Privacy, Data & Cyber Regulatory Counsel
On-site in Amadora·Added 20 days ago
Overview
Requirements
Work on-site in Amadora
No relocation package mentioned.
The role
The Privacy, Data and Cyber Regulatory Counsel - Europe & UK holds direct, end-to-end accountability for Nokia's legal compliance with data protection and cybersecurity regulation across Europe and the United Kingdom. This is not a background advisory role: you hold the legal position for your region, take ownership of your work, and are directly accountable for outcomes.
Nokia is at the centre of the AI supercycle - building 5G networks, cloud-native platforms, data centres, and the AI-native software stacks that connect billions of people. The legal and regulatory challenges here are genuinely interesting: from how telecom subscriber data is handled in real-time AI-driven networks, to the legal implications of the EU Cyber Resilience Act for open-source software in critical infrastructure. If you want to do privacy and cyber law at the frontier of where regulation meets real technology, this is the role.
- Provide expert legal advice across the full EU and UK data protection and cybersecurity regulatory landscape, including GDPR, UK GDPR/DPA 2018, NIS2, the EU Cyber Resilience Act, the EU Data Act, the EU AI Act, and applicable national implementing legislation.
- Lead Nokia's legal engagement with the Cyber Resilience Act, including the legal track for open-source software obligations in network products, conformity requirements, and evolving delegated acts.
- Own the legal workstream for Nokia's supplier security documentation, including the modular security appendix applied across Nokia's global supply chain.
- Advise on privacy and cybersecurity requirements in customer contracts and procurement processes, including data processing agreements, security appendices, and data localisation requirements.
- Conduct horizon scanning across EU and UK regulatory developments, triaging legal risk and preparing clear, actionable briefings for senior stakeholders and governance forums.
- Lead legal review of Nokia's use of regulated data types - telecom subscriber data, network data, employee data - advising on permissible use cases, anonymisation standards, and access controls.
- Conduct and review Data Protection Impact Assessments for high-risk processing activities, including AI-driven use cases and network analytics.
- Actively identify opportunities to move Nokia's compliance posture from paper-based to demonstrable - working with engineering, security, and data teams to embed legal requirements as technical controls into systems and workflows. In practice: data minimisation enforced at the API layer, purpose restrictions implemented as access controls, anonymisation validated against re-identification risk rather than assumed.
- Play a central role in cyber and privacy incident response - making timely, legally sound decisions on notification obligations under NIS2, GDPR Articles 33/34, and applicable national legislation, and maintaining Nokia's incident response legal playbook.
- Provide privacy, data use, and cyber law input into Nokia's AI governance programme and internal AI deployment - ensuring legal requirements are embedded at design stage.
- Deliver training and legal briefings to internal teams, leveraging AI tools to create scalable, repeatable guidance - building legal capability across the organisation rather than creating dependency on the legal team.
- Manage external legal counsel on EU and UK matters, with accountability for scope, quality, and cost.
- Build trusted, collaborative relationships across Information Security, Product Security, Procurement, Business Groups, CTO, and Human Resources - acting as a proactive legal partner and handling matters end-to-end, enabling the Head of Privacy and Data Trust to focus on global strategy and executive engagement.
Skills and experience
We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.
Must Have
- Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
- Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
- Substantive familiarity with EU cybersecurity regulation - particularly the Cyber Resilience Act, NIS2, and the EU AI Act - and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
- Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer - you do need to be genuinely interested in how the technology works.
- A working familiarity with AI tools - including large language models and agentic workflows - and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
- Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
- Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships - able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
- Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
- Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
- Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.
Nice to Have
- Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
- Experience designing modular contractual frameworks - such as security appendices or DPA templates - applied across a global supply chain.
- Experience with privacy management platforms such as OneTrust.
- A relevant qualification - CIPP/E, CIPM, or equivalent - is desirable but not essential; we are more interested in demonstrated capability than credentials.
- External visibility or a professional network in EU/UK data protection or cybersecurity law.
Requirements
Skills and experience
We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.
Must Have
- Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
- Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
- Substantive familiarity with EU cybersecurity regulation — particularly the Cyber Resilience Act, NIS2, and the EU AI Act — and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
- Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer — you do need to be genuinely interested in how the technology works.
- A working familiarity with AI tools — including large language models and agentic workflows — and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
- Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
- Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships — able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
- Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
- Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
- Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.
Nice to Have
- Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
- Experience designing modular contractual frameworks — such as security appendices or DPA templates — applied across a global supply chain.
- Experience with privacy management platforms such as OneTrust.
- A relevant qualification — CIPP/E, CIPM, or equivalent — is desirable but not essential; we are more interested in demonstrated capability than credentials.
- External visibility or a professional network in EU/UK data protection or cybersecurity law.
