Legal Counsel (Data Privacy & Compliance) (m/f/d)
Appinio
Published on
Location: Remote
Work Model: Remote
Job Type: Full-time
Skills: AI Flexible Schedule mid-level work from anywhere policy Legal GDPR Compliance Privacy
Description
Allow us to introduce ourselves
Hello there! We’re Appinio, a global market research company that combines an AI-powered insights platform with expert consultancy. On a mission to make the world a little more fact-based, we help companies understand how consumers think and make smarter decisions.
We started out in Hamburg back in 2014, but we’re now humbled to call the world our playground, with over 260 employees spread across 13 countries (we’re remote-first), 2600+ international clients, delivering research from +190 markets, globally.
Your mission as a Legal Counsel (Data Protection & Compliance)
We are looking for a mid-level Legal Counsel (m/f/d) to help Appinio sustain its rapid growth internationally while staying compliant and managing legal risks while cultivating business growth. This role requires someone with excellent data privacy and compliance experience in the EU and on an international scale.
What you’ll do
- Data Protection Compliance
- Advise on EU GDPR, and other privacy laws across the UK, US, and LATAM
- Draft, review, and negotiate Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs)
- Manage Data Subject Rights Requests (access, deletion, portability, etc.) within statutory deadlines
- Oversee Data Protection Impact Assessments (DPIAs) and ensure privacy-by-design in product and research processes
- Monitor cross-border data transfers and manage Transfer Impact Assessments (TIAs)
- Internal Governance & Compliance Frameworks
- Maintain and enhance Appinio’s internal privacy policies and compliance frameworks
- Conduct internal audits and risk reviews, driving continuous improvement
- Track new regulatory developments and translate them into actionable business guidance
- Contracting & Commercial Support
- Partner with commercial legal to ensure contracts align with privacy obligations
- Support due diligence processes and respond to client security and privacy questionnaires
- Advise on lawful use of personal data in marketing, research, and product innovation
- Incident & Risk Management
- Act as the contact point for data breach response and regulator communications
- Identify and mitigate privacy and compliance risks across departments
- Coordinate with external advisors and DPOs on high-risk or complex matters
- Product & AI Enablement
- Collaborate with Product and Data teams to ensure responsible data and AI use
- Review new tools, APIs, and technologies for compliance implications
You will thrive in this role if
- You bring 3+ years of experience in privacy and data protection, ideally gained in-house
- You have strong knowledge of EU and German data protection law (GDPR, BDSG, TTDSG)
- You’re experienced in commercial contracting and general corporate compliance.
- Ideally, you are a fully qualified German lawyer (Volljurist) who has completed both state examinations (Zweites Staatsexamen)
- You’re confident in advising on both EU and international level
- You’re confident advising internal stakeholders across Product, Research, Tech, and Commercial
- You have excellent legal drafting skills in German and English
- You’re proactive, analytical, and comfortable working independently
- You’re curious about the intersection of privacy, technology, and AI
- You are based in Europe (ideally in Germany, Spain, or the UK)