EU remote
Data Privacy Counsel
About this role
The Company We are Zeekr, built on a decade of European experience. We are a premium electric vehicle and technology solutions brand from Geely Holding Group, one of world’s largest automotive companies. Our goal and vision is to accelerate the shift to fully electrified mobility. We are committed to driving the future of transportation with cutting-edge technology and a customer-centric approach. The role As a Data Privacy Counsel , you will support the implementation of the ZEEKR Data Privacy Strategy, acting as data privacy specialist to support internal teams and help develop a privacy by design mind-set.
This is what you will do: Conduct data protection impact assessments (DPIAs) for new projects or initiatives involving the processing of personal data. Provide guidance to internal teams on data privacy best practices and ensure compliance with privacy requirements, measure process effectiveness, and develop action items to remediate identified risks. Manage and respond to data subject access requests (DSARs) and other privacy-related inquiries from individuals and authorities.
Perform Data Protection Impact Assessments (DPIAs), records of processing activities (RoPA), and privacy-by-design reviews for new products, features, and vehicle data flows Manage Data Transfer Impact Assessments for EU cross-border personal data transfers. Draft and implement data privacy policies and procedures in accordance with applicable data protection laws and regulations. Draft, review and negotiate Data Processing Agreements.
Develop and maintain internal privacy policies, notices, and training materials tailored to automotive and connected-vehicle data processing. Support data privacy audits (both internal and external audits). Partner with IT security, product, and engineering teams on privacy engineering matters and vendor due diligence. Support pan-EU Data Privacy team on data privacy matters across all EU markets. To be successful in the role you will demonstrate: 3+ years of experience in of relevant experience in data protection/privacy law, ideally combining law firm and in-house experience in a technology companies.