Privacy & Data Protection Analyst

King & SpaldingAtlanta, GA
Hybrid

About The Position

King & Spalding is a leading global law firm committed to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape. We are seeking a Privacy & Data Protection Analyst to support and mature the firm’s privacy program. This role will work closely with Information Security, Legal, Information Governance, Procurement, HR, the Privacy Committee, and other business stakeholders to help the firm govern, protect, and responsibly use personal information, including client information, employee HR data, PHI, Controlled Unclassified Information (CUI), and other regulated or sensitive data types.

Requirements

  • Bachelor’s degree in a related field or equivalent professional experience.
  • 3+ years of experience supporting privacy, data protection, or regulated data governance programs.
  • Working knowledge of privacy and data protection concepts, including personal information, protected health information, data processing agreements, data transfers, data subject rights, privacy notices, and records of processing or data flow documentation.
  • Experience reviewing privacy or security terms in vendor agreements, client contracts, or similar contractual documents.
  • Familiarity with privacy and security frameworks or requirements such as HIPAA, GDPR/UK GDPR, U.S. state privacy laws, NIST, ISO 27001, NIST 800-171, or CMMC.
  • Strong writing, organization, and stakeholder management skills, with the ability to keep work moving across legal, technical, and business teams.
  • Sound judgment, attention to detail, and the ability to apply privacy and security requirements in a practical, business-aware manner.

Nice To Haves

  • Privacy, security, or risk certifications such as CIPP/US, CIPP/E, CIPM, CIPT, CISSP, CISA, CISM, CRISC, or related credentials preferred.
  • Experience in a law firm, professional services, regulated industry, or client-service environment preferred.

Responsibilities

  • Support the firm’s privacy program, including Privacy Committee meeting coordination, agenda and materials preparation, follow-up tracking, privacy program updates, and governance documentation.
  • Support the review and negotiation of vendor and client privacy requirements, including Data Processing Agreements (DPAs), data transfer terms, privacy provisions within client agreements and Outside Counsel Guidelines, AI-related requirements, and other contractual data protection obligations.
  • Assess how vendors and software tools collect, use, store, share, and protect sensitive privacy-related information as part of the firm’s third-party risk management program.
  • Complete client privacy and AI assessments and questionnaires, working with internal stakeholders to demonstrate the firm’s controls and help ensure clients remain confident that their sensitive information is appropriately protected.
  • Manage and improve operational privacy processes, including data subject access request intake, tracking, and coordination; cookie and consent management; privacy notice updates; and privacy-related policy maintenance.
  • Lead governance activities for regulated and controlled information types, such as HIPAA-regulated PHI and Controlled Unclassified Information (CUI), including advising teams on the handling of especially sensitive matters, by coordinating compliance assessments, supporting initiatives such as HIPAA Security Risk Assessments and CMMC audits, and driving remediation and program maturity efforts.
  • Analyze highly sensitive or high-risk matters (e.g., significant PII, PHI, or sensitive government/regulatory matters) and advise engagement teams on appropriate data handling, access, and protection measures.
  • Maintain awareness of relevant privacy, data protection, AI, and regulated data requirements in jurisdictions where the firm operates, and translate changes into practical guidance for internal stakeholders.
  • Own core privacy governance activities in OneTrust, including ROPAs, PIAs/DPIAs, TIAs, vendor and application privacy assessments, data flow documentation, privacy risk tracking, remediation coordination, and stakeholder guidance.

Benefits

  • health and wellness plan
  • life and disability insurance
  • flexible spending accounts
  • health savings account
  • 401(k) plan
  • profit sharing plan
  • substantial Paid Time Off (PTO) program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service