Privacy Counsel
THE POSITION :
We are a forward-thinking, agile legal team dedicated to safeguarding the trust between people and the organizations that serve them. In a world where data is the new currency, we believe privacy is a fundamental right—not a privilege. Our mission is to help our internal clients and customers innovate responsibly, ensuring that personal information is handled with integrity, transparency, and compliance with evolving global regulations. As part of a health science services company, we support the responsible use of sensitive health, research, and business data in a manner that advances better outcomes while maintaining the highest standards of privacy, ethics, and compliance.
As Privacy Counsel, you will report into the Privacy Office and serve as a key member of our in-house legal team, helping shape how our company navigates the complex and rapidly changing privacy landscape. Your work will directly influence how our organization protects sensitive information, supports health science services, responds to data incidents, and designs privacy-first processes, products, and services. You won’t just interpret the law—you’ll help define and operationalize best practices that set the standard for ethical data use across our business.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Our employees are tasked with delivering excellent business results through the efforts of their teams. These results are achieved by:
- Advise internal business teams on compliance with U.S. federal and state privacy laws (e.g., CCPA/CPRA, HIPAA, GLBA) and international frameworks (e.g., GDPR, UK GDPR), with a particular focus on laws and guidance relevant to health science services and sensitive health-related information.
- Draft, review, and negotiate privacy-related agreements, including data processing addenda, vendor agreements, customer agreements, business associate agreements, and cross-border data transfer arrangements.
- Develop and implement privacy policies, notices, consent management strategies, and internal governance frameworks tailored to a health science services environment.
- Guide internal stakeholders through incident response, including breach notification requirements, escalation procedures, risk assessments, and regulatory reporting.
- Conduct privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, systems, and data uses.
- Monitor legislative developments and advise on emerging privacy trends, technologies, and enforcement actions affecting the company’s operations.
- Collaborate closely with cross-functional teams—including IT, security, compliance, marketing, product, operations, and research-focused teams—to embed privacy into business operations.
- Provide practical, risk-based legal advice to internal clients on the collection, use, sharing, retention, and de-identification of personal and health-related information.
- Demonstrate a commitment to diversity, equity, and inclusion through continuous development, modeling inclusive behaviors, and proactively managing bias.
- All other duties as assigned .
Consistent with the Americans with Disabilities Act (ADA) and applicable state and local laws, it is the policy of EVERSANA to provide reasonable accommodation when requested by an employee with a disability, unless such accommodation would cause an undue hardship for EVERSANA . If reasonable accommodation is needed to perform the essential functions of your job position, please contact Human Resources.
EXPECTATIONS OF THE JOB:
- Travel (Less than 10%)
- Hours (Monday-Friday, 40+ hours per week)
The above list reflects the general details necessary to describe the expectations of the position and shall not be construed as the only expectations that may be assigned for the position.
An individual in this position must be able to successfully perform the expectations listed above.
MINIMUM KNOWLEDGE, SKILLS AND ABILITIES: