# Data Protection & Privacy Counsel for Poland & Central Europe at AstraZeneca

AI Level 1, AI centrality 10 out of 100. Remote (Poland - Warsaw).

## Details

- Company: [AstraZeneca](https://jobsbylevel.com/companies/astrazeneca)
- AI level: AI Level 1 (score 10 out of 100)
- Location: Remote (Poland - Warsaw)
- Posted: October 7, 2026
- Apply: https://jobsbylevel.com/go/380b1813-4b43-45f3-95a8-c4c16e9cc8ce

## Description

Location: Warsaw Hybrid model of work Typical and Specific Accountabilities Role purpose. Provide practical, business-oriented legal advice on privacy, data protection and related data-governance matters across Poland, the Czech Republic, Slovakia and Hungary. The role enables the responsible use of personal data across business operations, clinical research, patient-related activities, HR, digital solutions, analytics, AI and other new technologies, translating global standards and evolving EU requirements into proportionate and workable safeguards. Act as the primary privacy legal adviser for Poland and provide coordinated privacy support across the Czech Republic, Slovakia and Hungary, working closely with local Legal and Compliance teams, privacy representatives and the Global Privacy Office. Provide clear, risk-based advice on the collection, use, sharing, retention, transfer and deletion of personal data, including local implementation of global privacy standards and monitoring of relevant legal and regulatory developments. Lead and advise on Privacy Impact Assessments and Data Protection Impact Assessments for new or materially changed processes, systems, studies, technologies and third-party engagements, identifying proportionate safeguards and documenting material risks and decisions. Advise on AI, Generative AI, Digital Health, analytics and other emerging technologies, including GDPR, EU AI Act, privacy-by-design, transparency and internal technology-governance considerations. Provide privacy support for clinical studies, observational research, real-world evidence, patient-support activities and other medical or research initiatives involving health, genetic or other sensitive personal data. Review and negotiate privacy provisions in commercial, technology, vendor, clinical-study and data-sharing agreements, including DPAs, controller/processor allocations, Standard Contractual Clauses and Transfer Impact Assessments. Support privacy due diligence and risk assessment of vendors and technology providers, partnering with Procurement, IT, Cyber Security, Digital and business owners throughout selection, contracting and implementation. Coordinate local and regional privacy support for suspected personal-data incidents and investigations, including assessment, containment, remediation, contractual obligations and potential regulatory or data-subject notifications. Coordinate and advise on complex data-subject rights requests in cooperation with global and local stakeholders, ensuring appropriate consideration of confidentiality, third-party rights, privilege and applicable limitations. Develop and maintain local and regional privacy procedures, notices, guidance and audit-ready compliance documentation, and deliver targeted privacy training and awareness activities. Coordinate consistent regional positions, manage external privacy counsel where required, and support engagement with supervisory authorities and regulatory enquiries in cooperation with Legal and the Global Privacy Office. Build effective relationships across Legal, Compliance, HR, Procurement, IT, Digital, Medical, Clinical Operations and other relevant business functions, translating complex requirements into practical actions. Geographic Remit Operates in four countries: Poland, Czech Republic, Slovakia and Hungary. Requirements: Essential: Degree in law or equivalent legal qualification. At least five years of relevant legal, privacy or data-protection experience, including substantial hands-on GDPR advisory experience in an organisation, law firm or regulated environment. Strong practical knowledge of GDPR, including lawful basis, transparency, special-category data, privacy by design, data-subject rights, incidents, accountability and international transfers. Demonstrable experience with PIA/DPIA, privacy contracts and DPAs, vendors, cross-border transfers, incidents and data-subject-rights processes. Working knowledge of privacy and data-governance

The description is cut here. Read the full offer: https://jobsbylevel.com/jobs/data-protection-privacy-counsel-for-poland-central-europe-at-astrazeneca-238b27

Source: https://jobsbylevel.com/jobs/data-protection-privacy-counsel-for-poland-central-europe-at-astrazeneca-238b27

## Cite this page

Level. https://jobsbylevel.com/jobs/data-protection-privacy-counsel-for-poland-central-europe-at-astrazeneca-238b27.

Get job alerts: https://jobsbylevel.com/newsletter
