Nuvepro - Task Intelligence for the Enterprise
Anthropic· Legal· San Francisco, CA | New York City, NY | Washington, DC

Privacy Governance Lead

Classified Tasks (20)

Automate 0%Augment 45%Human-Only 55%

Augment (9)

AI assists, human decides

2. Define policies and controls that translate privacy principles into operating practices

operational

3. Own the privacy documentation lifecycle end-to-end for Data Protection Impact Assessments, Records of Processing, Transfer Impact Assessments, and other accountability artifacts, including methodology, tooling, and quality standards

operational

6. Own the privacy controls testing program

operational

7. Define control effectiveness criteria and what "good" looks like for privacy controls

analytical

8. Set the testing cadence for privacy controls

operational

9. Present privacy controls testing results to the Head of Integrity & Compliance and other leadership forums

communication

11. Translate new legal obligations into concrete control changes ahead of enforcement

operational

13. Oversee the management of inputs for regulatory responses with the Privacy Program pillar

operational

14. Drive privacy training and awareness strategy for engineering, product, research, and go-to-market teams calibrated to their decision-making

communication

Human-Only (11)

Requires human judgment

1. Set the strategy and roadmap for Anthropic's privacy governance framework, including policies, standards, and internal controls mapping to GDPR, CCPA/CPRA, and other global regimes

leadership

4. Establish governance forums and approval workflows for privacy-significant product, research, and vendor decisions

leadership

5. Chair governance forums where novel or high-risk privacy questions are resolved

leadership

10. Partner with Privacy Legal to anticipate emerging privacy law

communication

12. Co-lead privacy regulator engagement on governance matters with Legal, including responses to inquiries, audits, and complaints

communication

15. Represent the privacy governance function in Internal Audit reporting

communication

16. Represent the privacy governance function in cross-functional risk and compliance forums

communication

17. Manage relationships with internal and external stakeholders who depend on the privacy governance framework

leadership

18. Contribute directly to reporting that reaches the Audit Committee and board(s)

communication

19. Build and develop the privacy governance team over time

leadership

20. Partner closely with Security, Product, Research, and the wider Integrity & Compliance team to operationalize privacy governance

operational

Job description

About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role Anthropic's Integrity & Compliance (I&C) function is building the systems that let us scale responsibly as our products reach more people, more enterprises, and more regulated industries. Our global compliance program is bespoke, reflecting our unique mission and position as one of the leading AI labs operating on the frontier. Within Integrity & Compliance, the Privacy Programs pillar owns how we operationalize privacy across the company — from how we handle personal data in our products and research, to how we meet our obligations under the GDPR, CCPA, and the growing patchwork of global privacy law. We work closely with our Privacy Legal team on all privacy related matters. We're hiring a Privacy Governance Lead to own the governance backbone of that work. You'll set the strategy for how privacy governance operates at Anthropic, define the policies and controls that translate privacy principles into operating practice, and help manage the relationship with internal and external stakeholders who depend on that framework holding up under scrutiny. This is a foundational role with significant scope. You'll be shaping a privacy governance function from a relatively early stage, with the autonomy to set the standard and the mandate to drive cross-functional change. You'll partner closely with Privacy Legal, Security, Product, Research, and the wider I&C team, and you'll contribute directly to reporting that reaches the Audit Committee and boards. You'll report to the Head of Integrity & Compliance. Key responsibilities Set the strategy and roadmap for Anthropic's privacy governance framework, including the policies, standards, and internal controls that map to GDPR, CCPA/CPRA, and other applicable global privacy regimes Own the privacy documentation lifecycle end-to-end — Data Protection Impact Assessments, Records of Processing, Transfer Impact Assessments, and other accountability artifacts — including the methodology, the tooling, and the quality bar Establish governance forums and approval workflows for privacy-significant product, research, and vendor decisions, and chair the forums where novel or high-risk questions are resolved Own the privacy controls testing program: define what "good" looks like, set the testing cadence, and present results to the Head of Integrity & Compliance and other leadership forums Partner with Privacy Legal to anticipate emerging privacy law and translate new obligations into concrete control changes ahead of enforcement In partnership with Legal, co-lead privacy regulator engagement on governance matters, including responses to inquiries, audits, and complaints Oversee the management of inputs for regulatory responses with the Privacy Program pillar Drive privacy training and awareness strategy for engineering, product, research, and go-to-market teams, calibrated to the actual decisions those teams make Represent the privacy governance function in Internal Audit reporting, and in cross-functional risk and compliance forums Build and develop the privacy governance team over time Minimum qualifications Deep working knowledge of GDPR and at least one major US state privacy regime (CCPA/CPRA, or equivalent), including how their requirements translate into operational controls a
Source: Anthropic careers · scraped 2026-05-22
Apply at Anthropic