Data Privacy Counsel, Office of the Chief Legal Officer

Creative Artists AgencyNashville, TN
Onsite

About The Position

Creative Artists Agency (CAA) is a leading entertainment and sports agency with global expertise in various sectors including filmed and live entertainment, digital media, publishing, sponsorship sales, consumer investing, fashion, and philanthropy. CAA is seeking a Data Privacy Counsel to join its Legal team. This senior-level role will be instrumental in implementing the company's AI programs, advising on and managing data privacy policies, and ensuring compliance with global privacy laws and regulations. The Data Privacy Counsel will report to the Deputy General Counsel and Chief Compliance Officer and will act as a trusted legal advisor to business units and functional teams on data privacy, protection, and governance.

Requirements

  • J.D. from an accredited law school and active bar membership (Tennessee bar admission or ability to register as In-House Counsel).
  • 15+ years of relevant legal experience, with a meaningful focus on privacy law, data protection, and related regulatory matters and issues in technology and/or AI-driven environments.
  • Deep knowledge of global and domestic privacy laws and frameworks, including GDPR, CCPA/CPRA, and other applicable international and state laws.
  • Experience drafting, reviewing, and negotiating privacy-related contractual provisions, including data processing agreements (DPAs) and standard contractual clauses (SCCs).
  • History of advising on legal issues relating to AI products, AI research, or machine learning systems, including familiarity with the machine learning development lifecycle.
  • Familiarity with privacy-enhancing technologies, information security practices, and data governance frameworks.
  • Strong ability to translate complex legal requirements into practical, business-oriented guidance for non-legal audiences.
  • Excellent written and verbal communication skills, with the ability to present to and advise senior leadership and cross-functional audiences.
  • Highly collaborative with strong interpersonal skills and the ability to partner effectively across legal, technology, and business functions.
  • Action-oriented with the ability to manage a substantial workload, set priorities, and meet deadlines in a fast-paced, dynamic environment.
  • Strong business acumen, sound judgment, and a practical, solutions-oriented approach to problem solving.

Nice To Haves

  • Law firm and/or in-house experience preferred.
  • Privacy certifications (e.g., CIPP/US, CIPP/E, CIPM) a plus.
  • Media & Entertainment industry experience a plus.

Responsibilities

  • Develop, implement, and maintain a comprehensive companywide data privacy strategy and program, including policies, procedures, notices, and guidelines that ensure compliance with applicable federal, state, and international privacy laws and regulations.
  • Act as a key leader for the selection and roll-out of CAA’s approved AI platforms, advising on safe and responsible implementation steps, model vulnerabilities, data protection considerations, employee trainings, evolving industry norms/best practices and any other issues that may arise throughout the integration process.
  • Serve as the primary legal advisor on data privacy and data protection matters across the organization, providing counsel to business, technology, finance, tax, marketing, human resources, and other functional teams.
  • Review, draft, and negotiate privacy and data protection provisions in vendor, partner, and client agreements, including data processing agreements (DPAs) and standard contractual clauses (SCCs).
  • Oversee and conduct privacy impact assessments and risk assessments relating to new and existing programs, products, and initiatives that involve the collection, use, or sharing of personal information.
  • Monitor and interpret developments in global privacy laws and regulations, including GDPR, CCPA/CPRA, and other applicable laws, and advise on their impact to CAA’s business operations.
  • Lead and manage the privacy incident response process, including breach assessment, regulatory notification, and remediation across relevant jurisdictions.
  • Collaborate cross-functionally with IT, Information Security, Marketing, Human Resources, and other departments to embed privacy-by-design principles into business processes, systems, and new initiatives.
  • Manage and respond to data subject rights requests in accordance with applicable law, and maintain internal processes for timely and accurate handling.
  • Develop and deliver privacy training and awareness programs for employees across the organization, including communicating legal and regulatory developments in an accessible manner.
  • Advise on cross-border data transfer mechanisms, data localization requirements, and global data governance, supporting CAA’s international operations.
  • Liaise with regulatory authorities, outside counsel, and other external privacy stakeholders and advisors as required.
  • Prepare periodic reports on the privacy program and its compliance posture for senior leadership and other relevant stakeholders.

Benefits

  • Eligible for benefits
  • Discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service