Full-Time

Privacy and Data Protection Counsel

Updated on 11/20/2024

Veracyte

Veracyte

501-1,000 employees

Develops genomic tests for cancer diagnosis

Biotechnology
Healthcare

Compensation Overview

$176k - $220kAnnually

+ Bonus + Incentives + Restricted Stock Units

Mid, Senior

United States

Hybrid position with potential in-office requirements.

Category
Legal
Risk & Compliance
Legal & Compliance
Requirements
  • In-depth knowledge of GDPR, HIPAA, U.S. state privacy laws and health information privacy and the global privacy legal regime.
  • Minimum of four (4) years of full-time experience as a privacy attorney, including two (2) years in-house experience or experience in biotech or life sciences industry.
  • Direct experience advising on privacy legal matters in new business initiatives, strong experience with contract reviews and negotiations, including templates and playbooks, and reviewing and negotiating a variety of privacy and data protection agreements, including GDPR data processing agreements, business associate agreements, data use and transfer agreements, for both customers and vendors.
  • Direct experience in establishing, implementing and managing U.S. and GDPR privacy operational requirements, including data inventories, DPIAs/PIAs for sensitive health data, ROPAs, intake review processes, notice and consent requirements, and assisting the business teams in managing their data requirements.
  • Proven success advising internal clients on legal privacy and data protection laws in the healthcare industry, including performing data privacy reviews of new products, services, tools and advising on requirements in a practical, risk-based approach; keen understanding of practical risks and ability to offer creative solutions.
  • Direct experience advising on and operationalizing requirements for processing of sensitive health data and personal health information; keen understanding of deidentification, pseudonymization and anonymization under GDPR and HIPAA, and in-depth experience advising on data usage rights and restrictions under applicable healthcare privacy laws, HIPAA, CCPA, GDPR and others.
  • Project management experience and ability to manage large-scale, multi-stakeholder projects for the privacy team.
  • Proven skills and experience collaborating across a wide range of global teams and with a diverse employee population.
  • Best in class communication and interpersonal skills.
  • Advanced legal degree and member in good standing with a U.S. state bar (or international equivalent).
Responsibilities
  • Advise global teams on a wide variety of privacy and data protection issues relating to our global diagnostics business’ processing of personal health data (PHI) under US and EU laws, including HIPAA, GDPR, CCPA, and other state laws, and other data processing activities amongst Veracyte global teams.
  • Distill complex legal requirements to provide practical, risk-based advice appropriate for Veracyte’s business models, operations and risk profile; create out of the box solutions to scale our ability to provide legal guidance to the global teams through guidelines, tools, training and processes;
  • Evaluate personal health data in a variety of forms and understand how data origin, patient consents, data use rights, international transfers, and deidentification/pseudonymization, third-party sharing, data flows, and other attributes determine what laws apply, what contract terms are appropriate, and what compliance requirements arise;
  • Manage global large-scale projects, including Privacy team’s own projects, and support projects of global cross-functional teams. Execute privacy team projects through project management, including designing the project plan, execution of tasks and deliverables, and managing inputs required from other teams.
  • Conduct a variety of privacy reviews, including privacy use-case reviews to determine if new tools, projects, products and data analytics are aligned with privacy and data protection laws, our contractual commitments, and policies; conduct privacy impact assessments and similar reviews.
  • Monitor U.S. and global privacy, data, and AI laws for updates, determine applicability to our business, and collaborate on implementing new requirements.
  • Negotiate privacy and data protection terms in a wide array of global agreements, including vendor agreements, research collaborations, clinical trial agreements, business associate agreements and data protection agreements, including standard contractual clauses and solid understanding of controller and processor roles.
  • Design and implement global privacy operations including GDPR and U.S. privacy impact assessments, records of processing activities, framework mapping to controls and tracking of program evidence and documentation, conducting transfer impact assessments, creating standard operating procedures on a wide range of privacy requirements, and managing privacy operational tools.
  • Establish and manage a variety of privacy program requirements and assist with privacy program management, including drafting privacy guidelines and procedures, creating and facilitating global privacy and data protection training, facilitate privacy audits, manage policy review cycles, outside counsel and vendor management, and other program needs.
  • Establish cross-functional collaborations with teams to align on data goals and needs of our business, and partner on privacy and data governance solutions to support our global data strategy.

Veracyte specializes in cancer diagnostics by developing advanced genomic tests that assist in the early detection and diagnosis of various cancers. Their tests analyze genetic information from non-invasive samples, such as nasal swabs or tissue biopsies, providing crucial insights into the presence and progression of cancer. This allows healthcare providers, including hospitals and clinics, to make informed treatment decisions tailored to individual patients. Veracyte differentiates itself from competitors by focusing on non-invasive testing methods and continuously investing in research to expand its product offerings. The company's goal is to improve patient outcomes and enhance the efficiency of cancer treatment through accurate and early diagnosis.

Company Stage

IPO

Total Funding

$69.4M

Headquarters

San Francisco, California

Founded

N/A

Growth & Insights
Headcount

6 month growth

5%

1 year growth

7%

2 year growth

10%
Simplify Jobs

Simplify's Take

What believers are saying

  • Recognition as a Bay Area Top Workplace for 11 consecutive years highlights a positive work environment and strong company culture.
  • Significant investments from firms like Aigen Investment Management and Quest Partners indicate strong financial backing and growth potential.
  • The upcoming launch of ClearLab and an MRD assay in 2026 showcases Veracyte's commitment to expanding its product portfolio and market reach.

What critics are saying

  • The competitive landscape in genomic diagnostics is intense, requiring Veracyte to continuously innovate to maintain its market position.
  • Dependence on successful clinical validation and regulatory approval for new tests can pose risks to product launch timelines.

What makes Veracyte unique

  • Veracyte specializes in non-invasive genomic tests for early cancer detection, setting it apart from traditional diagnostic methods.
  • Their Decipher Prostate and Bladder Genomic Classifiers offer superior prognostic information compared to standard approaches, enhancing treatment personalization.
  • Continuous investment in R&D and clinical validation ensures that Veracyte's tests remain at the forefront of cancer diagnostics.

Help us improve and share your feedback! Did you find this helpful?