Full-Time

Data Privacy Officer and Sr. Product Counsel

Posted on 2/23/2024

23andMe

23andMe

501-1,000 employees

Provides DNA genetic testing for health, ancestry

Biotechnology

Senior, Expert

Sunnyvale, CA, USA

Required Skills
Management
Marketing
Requirements
  • JD with excellent academic credentials and a member of a U.S. state bar, preferably including the State Bar of California.
  • 10+ years of privacy experience in a law firm, in-house, or other legal role with a track record of providing practical business-friendly advice. CIPP/US/E certification preferred.
  • 5+ years of product counseling experience for innovative technology and/or health data companies.
  • Expert knowledge of data protection and information security laws, rules, and regulations in the US and globally, including CPRA and other state consumer privacy laws, COPPA, privacy practice under the FTC Act, and GDPR, as well as leading privacy and data protection practices and standards.
  • Significant experience successfully implementing privacy-focused projects with efficiency, including data mapping, data privacy impact assessments, and third-party risk assessments, as well as in negotiating complex agreements involving personal data.
  • Knowledge of online and offline advertising and marketing rules and regulations, including state consumer protection statutes, CAN-SPAM, TCPA, and FTC guidelines pertaining to 23andMe’s business.
  • Experience with health privacy laws, including GINA and HIPAA, as well as associated privacy and data protection practices and standards.
  • Experience with data security, data breaches, and data loss prevention, including knowledge of relevant laws and regulations.
  • Experience and skill in responding to press inquiries and speaking on privacy matters.
  • Experience with project management methodologies and tools is a strong plus.
  • Demonstrated analytical skills as well as the ability to take disparate information and make strategic recommendations quickly.
  • Demonstrated leadership with evidence of increasing management responsibility.
  • Ability to develop, deliver presentations to and influence senior management.
  • Exceptional attention to detail and ability to get things done.
  • Ego-free, team-first mentality.
  • Exceptional verbal and written communicator.
  • Excellent interpersonal skills, including relationship-building and collaboration.
Responsibilities
  • Develop and enhance the company’s privacy and data governance policies, standards and practices, including compliance with laws in the U.S. and globally.
  • Build, manage, and motivate the Privacy and Product Legal team, fostering a collaborative and inclusive work environment.
  • Support Product, Marketing, Research, Security, IT, and other business teams to develop and implement solutions that comply with 23andMe’s privacy and data protection policies and procedures.
  • Coordinate with Product and Engineering teams, including ensuring privacy by design, data governance, and healthcare compliance for product launches and initiatives.
  • Assess how current and proposed laws and regulations impact business processes, reporting, record keeping, and other activities. Identify the need for, and advise on the introduction of new business processes, consultations, or training.
  • Collaborate with contracts, procurement, and business development teams, including responsibility for creating policies, processes, and templates and reviewing and negotiating contracts to support transactions involving customer, patient, and/or research participant data.
  • Develop strategies, tools, resources, and frameworks enabling data use and healthcare delivery innovation while ensuring adherence to applicable standards.
  • Perform/oversee privacy and data protection risk assessments and proactively monitor and identify opportunities, issues, and risks. Develop mitigation plans to support company risk management and internal audit reporting.
  • Member of the data protection governance committee, as well as incident response and resolution leadership.
  • Represent 23andMe’s privacy and data protection interests with external parties.
  • Develop, monitor, remediate, and report performance metrics for privacy and data protection.

23andMe offers DNA genetic testing for health and ancestry, providing personalized genetic insights into health predispositions, carrier status, wellness, and ancestry breakdowns across 2000+ geographic regions. The company utilizes genotyping to analyze DNA and has multiple FDA authorizations for genetic health risk reports, contributing to the world's largest crowdsourced platform for genetic research and powering drug discovery programs rooted in human genetics.

Company Stage

IPO

Total Funding

$1.2B

Headquarters

Sunnyvale, California

Founded

2006

Growth & Insights
Headcount

6 month growth

-1%

1 year growth

-8%

2 year growth

17%

Benefits

Comprehensive health, vision, & dental plans

Family planning, support, & leave for parents

Mental healthcare

Student loan assistance

Volunteer time off

Dog friendly office

INACTIVE