Privacy, Data & Cyber Regulatory Counsel

On-site in Amadora·Added 20 days ago

Nokia

41 open roles

Overview

Requirements

  • Work on-site in Amadora

    No relocation package mentioned.

The role

The Privacy, Data and Cyber Regulatory Counsel - Europe & UK holds direct, end-to-end accountability for Nokia's legal compliance with data protection and cybersecurity regulation across Europe and the United Kingdom. This is not a background advisory role: you hold the legal position for your region, take ownership of your work, and are directly accountable for outcomes. Nokia is at the centre of the AI supercycle - building 5G networks, cloud-native platforms, data centres, and the AI-native software stacks that connect billions of people. The legal and regulatory challenges here are genuinely interesting: from how telecom subscriber data is handled in real-time AI-driven networks, to the legal implications of the EU Cyber Resilience Act for open-source software in critical infrastructure. If you want to do privacy and cyber law at the frontier of where regulation meets real technology, this is the role.
  • Provide expert legal advice across the full EU and UK data protection and cybersecurity regulatory landscape, including GDPR, UK GDPR/DPA 2018, NIS2, the EU Cyber Resilience Act, the EU Data Act, the EU AI Act, and applicable national implementing legislation.
  • Lead Nokia's legal engagement with the Cyber Resilience Act, including the legal track for open-source software obligations in network products, conformity requirements, and evolving delegated acts.
  • Own the legal workstream for Nokia's supplier security documentation, including the modular security appendix applied across Nokia's global supply chain.
  • Advise on privacy and cybersecurity requirements in customer contracts and procurement processes, including data processing agreements, security appendices, and data localisation requirements.
  • Conduct horizon scanning across EU and UK regulatory developments, triaging legal risk and preparing clear, actionable briefings for senior stakeholders and governance forums.
  • Lead legal review of Nokia's use of regulated data types - telecom subscriber data, network data, employee data - advising on permissible use cases, anonymisation standards, and access controls.
  • Conduct and review Data Protection Impact Assessments for high-risk processing activities, including AI-driven use cases and network analytics.
  • Actively identify opportunities to move Nokia's compliance posture from paper-based to demonstrable - working with engineering, security, and data teams to embed legal requirements as technical controls into systems and workflows. In practice: data minimisation enforced at the API layer, purpose restrictions implemented as access controls, anonymisation validated against re-identification risk rather than assumed.
  • Play a central role in cyber and privacy incident response - making timely, legally sound decisions on notification obligations under NIS2, GDPR Articles 33/34, and applicable national legislation, and maintaining Nokia's incident response legal playbook.
  • Provide privacy, data use, and cyber law input into Nokia's AI governance programme and internal AI deployment - ensuring legal requirements are embedded at design stage.
  • Deliver training and legal briefings to internal teams, leveraging AI tools to create scalable, repeatable guidance - building legal capability across the organisation rather than creating dependency on the legal team.
  • Manage external legal counsel on EU and UK matters, with accountability for scope, quality, and cost.
  • Build trusted, collaborative relationships across Information Security, Product Security, Procurement, Business Groups, CTO, and Human Resources - acting as a proactive legal partner and handling matters end-to-end, enabling the Head of Privacy and Data Trust to focus on global strategy and executive engagement.

Skills and experience

We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.

Must Have

  • Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
  • Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
  • Substantive familiarity with EU cybersecurity regulation - particularly the Cyber Resilience Act, NIS2, and the EU AI Act - and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
  • Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer - you do need to be genuinely interested in how the technology works.
  • A working familiarity with AI tools - including large language models and agentic workflows - and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
  • Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
  • Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships - able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
  • Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
  • Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
  • Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.

Nice to Have

  • Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
  • Experience designing modular contractual frameworks - such as security appendices or DPA templates - applied across a global supply chain.
  • Experience with privacy management platforms such as OneTrust.
  • A relevant qualification - CIPP/E, CIPM, or equivalent - is desirable but not essential; we are more interested in demonstrated capability than credentials.
  • External visibility or a professional network in EU/UK data protection or cybersecurity law.

Requirements

Skills and experience

We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.

Must Have

  • Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
  • Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
  • Substantive familiarity with EU cybersecurity regulation — particularly the Cyber Resilience Act, NIS2, and the EU AI Act — and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
  • Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer — you do need to be genuinely interested in how the technology works.
  • A working familiarity with AI tools — including large language models and agentic workflows — and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
  • Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
  • Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships — able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
  • Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
  • Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
  • Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.

Nice to Have

  • Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
  • Experience designing modular contractual frameworks — such as security appendices or DPA templates — applied across a global supply chain.
  • Experience with privacy management platforms such as OneTrust.
  • A relevant qualification — CIPP/E, CIPM, or equivalent — is desirable but not essential; we are more interested in demonstrated capability than credentials.
  • External visibility or a professional network in EU/UK data protection or cybersecurity law.

About Nokia

Industry
Telecommunications
Website
nokia.com
All open roles at Nokia
WhatsApp