Please note that Digital Turbine is a hybrid work environment-only candidates local to the posting location will be considered.DT (Digital Turbine) sits at the intersection of mobile app distribution, device monetization, and the programmatic advertising ecosystem - a position that requires us to navigate one of the most dynamic privacy and data protection landscapes in the industry. The Privacy Counsel is the person who helps us do that with rigor and speed.
This
Privacy Counsel role is a high-visibility, high-impact position within the Legal team. You will serve as a hands-on advisor on global privacy and data protection matters across DT's platform, product, and partner ecosystem - advising on everything from day-to-day compliance questions to the privacy implications of new product launches and commercial deals.
You will work closely with the Legal, Product, Engineering, Partnerships, and Ad Operations teams to embed privacy considerations into how DT builds and ships products. This is a hands-on role for an experienced attorney who can move fluidly between detailed legal analysis and practical, business-friendly guidance, and who is comfortable being the primary privacy point of contact for a fast-moving, technical organization.
About the Privacy Counsel role:Privacy & Data Protection AdvisoryServe as day-to-day legal advisor on global privacy and data protection laws applicable to DT's business, including CCPA/CPRA and other U.S. state privacy laws, GDPR, UK GDPR, and the ePrivacy Directive. Knowledge of other countries privacy laws is an advantage.
Advise Product and Engineering teams on privacy-by-design considerations for new features, identifiers, and data flows, including data minimization, consent and opt-out signaling, pseudonymization and de-identification standards, retention, and purpose limitation.
Advise on the allocation of privacy roles and responsibilities (e.g., controller/processor, business/service provider) across DT's products and partnerships, and maintain the data-flow documentation that supports DT's positions in commercial negotiations.
Review, negotiate, and advise on data processing agreements, international data transfer mechanisms (e.g., SCCs and the UK IDTA), vendor contracts, and partner agreements from a privacy and data protection perspective, and maintain DT's DPA templates and negotiation positions.
Track and interpret evolving privacy laws and regulatory enforcement and guidance (e.g., FTC, CPPA, and EU/UK data protection authorities) globally, and translate them into practical guidance for internal stakeholders.
Compliance Programs & Risk ManagementSupport and help mature DT's privacy compliance program, including policies, data inventories and records of processing, data retention and de-identification standards, vendor and sub-processor management, privacy impact assessments, and training materials.
Own and maintain DT's privacy notices and external privacy disclosures.
Partner with Security and Engineering teams on data breach response protocols and incident management, including notification analysis under applicable laws and contractual commitments.
Monitor and respond to regulatory inquiries, audits, partner and customer privacy questionnaires and audits, and consumer and data subject rights requests (including opt-out and Global Privacy Control signals) in coordination with cross-functional teams.
Help build scalable processes and playbooks so that privacy review can keep pace with DT's product and commercial velocity.
Cross-Functional PartnershipAct as an internal consultant and thought partner for Product, Partnerships, Sales, and Ad Operations teams, helping them understand privacy risk and translate it into actionable product and deal decisions, and exercising sound judgment on when a matter requires escalation to the Head of Legal or outside counsel.
Prepare clear, business-friendly materials and guidance that can be used by non-legal stakeholders without extensive legal background.
Collaborate with outside counsel on complex or jurisdiction-specific matters as needed, with an eye to cost and to keeping institutional knowledge in-house.
About YOU as the Privacy Counsel:4+ years of experience practicing privacy and data protection law, in-house or at a law firm, including hands-on experience negotiating data processing agreements and advising on controller/processor and business/service provider allocation, ideally with exposure to the technology, ad tech, online and mobile ecosystem.
Strong working knowledge of global privacy frameworks, including CCPA/CPRA and other U.S. state privacy laws, COPPA and children's privacy requirements, GDPR, ePrivacy Directive, and other applicable U.S. and international data protection laws.
Comfort working directly with engineers and product teams to understand how data is actually collected and used before advising.
Demonstrated ability to translate complex legal requirements into clear, practical, and actionable guidance for non-legal, technical, and business stakeholders.
Strong written and verbal communication skills, with close attention to detail and the ability to produce work that is sharp, clear, and immediately usable by busy stakeholders.
Comfort operating in a fast-paced, matrixed environment, managing multiple workstreams and shifting priorities independently.
J.D. and active bar membership in good standing in any U.S. state (or eligibility for registered in-house counsel status in the state of employment).
CIPP/E, CIPP/US, or comparable privacy certification.
Preferred experience/skills:- Familiarity with the mobile app ecosystem, and the ad-tech industry.
- Familiarity with the ad-tech industry frameworks (e.g., IAB TCF and GPP) and platform policies is an advantage.
- Experience building or scaling a privacy compliance program from the ground up.
- Familiarity with emerging areas such as age assurance, AI governance (including the EU AI Act and U.S. state AI laws), and state-specific children's privacy laws.
- Experience supporting large telecommunication companies
- Experience supporting multi-party data supply chain.
- Experience handling regulatory investigations or inquiries from data protection authorities (such as the FTC, the CPPA, ICO, CNIL.
- Familiarity with privacy and data protection laws in other markets globally (e.g., Brazil, Japan, South Korea, India) is an advantage.
At DT, we are committed to pay transparency and equitable compensation. (For New York-based candidates). The salary range for this position is
$165,000 - $192,000, and is based on experience, skills, and qualifications. In addition to competitive pay, we offer a comprehensive benefits package, including (stock options, unlimited PTO and performance based bonus). We believe in fostering an environment where employees are valued and compensated fairly for their contributions.
The company is headquartered in Austin, Texas, with global offices in New York, Los Angeles, San Francisco, London, Berlin, Singapore, Tel Aviv, and other cities around the world, serving top agency, app developer, and advertising markets.
Digital Turbine will process the information you provide during the application process in accordance with the Digital Turbine Global Recruitment Privacy Notice.