EU remote
Legal Counsel
About this role
At xpate , we are building modern payment infrastructure for ambitious digital businesses. Our legal function works closely with teams across the company, helping xpate scale in a regulated, multi-jurisdictional environment. We are looking for a Legal Counsel who combines strong legal judgment with a practical, operational mindset. This role is ideal for someone who enjoys not only reviewing contracts and supporting regulatory matters, but also improving legal processes, data governance, and automation.
Legal support You will support the legal function across a broad range of commercial, operational, regulatory, and data protection matters, including: Maintaining data protection matters together with the DPO, including privacy engineering and privacy-by-design initiatives. Reviewing and advising on NDAs, service agreements, vendor documentation, marketing materials, and other commercial or operational legal documents.
Supporting the collection, analysis, and structuring of legal information for internal decision-making. Assisting payment scheme, compliance, risk, product, and operations teams with ad hoc legal input. Providing practical legal guidance in a fast-moving fintech environment. Legal operations You will also play an important role in building a scalable and well-organized legal function, including: Maintaining the Legal Single Source of Truth for multi-jurisdictional licenses, registrations, legal requirements, and related documentation.
Supporting finance, risk, compliance, and operational teams with the collection and preparation of legal data. Overseeing the Contract Lifecycle Management system, including the vendors and outsourcing register. Maintaining and improving legal function automation together with the IT team. Coordinating interdepartmental communication to ensure legal data is collected, updated, and accessible. Helping improve legal workflows, templates, registers, and internal processes.
Legal education and relevant experience in fintech, payments, data protection, or regulatory legal work. Extensive experience in payment acquiring, fintech, and other regulated financial environments, including collaboration with banks, payment institutions, payment service providers, and SaaS companies. Strong understanding of GDPR, privacy-by-design principles, outsourcing requirements, and payment scheme rules (e.g., Visa and Mastercard).