Edible Arrangements

Sr. Privacy Compliance Specialist

Edible Arrangements$90K — $110K *
Legal & Accounting
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree; preferred background in privacy, compliance, legal operations, or data governance.
  • 3-5 years in privacy or compliance roles, with hands-on experience in consent management platforms (e.g., OneTrust).
  • Experience with Shopify or e-commerce privacy compliance.
  • Knowledge of GDPR, CCPA, and state privacy laws with experience managing Data Subject Access Requests (DSARs).
  • Direct vendor management experience, including support escalation and contract negotiations.
  • Familiarity with technical workflows and ability to collaborate with engineering teams.
  • Proficient in Microsoft 365 and analytics platforms.

Responsibilities

  • Own and optimize the privacy compliance platform, including consent management and regulatory settings.
  • Serve as primary contact for the privacy platform vendor and manage relationship effectively.
  • Define and improve privacy operations including consent governance and DSAR processing.
  • Manage end-to-end DSAR and data deletion processes, ensuring compliance and audit readiness.
  • Monitor and coordinate DSAR response times with internal teams and vendors to meet deadlines.
  • Maintain inventory of cookies and third-party vendors, ensuring alignment with consent preferences.
  • Conduct audits on tracking technologies to ensure compliance with consent signals.

Benefits

  • Work onsite at the Corporate Office in Sandy Springs, GA, Monday to Friday.
  • Involvement in strategic initiatives post-Shopify migration for enhanced privacy compliance.
  • Collaboration with multiple departments (Legal, Engineering, Marketing) for comprehensive compliance approach.
Full Job Description
Sr. Privacy Compliance Specialist

The Big Picture:

Edible Brands® is committed to maintaining the highest standards of privacy compliance and regulatory adherence as we scale our operations across our portfolio of brands and geographies. The Privacy Compliance Specialist is a hands-on technical ownership role for our privacy and consent management platform (currently OneTrust), and the operational backbone of our Data Subject Access Request (DSAR) and consent management programs. This role strategically bridges Legal, Information Security, Engineering, Marketing Operations, and Data Analytics to establish and maintain enterprise-wide privacy governance, data subject request management, and regulatory compliance.

As privacy regulations expand (GDPR, CCPA, state privacy laws, and emerging frameworks), this role ensures our organization has clear ownership of Data Subject Access Requests (DSARs), deletion workflows, consent management, and cross-system compliance. The ideal candidate is detail-oriented, technically hands-on, systems-minded, and comfortable navigating ambiguity while coordinating across technical, legal, and business teams. This role reports to Legal/Compliance leadership and is essential to our post-Shopify migration strategy.

Location: This position will work onsite out of our Corporate Office in Sandy Springs, GA Monday - Friday.

What this looks like day to day:
  • Own the implementation, administration, and optimization of the privacy compliance platform (e.g., OneTrust), including consent management, preference centers, cookie categorization, regulatory settings, workflows, user permissions, integrations, testing, and deployments.
  • Serve as the primary point of contact and relationship owner for the privacy platform vendor, managing support escalations, tracking contract terms and renewal timelines, and coordinating any implementation or professional services engagements.
  • Define, document, and continuously improve privacy operations, including consent governance, Data Subject Access Request (DSAR) intake, identity verification, deletion workflows, cross-functional execution procedures, and audit-ready documentation.
  • Manage end-to-end DSAR and data deletion processes across all business systems, meeting statutory response deadlines and other applicable laws, ensuring timely completion, regulatory compliance, and maintenance of audit trails and proof of deletion.
  • Monitor DSAR response timelines, coordinate execution with internal teams and third-party vendors, verify request completion across systems, and escalate risks or delays as needed.
  • Maintain a complete inventory of cookies, tags, third-party vendors, and data integrations across all digital properties, ensuring proper categorization and alignment with user consent preferences.
  • Conduct ongoing cookie, tag, and tracking technology audits (including via Google Tag Manager) to identify undocumented technologies and partner with Marketing to ensure analytics and marketing tools honor consent signals.
  • Serve as the primary privacy operations partner to Legal, Engineering, Marketing, Information Security, Data Analytics, and external vendors by coordinating governance meetings, compliance initiatives, vendor privacy reviews, and cross-functional projects.
  • Partner with Legal to support privacy notices, data processing agreements, regulatory interpretation, and broader privacy governance initiatives.
  • Stay current on GDPR, CCPA, and emerging U.S. state privacy laws; prepare compliance reports and audit documentation while identifying, mitigating, and escalating privacy risks and compliance gaps.
  • Support the development of privacy policies, data governance standards, and best practices for data collection, processing, retention, and deletion across the organization.
  • Maintain and continuously update the organization's data inventory / Records of Processing Activities (RoPA) across business systems.


What you bring:
  • Bachelor's degree required; background in privacy, compliance, legal operations, or data governance preferred.
  • Minimum 3-5 years of experience in privacy, compliance, legal operations, or data governance roles, including direct hands-on configuration (not just use) of consent management or privacy platforms (OneTrust, TrustArc, Termly, or similar)
  • Hands-on experience with Shopify, e-commerce platforms, or retail-specific privacy compliance.
  • Demonstrated knowledge of GDPR, CCPA, and state privacy laws; experience managing Data Subject Access Requests (DSARs) or data deletion requests against statutory deadlines.
  • Experience partnering directly with vendors including support escalation, contract renewals and negotiations, and evaluation of vendor performance.
  • Familiarity with engineering/development workflows and the ability to work with technical teams.
  • Proficiency with Microsoft 365, data inventory/mapping tools, and analytics platforms.
  • Preferred:
  • CIPP (Certified Information Privacy Professional) certification or willingness to pursue.
  • Experience with data inventory or data governance platforms (Collibra, Traction, Alation).
  • Background in a multi-brand, regulated, or scaled legal/compliance function.

How you work:
  • Strong project management and organizational skills, with the ability to manage multiple priorities and coordinate across teams.
  • Excellent written and verbal communication skills, with the ability to translate technical and legal concepts for diverse audiences.
  • Strong attention to detail, discretion, and the ability to handle confidential information.
  • Comfortable being the in-house technical owner of a critical compliance system, proactively flagging risk rather than being asked.

About Edible Arrangements

Edible Arrangements is a franchise company that specializes in fresh fruit arrangements, chocolate-dipped fruit, and other fruit-based gifts. The company was founded in 1999 by Tariq Farid and is headquartered in Wallingford, Connecticut. Edible Arrangements products are made with fresh fruit and are designed to be both healthy and delicious. The company's product line includes fruit bouquets, chocolate-dipped fruit, smoothies, and other fruit-based treats. Edible Arrangements products are sold online and in over 1200 franchise locations worldwide.
Learn more about Edible Arrangements
Size
1,000 employees
Industry

Similar Jobs

More Jobs at Edible Arrangements

More Legal & Accounting Jobs

Find similar Sr. Privacy Compliance Specialist jobs: