Privacy Governance Lead

Anthropic Anthropic · AI Frontier · San Francisco, CA · Legal

This role is responsible for establishing and managing Anthropic's privacy governance framework, including policies, controls, and documentation for global privacy regimes like GDPR and CCPA. It involves partnering with legal, security, product, and research teams to ensure privacy compliance in AI systems and operations, and potentially building out the privacy governance team.

What you'd actually do

  1. Set the strategy and roadmap for Anthropic's privacy governance framework, including the policies, standards, and internal controls that map to GDPR, CCPA/CPRA, and other applicable global privacy regimes
  2. Own the privacy documentation lifecycle end-to-end — Data Protection Impact Assessments, Records of Processing, Transfer Impact Assessments, and other accountability artifacts — including the methodology, the tooling, and the quality bar
  3. Establish governance forums and approval workflows for privacy-significant product, research, and vendor decisions, and chair the forums where novel or high-risk questions are resolved
  4. Own the privacy controls testing program: define what "good" looks like, set the testing cadence, and present results to the Head of Integrity & Compliance and other leadership forums
  5. Partner with Privacy Legal to anticipate emerging privacy law and translate new obligations into concrete control changes ahead of enforcement

Skills

Required

  • GDPR
  • CCPA/CPRA
  • Privacy governance program development
  • Policy development
  • Internal controls
  • Data Protection Impact Assessments (DPIAs)
  • Records of Processing (ROPA)
  • Transfer Impact Assessments (TIAs)
  • Governance forums
  • Cross-functional collaboration
  • Written communication
  • Privacy certifications (CIPP/E, CIPP/US, CIPM)

Nice to have

  • AI-specific privacy considerations
  • Regulator engagement
  • High-growth environment experience
  • Board-level reporting
  • Broader compliance disciplines (security, risk management)

What the JD emphasized

  • Deep working knowledge of GDPR and at least one major US state privacy regime (CCPA/CPRA, or equivalent), including how their requirements translate into operational controls at scale
  • Demonstrated track record building, scaling, or transforming a privacy governance program end-to-end — policies, DPIAs, ROPAs, controls libraries, governance forums, and the operating model that supports them
  • Strong written communication, with the ability to produce clear policies, board-ready reporting, and practical guidance that engineering and product teams will actually use
  • Comfort owning hard cross-functional decisions and operating across legal, technical, and operational boundaries
  • A privacy certification such as CIPP/E, CIPP/US, or CIPM, or equivalent demonstrated expertise