Chief Data Privacy Counsel
CAA
Nashville, TNThis is a Full Time Job
Job Description
The Role
CAA is seeking a Data Privacy Counsel to join its Legal team. This role will be a key senior level leader responsible for assisting with the implementation of CAA's companywide AI programs, advising on and managing the organization's data privacy policies, and ensuring compliance with applicable privacy laws and regulations across CAA's global operations. Reporting to the Deputy General Counsel and Chief Compliance Officer, the Data Privacy Counsel will serve as a trusted legal advisor to business units and functional teams on a broad range of privacy, data protection, and data governance matters.
Responsibilities
• Develop, implement, and maintain a comprehensive companywide data privacy strategy and program, including policies, procedures, notices, and guidelines that ensure compliance with applicable federal, state, and international privacy laws and regulations
• Act as a key leader for the selection and roll-out of CAA's approved AI platforms, advising on safe and responsible implementation steps, model vulnerabilities, data protection considerations, employee trainings, evolving industry norms/best practices and any other issues that may arise throughout the integration process
• Serve as the primary legal advisor on data privacy and data protection matters across the organization, providing counsel to business, technology, finance, tax, marketing, human resources, and other functional teams
• Review, draft, and negotiate privacy and data protection provisions in vendor, partner, and client agreements, including data processing agreements (DPAs) and standard contractual clauses (SCCs)
• Oversee and conduct privacy impact assessments and risk assessments relating to new and existing programs, products, and initiatives that involve the collection, use, or sharing of personal information
• Monitor and interpret developments in global privacy laws and regulations, including GDPR, CCPA/CPRA, and other applicable laws, and advise on their impact to CAA's business operations
• Lead and manage the privacy incident response process, including breach assessment, regulatory notification, and remediation across relevant jurisdictions
• Collaborate cross-functionally with IT, Information Security, Marketing, Human Resources, and other departments to embed privacy-by-design principles into business processes, systems, and new initiatives
• Manage and respond to data subject rights requests in accordance with applicable law, and maintain internal processes for timely and accurate handling
• Develop and deliver privacy training and awareness programs for employees across the organization, including communicating legal and regulatory developments in an accessible manner
• Advise on cross-border data transfer mechanisms, data localization requirements, and global data governance, supporting CAA's international operations
• Liaise with regulatory authorities, outside counsel, and other external privacy stakeholders and advisors as required
• Prepare periodic reports on the privacy program and its compliance posture for senior leadership and other relevant stakeholders
Required Experience and Qualifications
• J.D. from an accredited law school and active bar membership (Tennessee bar admission or ability to register as In-House Counsel)
• 15+ years of relevant legal experience, with a meaningful focus on privacy law, data protection, and related regulatory matters and issues in technology and/or AI-driven environments
• Law firm and/or in-house experience preferred
• Deep knowledge of global and domestic privacy laws and frameworks, including GDPR, CCPA/CPRA, and other applicable international and state laws
• Experience drafting, reviewing, and negotiating privacy-related contractual provisions, including data processing agreements (DPAs) and standard contractual clauses (SCCs)
• History of advising on legal issues relating to AI products, AI research, or machine learning systems, including familiarity with the machine learning development lifecycle
• Familiarity with privacy-enhancing technologies, information security practices, and data governance frameworks
• Strong ability to translate complex legal requirements into practical, business-oriented guidance for non-legal audiences
• Excellent written and verbal communication skills, with the ability to present to and advise senior leadership and cross-functional audiences
• Highly collaborative with strong interpersonal skills and the ability to partner effectively across legal, technology, and business functions
• Action-oriented with the ability to manage a substantial workload, set priorities, and meet deadlines in a fast-paced, dynamic environment
• Strong business acumen, sound judgment, and a practical, solutions-oriented approach to problem solving
• Privacy certifications (e.g., CIPP/US, CIPP/E, CIPM) a plus
• Media & Entertainment industry experience a plus
Location
This role will be based out of our Nashville office.
CAA does not accept unsolicited resumes from third-party recruiters unless they were contractually engaged by CAA to provide candidates for a specified opening. Any such employment agency, person or entity that submits an unsolicited resume does so with the acknowledgement and agreement that CAA will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.
Salary/Benefits
$273,000 - $357,000 /year USD
Salary may vary based upon relevant experience, time in role, business sector, and geographic location.
Benefits
• Medical, dental, and vision insurance
• 401(k)
• Discretionary bonus
Additional Information
CAA is a leading entertainment and sports agency, representing a diverse range of clients across various industries. The company is committed to providing innovative solutions and strategic guidance, leveraging its extensive network and expertise in the media and entertainment landscape.