Nova Biomedical

Privacy Counsel

Nova Biomedical$175K — $215K *
Legal & Accounting
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Juris Doctor degree from an accredited law school required.
  • Active membership in good standing with a U.S. state bar required, admission to Massachusetts Bar preferred.
  • Minimum of eight years of relevant legal experience in a law firm, corporate legal department, or similar environment.
  • Extensive knowledge of global privacy, data-protection, data-management, and cybersecurity laws.
  • Experience managing and operationalizing privacy programs across various jurisdictions.

Responsibilities

  • Provide legal oversight and strategic guidance on privacy and data-management programs.
  • Review and negotiate privacy-related legal documents to ensure compliance.
  • Conduct privacy impact assessments and provide recommendations to mitigate risks.
  • Implement and maintain internal privacy policies and data-protection agreements.
  • Monitor and interpret changes in global privacy and information-security laws.
  • Develop and deliver privacy training programs for staff.
  • Collaborate with global teams to promote consistent privacy practices.

Benefits

  • Flexible Medical, Dental, & Vision Coverage
  • Competitive 401k company match
  • Bonus Program, Generous PTO and paid holidays
  • Generous Tuition reimbursement
  • Hybrid and flexible work arrangements
Full Job Description
Job Summary:

Nova Biomedical is seeking a Privacy Counsel to provide legal oversight, risk assessment, and strategic guidance on privacy, data protection, and data-management matters across Nova Biomedical Corporation and its subsidiaries.

The Privacy Counsel will help ensure compliance with applicable global privacy laws and regulations by developing and implementing privacy policies and procedures, reviewing contracts from a privacy perspective, conducting training, and advising business and technology teams on privacy and data-protection risks. This role will work closely with Governance, Risk and Compliance, Information Technology, Information Security, Legal, and business functions to protect Nova Biomedical from legal and compliance risks related to privacy, security, and data management.

In partnership with the Vice President of Governance, Risk and Compliance, the Privacy Counsel will develop short- and long-term plans for managing privacy-related legal matters and minimizing risk to the business. A key near-term priority will be operationalizing and maturing Nova Biomedical's global privacy program following its combination with Advanced Instruments.

Responsibilities:
  • Provide legal oversight and strategic guidance for Nova Biomedical's privacy, data-management, and information-security programs in accordance with applicable U.S. and global privacy laws.
  • Advise business, technology, and legal stakeholders on privacy, data protection, security, and compliance matters.
  • Interpret and apply privacy requirements under the General Data Protection Regulation and applicable U.S. federal and state laws.
  • Implement, maintain, and enforce internal and external privacy policies, procedures, data-protection agreements, and related legal documentation.
  • Ensure privacy policies and procedures reflect evolving legal requirements and relevant industry practices.
  • Draft, review, negotiate, and manage privacy-related legal documents, including:
    • Records of Processing Activities
    • Data Protection Impact Assessments
    • Privacy Impact Assessments
    • Privacy notices
    • Data Processing Agreements
    • Data-transfer agreements
    • Business Associate Agreements
    • Inter-Affiliate Data Transfer Agreements
  • Analyze products, services, technologies, projects, and business initiatives for privacy and data-protection risks.
  • Conduct privacy impact assessments and recommend appropriate measures to mitigate identified risks.
  • Develop, deliver, and lead privacy and data-protection training programs.
  • Establish role-based privacy training, new-hire training, annual refreshers, and appropriate completion records.
  • Support enterprise risk-management activities by identifying, assessing, documenting, and escalating material privacy and data-protection risks.
  • Contribute to risk assessments, risk registers, executive reporting, and related governance activities.
  • Serve as a liaison among Information Technology, Information Security, Legal, Governance, Risk and Compliance, and relevant business functions on privacy and information-security matters.
  • Monitor changes in privacy, data-protection, and information-security laws and regulations.
  • Evaluate and communicate the potential impact of legal and regulatory developments on Nova Biomedical.
  • Collaborate with global team members, particularly stakeholders in the European Union, to promote consistent privacy practices and risk-mitigation strategies.
  • Research complex privacy and data-protection matters and provide practical legal advice and recommendations.
  • Serve as the primary legal point of contact for personal data breaches.
  • Lead the legal aspects of Nova Biomedical's Personal Data Breach process in coordination with Information Technology, Information Security, and other stakeholders.
  • Establish breach-determination criteria, jurisdiction-specific notification requirements, escalation paths, defined responsibilities, and a centralized breach register.
  • Serve as the primary interface with the Data Protection Officer.
  • Support interactions with regulators and outside counsel when required.
  • Provide privacy-related legal support for strategic transactions and other mission-critical initiatives.
  • Support privacy due diligence and integration activities associated with mergers, acquisitions, and other strategic transactions.
  • Provide legal guidance regarding commercial agreements, compliance programs, and healthcare-industry requirements as needed.

Global Privacy Program Development
  • Own and operationalize an enterprise-wide data-subject-rights program.
  • Establish standardized processes for access, rectification, erasure, restriction, objection, portability, consent withdrawal, and opt-out requests involving the sale or sharing of personal data.
  • Develop standardized request-intake channels, response procedures, documentation requirements, and a centralized data-subject-rights log.
  • Ensure the data-subject-rights program addresses applicable requirements under the General Data Protection Regulation, United Kingdom privacy law, Swiss Federal Act on Data Protection, applicable U.S. state privacy laws, Brazil's General Data Protection Law, China's Personal Information Protection Law, Canada's Personal Information Protection and Electronic Documents Act, and Quebec Law 25.
  • Build and maintain an external-facing privacy-notice framework.
  • Develop and maintain an appropriate U.S. employee privacy notice.
  • Maintain streamlined website and California privacy policies with clearly defined ownership and review cycles.
  • Bring applicable consumer-facing channels into compliance with U.S. consumer health-data laws, including the Washington My Health My Data Act, Nevada Senate Bill 370, and the Connecticut Data Privacy Act.
  • Develop and publish a standalone Consumer Health Data Privacy Policy where required.
  • Establish appropriate consent processes for collecting and processing consumer health data.
  • Establish recurring cookie-governance processes across Nova Biomedical web properties.
  • Implement periodic cookie scanning and inventory practices.
  • Establish region-appropriate cookie and tracking-technology consent configurations.
  • Implement required 'Do Not Sell or Share My Personal Information• mechanisms and recognition of Global Privacy Control signals.
  • Establish, publish, and enforce a centralized data-retention and destruction policy and schedule.
  • Define retention periods by data category, applicable legal or business bases, deletion and anonymization protocols, and legal-hold exceptions.
  • Align retention requirements with Records of Processing Activities and applicable privacy notices.
  • Develop and implement operational privacy procedures and standard operating procedures across applicable jurisdictions.
  • Build a comprehensive Data Protection Impact Assessment and Privacy Impact Assessment framework.
  • Establish assessment triggers, templates, ownership requirements, review processes, and workflows.
  • Integrate privacy assessments into project planning, product development, procurement, and vendor onboarding.
  • Establish documented vendor privacy due-diligence procedures.
  • Develop standardized Data Processing Agreement templates and maintain a centralized agreement register.
  • Review and update Nova Biomedical's Inter-Affiliate Data Transfer Agreement.
  • Establish appropriate governance, documentation, metrics, and reporting to measure the maturity and effectiveness of the global privacy program.

Experience Requirements:
  • Juris Doctor degree from an accredited law school required.
  • Active membership in good standing with a U.S. state bar required.
  • Admission to the Massachusetts Bar preferred.
  • Minimum of eight years of relevant legal experience within a law firm, corporate legal department, or comparable environment.
  • Extensive knowledge of global privacy, data-protection, data-management, and cybersecurity laws and regulations.
  • In-depth knowledge of the General Data Protection Regulation and applicable U.S. federal and state privacy laws.
  • Practical experience developing, operationalizing, and maturing global privacy programs.
  • Experience managing Records of Processing Activities, data-subject-rights requests, breach response, impact assessments, retention schedules, cookie and consent management, vendor privacy reviews, and Data Processing Agreements.
  • Experience drafting, reviewing, and negotiating privacy notices, Data Processing Agreements, data-transfer agreements, Business Associate Agreements, and related privacy documentation.
  • Experience interpreting privacy requirements and translating legal obligations into practical business processes.
  • Experience advising on privacy concerns involving products, technology, security, data management, digital platforms, vendors, and business initiatives.
  • Experience partnering with Information Technology, Information Security, Governance, Risk and Compliance, and business teams.
  • Experience identifying, assessing, documenting, and escalating privacy and data-protection risks.
  • Strong understanding of enterprise risk-management principles and practices.
  • Ability to evaluate privacy incidents and guide personal data-breach response and notification decisions.
  • Experience working with international organizations and resolving differences in legal requirements, business practices, and approaches across jurisdictions.
  • Experience supporting commercial contracting, compliance programs, mergers and acquisitions, healthcare-industry matters, and strategic transactions is a plus.
  • Certified Information Privacy Professional certification or a comparable privacy credential is preferred.
  • Demonstrated thought leadership in privacy and data-protection law.
  • Ability to balance legal rigor and regulatory compliance with business agility and practical operational needs.
  • Strong business acumen and an understanding of the legal processes required to support a growing global organization.
  • Strong leadership, collaboration, negotiation, and influencing skills.
  • Excellent written and verbal communication skills, including policy drafting, legal analysis, presentations, training, and stakeholder communications.
  • Demonstrated ability to build relationships and collaborate effectively with employees, executives, outside counsel, regulators, vendors, and other external stakeholders.
  • Strong change-leadership skills with the ability to assess complex challenges, develop practical plans, and implement effective solutions.
  • Strong analytical, research, organizational, and problem-solving skills.
  • Ability to manage multiple legal matters, privacy initiatives, deadlines, and stakeholder priorities.
  • High level of judgment, professionalism, discretion, and integrity.
  • Proficiency with standard business and legal technology, including word-processing, spreadsheet, database, presentation, and internet-based software.

Physical Requirements and Working Conditions:
  • Comfort with working at a computer for extended periods.
  • Capacity to lift and carry up to [25• 50] pounds as required
  • Able to communicate effectively via phone, video, and written communication.
  • Occasional need to move about the office to access meetings or resources.

Why Work for Nova Biomedical
  • Flexible Medical, Dental, & Vision Coverage
  • Competitive 401k company match
  • Bonus Program, Generous PTO and paid holidays
  • Generous Tuition reimbursement
  • Hybrid and flexible work arrangements
  • Professional development, engagement and events
  • Company marketplace for lunch and snacks in our Norwood, MA, Billerica, MA and Westbrook, ME offices
  • Company subsidized cafeteria in our Waltham, MA office

Work Location: Hybrid in Waltham MA Monday - Thursday

Targeted Salary Range: $175,000 to $215,000 annually

Nova Biomedical believes in transparency and integrity throughout all we do, including compensation. The provided salary range for this role represents the expected base salary or hourly rate for this opening. Actual compensation will be commensurate with the candidate's experience and may vary based on individual factors such as location, skills, and education.

About Nova Biomedical

Nova Biomedical is a privately held medical device company based in Waltham, Massachusetts. The company develops, manufactures, and sells blood testing analyzers, and provides diagnostic testing solutions for hospitals, clinics, and laboratories worldwide. Nova Biomedical's products are used in critical care settings, emergency rooms, physician offices, and clinics. The company's products include point-of-care blood gas and electrolyte analyzers, as well as benchtop laboratory analyzers. Nova Biomedical was founded in 1976 by Robert C. Collins, and is still owned by the Collins family.
Learn more about Nova Biomedical
Size
1,200 employees
Industry
Founded
1976

Similar Jobs

More Jobs at Nova Biomedical

More Legal & Accounting Jobs

Find similar Privacy Counsel jobs: