LEXAUPDATES
PostAdvertiseAboutContact
jobsPosted 16 days ago

Sr Legal Counsel, EMEA Privacy at Dexcom

D

Dexcom

📅Primary

last date

Open Access

📍

Location/Place/Mode

Barcelona, Spain (Remote/Hybrid options available)

🔖

Eligibility

Bachelor's degree and 5–8 years of related experience; 5+ years of privacy and data protection experience at a law firm or in-house, preferably in regulated industries (life sciences, healthcare, or technology); knowledge of European privacy laws and best practices; proven project management and process development skills; CIPP or other data privacy certifications preferred; ability to work independently in a fast-paced environment.

Opportunity

Why This EMEA Privacy Role at Dexcom Deserves Your Attention

In an era where data protection has become a strategic business imperative, the Senior Legal Counsel, EMEA Privacy position at Dexcom is not just another in-house vacancy. It is a front-row seat to the convergence of cutting-edge medical technology, the European Union's evolving digital rulebook, and the day-to-day operational reality of a global health tech leader. For privacy lawyers who want to move beyond compliance checklists and into meaningful influence, this Barcelona-based role promises a blend of regulatory depth, commercial pragmatism, and career-defining exposure.

Dexcom is a NASDAQ-listed pioneer in continuous glucose monitoring (CGM). The company has spent 25 years building an industry around biosensing technology that helps people with diabetes manage their health. But its ambition now reaches beyond diabetes into broader consumer health technology. That expansion makes privacy and data security central to product development, vendor relationships, and public procurement—not an afterthought. This is precisely where this role sits.

“We are broadening our vision beyond diabetes to empower people to take control of health,” says Dexcom’s own description. That vision is why the Global Privacy team is investing in a senior counsel who can navigate GDPR, the EU AI Act, and the labyrinth of digital regulation—while keeping the business moving.

The Strategic Relevance of Privacy in Medical Technology

Medical devices generate increasingly granular health data. This makes the legal function a critical partner in deciding how data is processed, shared across borders, and protected from misuse. The EMEA Privacy Counsel at Dexcom will report directly to the Chief Privacy Officer, giving the role a direct line to the highest levels of the legal and compliance structure. That visibility is rare and invaluable for career progression.

One of the most notable aspects of this posting is the explicit mention of the EU AI Act. For lawyers who have spent the last decade mastering GDPR alone, the AI Act introduces a new universe of obligations regarding algorithmic transparency, risk classification, and human oversight. Dexcom is already planning for this future, which signals a forward-thinking legal department. Working here means you will be ahead of the curve, building frameworks that many organisations are only beginning to consider.

Decoding the Day-to-Day: What You'll Actually Own

The job description is refreshingly specific. You will not be a passive advisor waiting for questions to arrive. Instead, you will be embedded in commercial and operational workflows:

  • Vendor vetting and auditing: Working with Procurement and Legal to ensure all third-party vendors align with privacy and data security policy.
  • EU public tenders: Supporting Dexcom’s competitive submissions for sale of products and services in the EU—where data protection compliance is often a decisive award criterion.
  • Data subject rights management: Owning the process for handling complaints and rights requests, from access requests to erasure requests.
  • Data Protection Impact Assessments (DPIAs): Advising on high-risk processing activities and maintaining a robust DPIA pipeline.
  • Regulatory relationships: Managing engagement with applicable supervisory authorities and coordinating with Dexcom’s Data Protection Officer.

This list reveals a broad mandate. You are expected to understand the lifecycle of personal data from procurement to product, from tendering to enforcement. It demands project management skills as much as legal analysis. The role also offers variety—no two days will look the same, and you will constantly toggle between strategic guidance and hands-on execution.

The Experience Blueprint: Do You Have What It Takes?

Dexcom is looking for someone with 5+ years of privacy and data protection experience, gained either at a law firm or in-house. Preference is given to candidates from regulated sectors—life sciences, healthcare, or technology—where privacy risk is acute and the regulatory landscape is complex. A CIPP or other data privacy certification is preferred but not mandatory.

“Ability to work independently with minimal supervision in a fast-paced and high-volume practice” is not corporate fluff. It is the single most important personality trait for this role. The legal team works across time zones, and the Chief Privacy Officer needs a self-starter who can own outcomes without constant oversight.

The formal education requirement states a Bachelor’s degree and 5–8 years of related experience. Typically, this means a law degree and relevant post-qualification experience. Iberian legal qualifications are not explicitly required, but an understanding of European privacy laws and best practices is non-negotiable. If you are a Spanish-qualified lawyer with strong English and EU data protection expertise, this role is an exceptional fit. Even candidates with a strong advisory background from a top-tier law firm or a multinational tech company will find their profile highly relevant.

How to Craft an Application That Stands Out in Barcelona

Barcelona is a magnet for international legal talent, especially in privacy and data protection. The city hosts a dense network of startups, tech giants, and professional services firms, so competition is steep. To stand out for this role, consider these strategies:

  • Mirror the language of the job description. Use keywords like 'DPIAs', 'GDPR compliance', 'AI Act', 'data subject rights', and 'vendor due diligence' in your CV and cover letter.
  • Showcase tangible achievements. Rather than saying 'advised on GDPR', describe how you led a cross-border vendor audit or reduced data subject request backlog by a certain percentage.
  • Emphasize project management. The role requires the development and implementation of processes. Share examples where you created a privacy framework, rolled out a training program, or managed a regulatory notification.
  • Highlight industry exposure. If you have worked in digital health, medical devices, or any regulated tech space, make that unmistakable.

Since the application goes through LinkedIn, your profile must be fully optimised. Recruiters will likely click through to your profile before calling. Use the 'Featured' section to pin a portfolio of privacy policies, articles, or case studies you have written. Also, craft a LinkedIn 'About' section that tells a coherent story about your transition into privacy law and your passion for healthcare innovation.

Beyond the Paycheck: What Dexcom Offers a Privacy Professional

The annualised base salary for this role is €52,360 to €67,760 gross. That range is competitive for the Spanish market, though not extraordinary for senior privacy talent. What makes the package more attractive is the broader context:

  • A front-row seat to life-changing CGM technology — how often do you get to say your advice helps people with diabetes live safer, better lives?
  • A comprehensive benefits program, though details are not fully specified in the posting.
  • Global growth opportunities, with structured development programs and tuition reimbursement.
  • Flexible working: The role is remote-friendly. You can work from a home office anywhere in the region, and if you live within 120 km of a Dexcom site, a hybrid arrangement may be available.

Travel is minimal (0–5%), meaning your time is mostly spent on deep work and stakeholder collaboration rather than road warrior exhaustion. For those raising a family, this is a significant lifestyle benefit. Moreover, Dexcom explicitly states that it is committed to a fair and inclusive recruitment process, welcoming candidates of all genders and gender identities—a positive signal for workplace culture.

Your Strategic Career Playbook: Why This Role Is a Stepping Stone

If you are weighing whether to apply, consider the trajectory. Privacy law is now one of the most resilient and high-demand legal niches globally, and the EU AI Act will only accelerate this trend. At Dexcom, you will be at the vanguard of applying GDPR and AI Act rules to real products in real time. The direct reporting line to the Chief Privacy Officer means your work will be visible to decision-makers who shape the company. This role could be your launchpad to a Head of Privacy or Data Protection Officer position within the next 3–5 years.

Moreover, the exposure to EU public tenders and vendor audits gives you commercial acumen that pure law firm practice rarely offers. You will learn how to balance legal risk against business opportunity—a skill that separates future general counsel from lifetime associates. The role also allows you to build an internal network across procurement, engineering, regulatory affairs, and commercial teams, making you a truly cross-functional legal partner.

Frequently Asked Questions (FAQs)

Is this role open to candidates outside Spain?

Dexcom's job posting does not specify nationality requirements, but the role is based in Barcelona and requires deep knowledge of European privacy laws. Candidates with EU work authorization and strong English skills are likely the intended audience. If you require visa sponsorship, you should check directly with Dexcom's Talent Acquisition team.

What exactly is the EU AI Act, and how does it relate to this role?

The EU AI Act is a landmark regulation that classifies artificial intelligence systems by risk and imposes obligations on providers and deployers. In a medical device company like Dexcom, AI may be used in algorithms that analyse glucose data to provide insights. This role supports the company's response to AI Act requirements, ensuring AI innovations are compliant while still reaching the market.

What certifications will give me an edge?

CIPP/E (Certified Information Privacy Professional/Europe) is the most recognised certification for this role. CIPM (Certified Information Privacy Manager) is also valuable because the job requires process ownership and project management. If you already hold these, highlight them prominently; if not, consider obtaining CIPP/E before applying.

Can I apply if I have a law degree but no privacy certification?

Yes. The job description says certification is 'preferred', not required. At least 5 years of hands-on privacy experience in a relevant industry can compensate. However, you should demonstrate that you have kept up with current developments, perhaps through continuous legal education courses or published thought leadership.

Advertisement
Ad slot — configure in AdSense

More Legal Job Opportunities

jobs

Fund Legal – Assistant Vice President

State Street

📅 Open

View Details →
jobs

Legal Counsel / Senior - Real Estate Investments

SD Legal

📅 Open

View Details →
jobs

Legal Counsel – Calvin James Recruitment (Abu Dhabi, UAE)

Calvin James Recruitment

📅 Open

View Details →
jobs

Senior Legal Counsel - Digital Banking

SD Legal

📅 Open

View Details →
Advertisement
Ad slot — configure in AdSense