Draft, review, and negotiate a broad range of customer-facing agreements across multiple jurisdictions, including MSAs, SaaS and platform contracts.
Oversee the contract lifecycle for customer agreements, leveraging existing automation, with a hands-on focus on larger and non-standard contracts and on keeping the underlying processes current across 1NCE's key markets in Europe, the Americas, and Asia-Pacific.
Advise on jurisdiction-specific requirements and adapt standard contract frameworks for local law compliance across 1NCE's operating markets.
Draft, review, and negotiate vendor and supply chain agreements.
Support the commercial team by developing and maintaining standard customer contract templates, GTCs, negotiation playbooks, and pre-approved fallback positions.
Advise the business on GDPR compliance, working in close coordination with the DPO and CISO.
Support developing, maintaining, and continuously improving 1NCE's privacy compliance framework — including ROPA, privacy policies and notices, consent and cookie mechanisms, internal data protection policies, data subject request handling, and vendor privacy reviews.
Support privacy compliance across 1NCE's key jurisdictions beyond the EU (including the US and Singapore), coordinating with external counsel where local depth is required.
Draft, review, and negotiate data processing agreements (DPAs), data transfer clauses, and joint controller arrangements as part of customer and vendor contract workflows.
Support international data transfer compliance, including EU Standard Contractual Clauses and adequacy framework monitoring, and assist the DPO with TIAs and DPIAs where additional internal capacity is needed.
Monitor and understand developments in EU data protection and tech regulation (including the EU AI Act, Data Act, ePrivacy and CRA) and translate them into practical guidance for the business.
Support the business on contentious commercial matters with customers, partners and suppliers through negotiation, settlement, and pre-litigation resolution, instructing and supervising external counsel where required.
Identify, assess, and communicate legal risk to the business clearly and actionably.
Support the development of internal compliance policies and risk frameworks.
Act as trusted legal advisor to Sales, Product, IT, Security, Finance/Accounting and Operations.
Requirements
Fully qualified lawyer in Germany (Volljurist/in); Syndikusrechtsanwalt status preferred or obtainable.
Minimum 5 years of post-qualification experience covering commercial / technology law and data protection, ideally combining law firm and in-house experience.
Strong track record in drafting and negotiating customer-facing commercial agreements across multiple jurisdictions.
Strong working knowledge of GDPR and demonstrated experience operationalising privacy compliance — e.g. ROPA, privacy notices, consent and cookie mechanisms, internal policies and data subject request processes — not solely in a contract-review context.
Experience handling contentious commercial matters and negotiating settlements with customers, partners or suppliers.
Comfortable working in a small team with a broad mandate and global scope, with a hands-on attitude and sound judgement on prioritisation.
Genuine interest in the IoT, telecommunications, software and cloud space; prior in-house or law firm experience in these sectors is strongly preferred.
Fluent in German and English — written and spoken.
Tech Stack
Cloud
IoT
Benefits
Competitive compensation package
Flexible hybrid working from Cologne, Hamburg or elsewhere