Privacy Counsel
Aon
- Location
- Krakow, Poland
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 2h ago
About this role
Are you passionate about privacy law and looking to deepen your expertise in GDPR and data protection? Would you like to work with international teams, helping solve complex privacy challenges while enabling business success? Join our Global Privacy, Data & Technology Office team in Poland and help shape practical, business-focused privacy solutions for a global organization. This role can be based in Kraków or Warsaw and offers flexibility to work in a hybrid model, combining virtual work with time in the office, aligned with local smart working policies. Aon is in the business of better decisions At Aon, we shape decisions for the better to protect and enrich the lives of people around the world. As an organization, we are united through trust as one inclusive team and we are passionate about helping our colleagues and clients succeed. What the day will look like As a Privacy Counsel, you will support Aon's global privacy program by working closely with privacy professionals, legal colleagues, security teams, and business partners. This role helps ensure compliance with GDPR and other EMEA data protection requirements. Key responsibilities include: Supporting the assessment and management of Data Subject Requests (DSRs) under GDPR and applicable local laws. Assisting with the review and handling of privacy and security incidents, including assessing notification obligations and helping prepare regulatory, contractual, and stakeholder communications. Reviewing and negotiating privacy-related contractual provisions, including Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and privacy and security schedules, using established frameworks and playbooks. Supporting Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) by identifying risks, documenting mitigation measures, and facilitating approvals. Contributing to privacy policies, guidance, training materials, and regulatory monitoring activities across the EMEA region. Collaborating with cross-functional teams to provide practical, risk-based privacy advice that supports business objectives. How this opportunity is different This role offers an outstanding opportunity to build your privacy law career within an international company operating across multiple jurisdictions. You will work alongside experienced privacy counsels and privacy professionals who are committed to knowledge sharing, development, and collaboration. You will gain exposure to a broad range of privacy matters, including data subject rights, incident response, contractual privacy requirements, and privacy assessments. This role offers the chance to collaborate with teams in Legal, Privacy, Information Security, Technology, and business. You will develop technical expertise and skills in managing collaborators in a diverse international setting. Skills and experience that will lead to success Qualified lawyer (advocate, legal advisor, or equivalent) in Poland or another EMEA jurisdiction, with 1–3 years of post-qualification legal experience gained in private practice and/or an in-house legal environment. Strong knowledge of GDPR and a demonstrated interest in privacy and the protection of sensitive data, with experience supporting Data Subject Requests and privacy/security incident matters. Experience reviewing privacy contractual arrangements and/or supporting privacy assessments such as PIAs and DPIAs. Excellent legal research, drafting, analytical, and problem-solving capabilities combined with a practical, results-focused approach. Strong communication and collaboration skills, with the ability to work effectively across international and cross-functional teams while handling sensitive and confidential matters with discretion. #LI-JW1 #LI-HYBRID 2584029