Tech Privacy & Compliance Lead
Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted1 day ago
• Global Requirements & Mapping: Own the global cookie consent requirements catalog for the U.S. and EMEA (including country-specific and state-specific nuances). Maintain authoritative jurisdiction-to-consent-profile mappings covering prior-consent, opt-out, limited-banner, strict fallback, sensitive-data, child, health-data, and unknown-location scenarios.
• Legal Translation & UX Specifications: Translate legal guidance into atomic business requirements, user experience specifications, technical controls, acceptance criteria, and test cases. Define required content, buttons, links, category descriptions, toggle defaults, languages, and accessibility behaviour for banners and preference centres.
• OneTrust Web CMP Ownership: Own the OneTrust Web CMP design, including domain groups, templates, geolocation rules, category groups, cookie classification, Autoblocking, script blocking, consent receipts, policy versions, renewal rules, and withdrawal behaviour.
• Technical Controls & Signal Management: Own Global Privacy Control (GPC) and universal opt-out signal requirements, including signal precedence, manual-choice handling, downstream propagation, and evidence capture. Direct the inventory and classification of cookies, local storage, SDKs, tags, APIs, network requests, first/third-party identifiers, and server-side destinations.
• Validation & Traceability: Maintain end-to-end traceability between legal sources, requirements, OneTrust configurations, Adobe controls, test evidence, defects, approvals, and releases. Lead validation for first visits, no interaction, Accept All, Reject All, granular choices, withdrawal, policy updates, GPC, geolocation failures, cross-domain journeys, single-page applications, and mobile experiences.
• Fail-Closed Governance & Oversight: Define fail-closed behaviour for unknown jurisdictions, unresolved consent, configuration failures, missing OneTrust responses, and unavailable browser storage. Chair design reviews and obtain formal sign-offs from Privacy Legal, Security, Accessibility, Analytics, Marketing, and Engineering.
• Backlog & Operations Management: Own the consent-management backlog, implementation roadmap, release gates, defect prioritization, and remediation tracking. Monitor regulatory, browser, OneTrust, and Adobe updates to coordinate impact assessments, configuration updates, regression testing, and policy renewals.
• Documentation & Executive Reporting: Produce operating procedures, implementation standards, architecture documentation, training materials, and audit-ready evidence. Deliver executive reporting on coverage, consent defects, unclassified technologies, control exceptions, regulatory changes, and remediation progress.
• Legal Translation & UX Specifications: Translate legal guidance into atomic business requirements, user experience specifications, technical controls, acceptance criteria, and test cases. Define required content, buttons, links, category descriptions, toggle defaults, languages, and accessibility behaviour for banners and preference centres.
• OneTrust Web CMP Ownership: Own the OneTrust Web CMP design, including domain groups, templates, geolocation rules, category groups, cookie classification, Autoblocking, script blocking, consent receipts, policy versions, renewal rules, and withdrawal behaviour.
• Technical Controls & Signal Management: Own Global Privacy Control (GPC) and universal opt-out signal requirements, including signal precedence, manual-choice handling, downstream propagation, and evidence capture. Direct the inventory and classification of cookies, local storage, SDKs, tags, APIs, network requests, first/third-party identifiers, and server-side destinations.
• Validation & Traceability: Maintain end-to-end traceability between legal sources, requirements, OneTrust configurations, Adobe controls, test evidence, defects, approvals, and releases. Lead validation for first visits, no interaction, Accept All, Reject All, granular choices, withdrawal, policy updates, GPC, geolocation failures, cross-domain journeys, single-page applications, and mobile experiences.
• Fail-Closed Governance & Oversight: Define fail-closed behaviour for unknown jurisdictions, unresolved consent, configuration failures, missing OneTrust responses, and unavailable browser storage. Chair design reviews and obtain formal sign-offs from Privacy Legal, Security, Accessibility, Analytics, Marketing, and Engineering.
• Backlog & Operations Management: Own the consent-management backlog, implementation roadmap, release gates, defect prioritization, and remediation tracking. Monitor regulatory, browser, OneTrust, and Adobe updates to coordinate impact assessments, configuration updates, regression testing, and policy renewals.
• Documentation & Executive Reporting: Produce operating procedures, implementation standards, architecture documentation, training materials, and audit-ready evidence. Deliver executive reporting on coverage, consent defects, unclassified technologies, control exceptions, regulatory changes, and remediation progress.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.