What are the responsibilities and job description for the Privacy Counsel position at BD?
Job Description Summary
Job Description
Position Summary:
The Privacy Counsel–Segments is a member of the Global Privacy LT and serves the BD Privacy and Data Protection Strategy and Program in the Segment and related Business Units, reporting to the Global Head of Privacy.
This role is responsible for assisting the Business Units in:
―ensuring Privacy by Design and by Default requirements are embedded in BD Products and Services, and the BD digitalization strategy is appropriately supported, assessed and cleared, in accordance with the BD Privacy and Data Protection Strategy and Program
―developing and establishing fit-for-purpose written standards, processes and controls to support delivery of BD Products and Services to customers, as well as BD commercial initiatives, in line with sector specific requirements and expectations of regulators
―providing qualified advice on Technical and Organizational Measures (TOMs) to be implemented, and any other technical and security related aspects of privacy, in coordination with the members of the BD Global Privacy Leadership Teams and local DPOs
Essential / Key Job Responsibilities:
―Privacy Counselling: monitor the evolution of the privacy regulatory landscape and escalate sector specific laws, regulations and standards impacting BD Products and Services (e.g. artificial intelligence, Internet of Medical Things, analytics, automated decision making, anonymization), provide businesses and relevant supporting functions with expert advice, and support the Segment and related Business Units to design appropriate processes and controls to address/mitigate gaps and risks related to privacy by design and by default
―Project Management: provide project management leadership and support for complex business and privacy related projects in the Segment and related Business Units, ensure privacy requirements are prioritized at the very outset of any project and develop creative solutions to embed applicable privacy requirements in the business planning of commercial activities
―Data Lifecycle Management: coordinate mapping and documentation of global BD Products and Services and provide business support for analysis of privacy assessments in line with applicable data protection laws in the Segment
―Written Standards: under the direction of the Global Head of Privacy, develop and implement effective, proportionate privacy written standards to support repeatable business initiatives and address specific one-off projects by nimble, user friendly documents and guidelines, develop privacy white papers for Products to describe existing TOMs
―Training & Awareness: develop and deliver training plans for the Segment and related Business Units in line with BD Segment specifics and needs and the evolution of privacy regulations
―Third Party Management: support privacy third party assessments and transfer impact assessments and, assisted by the Global Head of Privacy, manage privacy relevant contract templates in collaboration with appropriate functions
―Incident Management and Individual Rights Processing: detect and escalate potential vulnerabilities in BD Products and Services and digital solutions (websites and mobile apps), which may expose BD to complaints from data subjects or give rise to incidents and personal data breaches, and develop solutions to prevent such outcomes, in coordination with the Global Privacy LT members and local DPOs
―Monitoring and Remediation: support the design and delivery of plans for privacy by design and by default compliance, auditing, and monitoring activities to assess the effectiveness and efficiency of the BD Privacy and Data Protection Program
Education and experience requirements:
Active license to practice law in a jurisdiction and capable of meeting admission requirements in relevant jurisdiction, and Juris Doctorate Degree
5 years’ experience as a practicing attorney, with strong familiarity with privacy, security, and data protection regulations, including (but not limited to) HIPAA, GDPR, FTC Section 5, and state privacy laws
IAPP certification(s): CIPP, CIPM, CIPT strongly preferred
Knowledge and experience of building and maintaining programs and/or controls in a highly regulated area
Additional or Preferred Qualifications
3 years’ experience as an attorney specializing in privacy and data protection as
in-house counsel or in a law firmPrevious employment with a healthcare-related organization, or regulatory agency
Experience of working in a multinational company and a complex, matrixed environment is a significant plus
Primary Work Location
USA NJ - Franklin LakesAdditional Locations
Work Shift