Job Description
As part of Nokia's Legal job family, this role sits within the Global Privacy, Data and Cyber Regulatory Office (GPDCRO) — Nokia's centre of excellence for data protection, cybersecurity regulation, and emerging data-related law — reporting to the Head of Privacy and Data Trust. It applies deep specialist expertise across data protection, cybersecurity law, AI governance, commercial contracting, and incident response, acting as the primary legal interface between Nokia's European and UK business operations and the rapidly evolving regulatory landscape.
This is an AI-first legal team. We actively build and use AI-assisted workflows — from agentic legal research to automated regulatory horizon scanning — and expect everyone in the team to engage seriously with what AI can do for legal work. The role works alongside counterparts covering the Americas, Middle East and Africa, and Asia Pacific, with genuine opportunity to collaborate on cross-jurisdictional matters. If you are excited by building the legal function of the future rather than maintaining the legal function of the past, you will fit in here.
- Provide expert legal advice across the full EU and UK data protection and cybersecurity regulatory landscape, including GDPR, UK GDPR/DPA 2018, NIS2, the EU Cyber Resilience Act, the EU Data Act, the EU AI Act, and applicable national implementing legislation.
- Lead Nokia's legal engagement with the Cyber Resilience Act, including the legal track for open-source software obligations in network products, conformity requirements, and evolving delegated acts.
- Own the legal workstream for Nokia's supplier security documentation, including the modular security appendix applied across Nokia's global supply chain.
- Advise on privacy and cybersecurity requirements in customer contracts and procurement processes, including data processing agreements, security appendices, and data localisation requirements.
- Conduct horizon scanning across EU and UK regulatory developments, triaging legal risk and preparing clear, actionable briefings for senior stakeholders and governance forums.
- Lead legal review of Nokia's use of regulated data types — telecom subscriber data, network data, employee data — advising on permissible use cases, anonymisation standards, and access controls.
- Conduct and review Data Protection Impact Assessments for high-risk processing activities, including AI-driven use cases and network analytics.
- Actively identify opportunities to move Nokia's compliance posture from paper-based to demonstrable — working with engineering, security, and data teams to embed legal requirements as technical controls into systems and workflows. In practice: data minimisation enforced at the API layer, purpose restrictions implemented as access controls, anonymisation validated against re-identification risk rather than assumed.
- Play a central role in cyber and privacy incident response — making timely, legally sound decisions on notification obligations under NIS2, GDPR Articles 33/34, and applicable national legislation, and maintaining Nokia's incident response legal playbook.
- Provide privacy, data use, and cyber law input into Nokia's AI governance programme and internal AI deployment — ensuring legal requirements are embedded at design stage.
- Deliver training and legal briefings to internal teams, leveraging AI tools to create scalable, repeatable guidance — building legal capability across the organisation rather than creating dependency on the legal team.
- Manage external legal counsel on EU and UK matters, with accountability for scope, quality, and cost.
- Build trusted, collaborative relationships across Information Security, Product Security, Procurement, Business Groups, CTO, and Human Resources — acting as a proactive legal partner and handling matters end-to-end, enabling the Head of Privacy and Data Trust to focus on global strategy and executive engagement.
Skills and experience
We recognise that experience rarely maps perfectly to a job description. If this role excites you and your experience covers the substantial majority of the requirements below, we encourage you to put yourself forward.
Must Have
- Qualified lawyer, admitted to practise in at least one EU member state or in England and Wales, with a minimum of 10 years of post-qualification experience in data protection, cybersecurity law, or a closely related technology law specialism.
- Hands-on knowledge of GDPR and UK GDPR, with a track record of advising complex, multinational organisations on compliance programme design, incident response, and supervisory authority engagement.
- Substantive familiarity with EU cybersecurity regulation — particularly the Cyber Resilience Act, NIS2, and the EU AI Act — and the ability to translate evolving regulatory requirements into clear, practical guidance for technical and commercial audiences.
- Genuine intellectual curiosity about technology: comfortable engaging with engineers and architects, asking the right questions, and identifying legal risk in technically complex environments. You do not need to be a software engineer — you do need to be genuinely interested in how the technology works.
- A working familiarity with AI tools — including large language models and agentic workflows — and a willingness to use them to enhance legal research, drafting, and horizon scanning. We are building a team that embraces AI to amplify legal capability and deliver better outcomes.
- Experience advising on privacy, security, and AI clauses in commercial contracts, supplier agreements, and customer-facing data processing agreements.
- Strong commercial awareness and an understanding of how legal and regulatory work contributes to business performance and customer relationships — able to frame legal risk in terms that resonate with commercial and operational audiences, not just legal ones.
- Ability to manage a varied, high-volume portfolio independently, prioritising by materiality and delivering concise, business-ready advice.
- Experience of incident and crisis response from a legal perspective, including regulatory notification obligations under NIS2 and GDPR, and privilege management under time pressure.
- Excellent written and spoken English, with the ability to make complex legal analysis genuinely useful for non-legal audiences, and the interpersonal skills to build trusted relationships and influence without authority in a large, matrixed organisation.
Nice to Have
- Experience in telecommunications, technology, or critical infrastructure, where data sovereignty, network data, and cybersecurity regulatory obligations intersect.
- Experience designing modular contractual frameworks — such as security appendices or DPA templates — applied across a global supply chain.
- Experience with privacy management platforms such as OneTrust.
- A relevant qualification — CIPP/E, CIPM, or equivalent — is desirable but not essential; we are more interested in demonstrated capability than credentials.
- External visibility or a professional network in EU/UK data protection or cybersecurity law.