Taylor Root
Privacy Counsel (Product)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Privacy & Product Counsel | AI | Global Role
UK-based & Remote-first (No Sponsorship Offered) | £100K - £115,000 + equity
I’m working with a well-backed, San Francisco-headquartered AI company to hire its first dedicated Privacy & Product Counsel.
You’ll build the privacy programme, work directly with product and engineering on how agentic AI systems use data, negotiate with major enterprise customers, and become the internal authority on privacy across the US, UK and Europe.
It’s a great and rare opportunity.
The company moves extremely quickly, operates across US and European time zones, and wants someone who actively enjoys that, and wants to build in a frontier environment. The role is remote-first in the UK, there will be occasions where you need to cover US hours, or travel for customer meetings.
If you want clearly defined boundaries, a large legal team around you and, a more traditional 9–5 working pattern, this isn’t the right role.
If you want to build something, value equity, work very closely with a founding team, a great GC, and have significant influence over how a frontier AI product develops, this is the role for you.
The role
The core of the position is privacy.
You’ll own the privacy programme across a business whose technology processes significant volumes of consumer data within major enterprise environments.
That means:
- Building and running the privacy programme from the ground up: data mapping, policies, retention, vendor and subprocessor management.
- Advising product and engineering on privacy-by-design for agentic AI systems — including what an agent can access, retain, infer and act upon.
- Owning the company's approach to GDPR, UK GDPR, CCPA/CPRA and the wider US state privacy landscape.
- Keeping ahead of developing AI regulation across the US, UK and EU.
- Building scalable approaches to DPAs, SCCs, the UK IDTA/Addendum and international data transfers.
- Working with security on incident response, breach notification and customer-facing security commitments.
- Acting as a senior privacy SME with enterprise customers who want to understand exactly how their information is being handled.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
There is also a meaningful product and commercial counsel element.
You’ll negotiate enterprise agreements, DPAs and security schedules and work closely with the commercial team to get deals completed without making commitments the product cannot support.
And because this is a startup, occasionally something will land on your desk that does not fit neatly inside the job description.
You need to be comfortable picking it up.
They do not want a generalist with a bit of privacy experience, though. Privacy expertise is the foundation of the hire.
Who they are looking for
The sweet spot is likely someone around 6 - 8 years' PQE mark, but we’re more looking for the right kind of person and attitude to the challenge. Do not let the PQE mark above put you off applying, if you feel you would thrive in this environment.
The most important requirement is genuine depth across European privacy law.
You therefore need to be genuinely comfortable across:
- EU GDPR / UK GDPR / DPA 2018 + CCPA/CPRA and US state privacy laws.
Beyond that, the strongest candidates are likely to have:
- Worked in-house in a technology, data-heavy or AI business.
- Sat alongside product and engineering teams rather than operating purely as an advisory function.
- Negotiated enterprise DPAs, security schedules and international transfer arrangements.
- Experience dealing directly with sophisticated customer legal, procurement and security teams.
- Enough commercial breadth to help outside the privacy lane when required.
- The confidence to make decisions where there may not yet be a perfect regulatory answer.
Your training route is much less important than what you have actually done and why.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Someone who deliberately moved into privacy, built genuine subject-matter expertise and can explain the thinking behind their career decisions will be taken seriously.
The working environment
They want someone with a “let’s build it and get moving” mentality.
You will not inherit a mature privacy department with established processes for everything. Some things will need to be built manually, some automated quickly, and some solved pragmatically.
The company wants rigour, but not bureaucracy for its own sake.
You will work closely with founders, engineering, product and commercial leadership.
The role is customer-facing and you will be involved in areas such as board-level privacy and risk reporting.
The business is operating at the sharp end of AI and machine learning, working with very large datasets and sophisticated and high profile enterprise customers.
For somebody who genuinely wants to build their career around privacy + AI + product, there is significant scope here.
Compensation
The UK salary banding is £100K - £115K, depending on experience + Bonus & Equity from day one.
Interview process
(After an in-depth call with the recruiter)
Stage one: an initial conversation focused on your background, motivations and relevant experience with the GC.
Stage two: conversation with a Co-Founder, with a significant focus on fit, ambition and how you operate in a startup environment.
Neither stage is intended to become an academic privacy-law examination.
They will want to understand whether you genuinely know your subject, but they are equally interested in how you communicate, why you have made the career decisions you have made, and why you want this particular type of role now.
They also need somebody who can move relatively quickly. A long notice period is likely to be difficult for this search.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location