in King & Spalding’s comprehensive benefit program including health and wellness plan, life and disability insurance, flexible spending accounts and a health savings account, a 401(k) plan, profit sharing plan, and a substantial Paid Time Off (PTO) program.
King & Spalding LLP (K&S) is committed to providing equal employment opportunity to all applicants and employees in full compliance with all state, federal, and local laws prohibiting discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, age, disability or any other status protected by applicable law.
We are proud of our remarkably cohesive culture, which now encompasses more than 2,500 lawyers and business professionals worldwide. We seek to attract and develop the very best talent to work with us.
Salary insight
This posting doesn't disclose pay. Across 689 Atlanta jobs with disclosed salaries on ForgeApply, the median is $135k.
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Kslaw role before you apply.
Tailor my resume for this jobSimilar jobs
- Data Protection Analyst — Acrisure · Suite 2750 - ATLANTA, GA | GRAND RAPIDS, MI
- Privacy and Compliance Analyst — Hklaw · Operations Center - Tampa | Dallas
- Privacy Security Analyst — Owensboro Health · Owensboro Health Regional Hospital - Owensboro, KY
- Data Security Analyst — Clarivate · R244-Kansas City
- Analyst, Privacy — Coinbase · Remote
- Privacy, Data Protection and Compliance Intern — Crowe · Chicago IL USA
- Sr Privacy Specialist — Fresenius Medical Care · Remote
- Senior Analyst, Data Privacy - Americas — AIG · NY-New York | GA-Atlanta | NJ-Jersey City
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview