Privacy counsel
Advises on the law, contracts and disputes about personal data.
Or does one of these fit you better?

What does a privacy counsel do?
A privacy counsel is the lawyer for personal data. The role advises the organisation on what the law allows, drafts and negotiates the data clauses in contracts, deals with regulators and disputes, and reviews new products before they launch.
Privacy counsel work in the legal department of an organisation or in a law firm. Either way the work is advice the business can act on: how to do what it wants to do, within the law.
How do you become a privacy counsel?
- Qualify in lawPrivacy counsel is a legal role. It starts with a law degree, and in most organisations with admission as a lawyer.
- Get certifiedThe CIPP/E covers European law and the CIPP/US American law. Together they show you can advise on both sides of the Atlantic.
- Take privacy matters nowData processing agreements, transfer clauses, a regulator's letter: ask for them in your current practice.
- Move into the rolePrivacy counsel in a legal department, or a privacy associate at a law firm.
Which certifications does a privacy counsel need, and in which order?
- 1CIPP/EEuropean data protection law: the GDPR, the ePrivacy rules and how the authorities apply them.About a month at three hours a day
- 2CIPP/USUnited States privacy law: the federal sector rules, the state privacy acts and how they meet in practice.About a month at three hours a day.
Already hold the CIPP/E? Start with the CIPP/US.
Organisations with customers in Europe and the United States need both bodies of law. The CIPP/E covers European data protection law and the CIPP/US American privacy law.
What skills does a privacy counsel need?
The text, the guidance and the decisions, and how they apply to the facts in front of you.
Data clauses that protect the organisation and that the other side can sign.
Saying how something can be done lawfully, not only that it cannot.
Knowing what an authority asks for, and answering it clearly and on time.
The GDPR does not ask for a certificate. Employers do.
Start CIPP/E freeWhere does a privacy counsel work?
In the legal team of a technology, finance or healthcare company, close to the product and the contracts.
In a privacy and data protection practice, advising many clients.
At organisations with customers in Europe and the United States, where both bodies of law apply at once.
What does a privacy counsel earn?
Pay depends on the country, the sector, your experience and whether the role is in-house or external. The ranges below come from published salary guides; verify them against the market you are in.
Sources: Glassdoor, September 2026 (Dublin); Legal.io, salary data (United States).
Questions about the Privacy counsel role
Do I need to be a lawyer?
For this role, yes, in most organisations. It is the one role in the career plan that asks for a legal qualification. The certifications show that your legal training covers privacy.
Why two certifications?
Organisations with customers in Europe and the United States need both bodies of law. The CIPP/E covers the first and the CIPP/US the second.
Privacy counsel or data protection officer?
The privacy counsel is the organisation's lawyer and acts in its interest. The data protection officer is independent and monitors the organisation. They work together, and the roles should not be held by the same person.
Does the AIGP help?
Yes, if your organisation builds or uses AI. The AIGP covers the rules that come on top of data protection law.
Your path starts with the CIPP/E
Your first lesson is free. No card.
