1

Privacy Data Protection Manager Jobs (NOW HIRING)

next page

Showing results 1-20

Privacy Data Protection Manager information

See salary details

$99.5K

$115.5K

$129.5K

How much do privacy data protection manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for privacy data protection manager in the United States is $115,505.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What does a Privacy Data Protection Manager do?

A Privacy Data Protection Manager is responsible for ensuring that an organization complies with data protection laws and regulations, such as the GDPR or CCPA. They develop and oversee policies and procedures that safeguard sensitive information, manage privacy risk assessments, and respond to data breaches or privacy incidents. This role also involves training staff on privacy best practices, conducting audits, and acting as a liaison with regulatory authorities. Their work is critical in protecting both the organization and its clients from privacy risks and legal repercussions.

What are some typical challenges a Privacy Data Protection Manager faces when implementing new data privacy regulations across an organization?

A Privacy Data Protection Manager often encounters challenges such as ensuring company-wide understanding and compliance with complex, evolving regulations like GDPR or CCPA. Coordinating efforts across departments—especially IT, legal, and HR—can be demanding, as each may have different data practices and priorities. Additionally, updating and integrating new privacy policies into existing workflows while minimizing disruptions requires strong project management and communication skills. Staying current with regulatory changes and training staff are also ongoing responsibilities that require proactive engagement.

What are the key skills and qualifications needed to thrive as a Privacy Data Protection Manager, and why are they important?

To thrive as a Privacy Data Protection Manager, you need a deep understanding of data protection laws (like GDPR or CCPA), risk management, and privacy frameworks, typically supported by a relevant degree and certifications such as CIPP or CIPM. Familiarity with privacy management software, data mapping tools, and compliance monitoring systems is essential. Strong analytical thinking, problem-solving, and effective communication are crucial for ensuring compliance and building trust across the organization. These skills are vital for safeguarding sensitive data, reducing legal risks, and fostering a culture of privacy and accountability.

What are popular job titles related to Privacy Data Protection Manager jobs?

For Privacy Data Protection Manager jobs, the most frequently searched job titles are:

Privacy & Data Protection Analyst

Atlanta, GA • On-site

King & Spalding LLP
Law Firms • 1 - 5K employees

$79K - $94K/yr

Other

Medical, Life, Retirement, PTO

Posted 7 days ago


Job description

King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape.

We are seeking a Privacy & Data Protection Analyst to support and mature the firm’s privacy program. This role will work closely with Information Security, Legal, Information Governance, Procurement, HR, the Privacy Committee, and other business stakeholders to help the firm govern, protect, and responsibly use personal information, including client information, employee HR data, PHI, Controlled Unclassified Information (CUI), and other regulated or sensitive data types.

POSITION OVERVIEWKEY RESPONSIBILITIES
  • Support the firm's privacy program, including Privacy Committee meeting coordination, agenda and materials preparation, follow-up tracking, privacy program updates, and governance documentation.
  • Support the review and negotiation of vendor and client privacy requirements, including Data Processing Agreements (DPAs), data transfer terms, privacy provisions within client agreements and Outside Counsel Guidelines, AI-related requirements, and other contractual data protection obligations.
  • Assess how vendors and software tools collect, use, store, share, and protect sensitive privacy-related information as part of the firm's third-party risk management program
  • Complete client privacy and AI assessments and questionnaires, working with internal stakeholders to demonstrate the firm's controls and help ensure clients remain confident that their sensitive information is appropriately protected
  • Manage and improve operational privacy processes, including data subject access request intake, tracking, and coordination; cookie and consent management; privacy notice updates; and privacy-related policy maintenance.
  • Lead governance activities for regulated and controlled information types, such as HIPAA-regulated PHI and Controlled Unclassified Information (CUI), including advising teams on the handling of especially sensitive matters, by coordinating compliance assessments, supporting initiatives such as HIPAA Security Risk Assessments and CMMC audits, and driving remediation and program maturity efforts.
  • Analyze highly sensitive or high-risk matters (e.g., significant PII, PHI, or sensitive government/regulatory matters) and advise engagement teams on appropriate data handling, access, and protection measures.
  • Maintain awareness of relevant privacy, data protection, AI, and regulated data requirements in jurisdictions where the firm operates, and translate changes into practical guidance for internal stakeholders.
  • Own core privacy governance activities in OneTrust, including ROPAs, PIAs/DPIAs, TIAs, vendor and application privacy assessments, data flow documentation, privacy risk tracking, remediation coordination, and stakeholder guidance.
QUALIFICATIONS
  • Bachelor's degree in a related field or equivalent professional experience.
  • 3+ years of experience supporting privacy, data protection, or regulated data governance programs.
  • Working knowledge of privacy and data protection concepts, including personal information, protected health information, data processing agreements, data transfers, data subject rights, privacy notices, and records of processing or data flow documentation.
  • Experience reviewing privacy or security terms in vendor agreements, client contracts, or similar contractual documents.
  • Familiarity with privacy and security frameworks or requirements such as HIPAA, GDPR/UK GDPR, U.S. state privacy laws, NIST, ISO 27001, NIST 800-171, or CMMC.
  • Strong writing, organization, and stakeholder management skills, with the ability to keep work moving across legal, technical, and business teams.
  • Sound judgment, attention to detail, and the ability to apply privacy and security requirements in a practical, business-aware manner.
  • Privacy, security, or risk certifications such as CIPP/US, CIPP/E, CIPM, CIPT, CISSP, CISA, CISM, CRISC, or related credentials preferred.
  • Experience in a law firm, professional services, regulated industry, or client-service environment preferred.
  • All full-time Business Services employees may participate in King & Spalding's comprehensive benefit program
  • health and wellness plan
  • life and disability insurance
  • flexible spending accounts and a health savings account
  • a 401(k) plan
  • profit sharing plan
  • a substantial Paid Time Off (PTO) program

King & Spalding LLP (K&S) is committed to providing equal employment opportunity to all applicants and employees in full compliance with all state, federal, and local laws prohibiting discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, age, disability or any other status protected by applicable law.

We seek to attract and develop the very best talent to work with us.

King & Spalding advances leading companies' complex legal and business interests in more than 160 countries. Collaborating across an integrated platform of transactional, litigation and regulatory talent in 24 offices globally, we work to understand and achieve our clients’ business objectives.

Personal Information will be retained by King & Spalding for as long as the information is required to fulfill our legitimate business needs or the purposes for which the Personal Information was collected, or for as long as is required by law. For more information, click here.

#J-18808-Ljbffr