Takaisin kaikkiin työpaikkoihin

Privacy, Data & Cyber Regulatory Counsel

Nokia · Espoo

Hybridisenior💰 5,950–7,250 EURLegal · TechnologyJulkaistu 09.09.2026 klo 03.00

Taidot

gdpruk gdprnis2cyber resilience acteu data acteu ai actdata protectioncybersecurity regulationregulatory compliancecontract draftingdata protection impact assessments (dpias)incident responsesupervisory authority engagementai governance

Työn kuvaus

Tiivistelmä työpaikkailmoituksesta: This role sits in Nokia's Global Privacy, Data and Cyber Regulatory Office as the primary legal interface for EU/UK privacy, cybersecurity and AI regulatory matters and is part of an AI-first legal team. You will provide expert legal advice on GDPR/UK GDPR, NIS2, the Cyber Resilience Act, the EU Data Act and the EU AI Act, lead Nokia's legal engagement on the Cyber Resilience Act, and own supplier security documentation and privacy/security contractual provisions. The role requires a qualified lawyer admitted in at least one EU member state or in England and Wales with a minimum of 10 years' post-qualification experience and demonstrable hands-on knowledge of GDPR, cybersecurity regulation and supervisory authority engagement. You will conduct DPIAs, lead privacy and cyber incident response and regulatory notifications, use AI tools to scale legal workflows, manage external counsel, and build collaborative relationships across engineering, security, procurement and business teams. Tämä tiivistelmä on luotu tekoälyn avulla. As part of Nokia's Legal job family, this role sits within the Global Privacy, Data and Cyber Regulatory Office (GPDCRO) — Nokia's centre of excellence for data protection, cybersecurity regulation, and emerging data-related law — reporting to the Head of Privacy and Data Trust. It applies deep specialist expertise across data protection, cybersecurity law, AI governance, commercial contracting, and incident response, acting as the primary legal interface between Nokia's European and UK business operations and the rapidly evolving regulatory landscape. This is an AI-first legal team. We actively build and use AI-assisted workflows — from agentic legal research to automated regulatory horizon scanning — and expect everyone in the team to engage seriously with what AI can do for legal work. The role works alongside counterparts covering the Americas, Middle East and Africa, and Asia Pacific, with genuine opportunity to collaborate on cross-jurisdictional matters. If you are excited by building the legal function of the future rather than maintaining the legal function of the past, you will fit in here. HOW YOU WILL CONTRIBUTE AND WHAT YOU WILL LEARN Provide expert legal advice across the full EU and UK data protection and cybersecurity regulatory landscape, including GDPR, UK GDPR/DPA 2018, NIS2, the EU Cyber Resilience Act, the EU Data Act, the EU AI Act, and applicable national implementing legislation. Lead Nokia's legal engagement with the Cyber Resilience Act, including the legal track for open-source software obligations in network products, conformity requirements, and evolving delegated acts. Own the legal workstream for Nokia's supplier security documentation, including the modular security appendix applied across Nokia's global supply chain. Advise on privacy and cybersecurity requirements in customer contracts and procurement processes, including data processing agreements, security appendices, and data localisation requirements. Conduct horizon scanning across EU and UK regulatory developments, triaging legal risk and preparing clear, actionable briefings for senior stakeholders and governance forums. Lead legal review of Nokia's use of regulated data types — telecom subscriber data, network data, employee data — advising on permissible use cases, anonymisation standards, and access controls. Conduct and review Data Protection Impact Assessments for high-risk processing activities, including AI-driven use cases and network analytics. Actively identify opportunities to move Nokia's compliance posture from paper-based to demonstrable — working with engineering, security, and data teams to embed legal requirements as technical controls into systems and workflows. In practice: data minimisation enforced at the API layer, purpose restrictions implemented as access controls, anonymisation validated against re-identification risk rather than assumed. Play a central role in cyber and privacy incident response — making timely, legally sound decisions on notification obligations under NIS2, GDPR Articles 33/34, and applicable national legislation, and maintaining Nokia's incident response legal playbook. Provide privacy, data use, and cyber law input into Nokia's AI governance programme and internal AI deployment — ensuring legal requirements are embedded at design stage. Deliver training and legal briefings to internal teams, leveraging AI tools to create scalable, repeatable guidance — building legal capability across the organisation rather than creating dependency on the legal team. Manage external legal counsel on EU and UK matters, with accountability for scope, quality, and cost. Build trusted, collaborative relationships across Information Security, Product Security, Procurement, Business Groups, CTO, and Human Resources — acting as a proactive legal partner and handling matters end-to-end, enabling the Head of Privacy and Data Trust to focus on
Kirjaudu ilmaiseksi tallentaaksesi tämän työpaikan.