Counsel, Legal, Privacy and Cybersecurity - Asia-Pacific Region

LenovoApplyPublished 4 days agoFirst seen 1 days ago
Apply

Why Work at Lenovo

We are Lenovo. We do what we say. We own what we do. We WOW our customers. 

Lenovo is a US$83 billion revenue global technology powerhouse, ranked #153 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world’s largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo’s continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY). 

This transformation together with Lenovo’s world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit www.lenovo.com, and read about the latest news via our StoryHub.

Description and Requirements

Lenovo is seeking an experienced, business-oriented AP Privacy Counsel based in Japan to join Lenovo’s Legal Department and Privacy & Data Protection team. This role will work closely with the Senior AP Privacy Counsel and support Lenovo’s privacy, cybersecurity, data protection matters across Asia Pacific, with a particular focus on Japan and Lenovo’s Japan-based subsidiaries.

The successful candidate will be a bilingual legal and privacy professional who can operate fluently in both Japanese and English.

The role requires strong knowledge of Japan’s Act on the Protection of Personal Information, guidance from Japan’s Personal Information Protection Commission, and Japan-specific cybersecurity and data-related laws and regulations, including the Basic Act on Cybersecurity, relevant NISC and METI cybersecurity guidance, and sector-specific or technology-specific cyber, data, and security requirements.

The role will also provide limited support on Japan-specific AI governance matters, including the privacy, cybersecurity, and data protection implications of AI-enabled products, services, and internal tools.

Key Responsibilities

Japan Privacy and Cybersecurity Advisory Support

  • Provide legal advice on privacy, data protection, cybersecurity, data incident response, data governance, and responsible data use across Lenovo’s Japan operations and Japan-based subsidiaries.
  • Advise Japan-based Lenovo entities and subsidiaries on compliance with Japan’s Act on the Protection of Personal Information, related Cabinet Orders and PPC guidelines, data breach notification requirements, cross-border transfer rules, consent and transparency requirements, data subject rights, vendor management, employee data, customer data, and sensitive personal information.
  • Advise on Japan cybersecurity and related data regulations, including the Basic Act on Cybersecurity, NISC cybersecurity policies, METI cybersecurity guidance, cyber incident reporting expectations, critical infrastructure considerations, and sector-specific security requirements.
  • Monitor, analyze, and report on privacy, data protection, cybersecurity and related regulatory developments in Japan and across AP. Assess the impact of new laws, regulatory guidance, enforcement trends, government policies, and industry standards on Lenovo’s Japan business, Japan-based subsidiaries, products, services, customers and internal operations.
  • Serve as a trusted Japan-facing counsel for local business stakeholders, subsidiary leadership, and regional legal and compliance teams on privacy, cybersecurity, and data-related risks. Work closely and coordinate with Japan team Legal to ensure that privacy and cybersecurity obligations are understood and embedded into day-to-day operations.
  • Provide dedicated privacy, cybersecurity, and data protection support to Lenovo’s subsidiaries and affiliated entities based in Japan. Help Japan-based subsidiaries implement Lenovo’s global and regional privacy and cybersecurity policies in a way that is practical, locally compliant, and aligned with Japanese regulatory expectations. Act as a bridge between Japan-based subsidiaries and Lenovo’s global and AP privacy, cybersecurity, legal, and compliance teams.

Privacy-by-Design and Reviews

  • Conduct and support privacy reviews for products and services, including platforms, AI-enabled features, software, hardware, cloud services, managed services, enterprise solutions, connected devices, internal tools, marketing technologies, and IT systems.
  • Review data flows, system architecture, product designs, customer-facing platforms, employee systems, and vendor integrations to identify and mitigate privacy and regulatory risks.
  • Work with product, technology, information security, and product security teams to embed privacy-by-design and appropriate controls, including data minimization, purpose limitation, transparency, consent, access controls, retention, deletion, secure data transfers, amongst others.
  • Provide limited support on Japan-specific AI governance matters as part of product, service, and internal tool reviews, focusing on the privacy, cybersecurity, and data protection implications of AI-enabled products, services, and internal tools.

Incident Response and Regulatory Engagement

  • Partner with Lenovo’s information security, product security, legal, communications, IT, and business teams (as relevant) to investigate suspected or actual privacy and cybersecurity incidents involving Japan operations, Japan-based subsidiaries, customers, employees, vendors, or systems.
  • Advise on incident assessment, privilege, containment, mitigation, legal analysis, regulatory notification, customer communications, data subject notices, contractual notification obligations, and internal reporting.
  • Support breach assessment and notification obligations under Japan’s APPI and PPC guidance, and advise on cyber incident reporting considerations under applicable Japan cybersecurity, sector-specific, or contractual requirements.
  • Assist with regulatory inquiries, audits, investigations, customer escalations, government requests, and law enforcement requests involving privacy, cybersecurity, data handling, or information security matters in Japan.
  • Help Japan-based subsidiaries prepare for incident response by supporting escalation pathways and stakeholder training.

Commercial Privacy and Third-Party Risk Support

  • Review, negotiate, and advise on privacy-related clauses, data protection agreements, cross-border transfer mechanisms, intra-group data sharing, outsourcing and entrustment arrangements, onward transfers, customer security requirements, vendor due diligence, and ongoing vendor governance.
  • Support procurement and business teams in assessing third-party privacy risks for Japan and AP engagements.
  • Support Japan-based subsidiaries in customer and partner negotiations where local privacy, cybersecurity, or data localization concerns arise.

Privacy and Cybersecurity Program, Governance, and Training

  • Support global and regional privacy program initiatives, including developing data governance frameworks, data mapping, records of processing, privacy assessments and compliance monitoring.
  • Develop and deliver bilingual Japanese and English training, awareness materials, FAQs, playbooks, and guidance for legal, business, product, sales, marketing, procurement, HR, customer service, IT, and security stakeholders.
  • Support senior privacy counsels and product privacy counsels to ensure consistent application of Lenovo’s global standards while accounting for Japan-specific and subsidiary-specific requirements.
  • Support privacy and cybersecurity advice across other AP markets, including Australia, Singapore, India, South Korea, Malaysia, Thailand, Indonesia, and other jurisdictions as needed.

Required Qualifications

  • LLB, JD, or equivalent legal qualification.
  • Licensed or qualified to practice law in Japan or another relevant jurisdiction; Japan qualification is strongly preferred.
  • Fluency in both Japanese and English is required, including the ability to draft, negotiate, advise, and present in both languages.
  • 8+ years of experience advising on privacy, data protection, cybersecurity, technology, commercial, regulatory, or related legal matters, preferably in a multinational technology, IT, hardware, software, cloud, services, telecommunications, infrastructure, or digital business environment.
  • Strong working knowledge of Japan’s Act on the Protection of Personal Information, PPC guidelines, breach notification requirements, cross-border transfer rules, data subject rights, outsourcing and entrustment requirements, and privacy compliance expectations.
  • Strong understanding of Japan cybersecurity and related cyber/data regulations, including the Basic Act on Cybersecurity, NISC and METI cybersecurity guidance, cyber incident reporting expectations, and sector-specific or technology-specific security requirements (e.g. Telecommunications Business Act considerations).
  • Demonstrated ability to advise Japan-based subsidiaries, senior local stakeholders, and regional/global teams on privacy, cybersecurity, and data protection issues.
  • Experience conducting privacy impact assessments, data transfer assessments and vendor privacy reviews.
  • Hands-on experience supporting incident response, breach assessment, regulatory engagement, customer escalations, and internal investigations.
  • Experience reviewing and negotiating privacy provisions in commercial, vendor, partner, and customer agreements.
  • Excellent written and verbal communication skills, with the ability to explain complex legal, technical, and regulatory issues clearly to senior leaders, commercial teams and operational stakeholders.
  • Strong analytical judgment, project management skills, stakeholder management skills, and ability to operate in a fast-paced, matrixed, global environment.

Preferred Qualifications

  • Experience in a global privacy program, regional AP privacy role, Japan privacy/cybersecurity counsel role, or in-house legal role supporting Japan subsidiaries of a multinational company.
  • Thorough understanding of intra-group data transfers and data sharing arrangements, including the privacy, cross-border transfer, governance, documentation, and compliance implications of sharing personal information across affiliated entities, Japan-based subsidiaries, and regional or global group companies.
  • Familiarity with cybersecurity frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, SOC 2, CIS Controls, or similar frameworks.
  • Experience with Japan regulatory engagement, including interactions with or advice relating to the PPC, MIC, METI, NISC, JPCERT/CC, or sector regulators.
  • Privacy certifications such as CIPP/E, CIPP/A, CIPM, CIPT or equivalent.

Key Competencies

  • Business-oriented legal judgment and practical problem-solving.
  • Strong bilingual communication and drafting capability in Japanese and English.
  • Ability to support local Japan stakeholders while aligning with global and AP privacy and cybersecurity strategy.
  • Strong collaboration across legal, technical, commercial, security, product, and operational teams.
  • Ability to work independently while managing multiple subsidiaries, markets, projects, and stakeholders.
  • Ability to balance legal risk, cybersecurity risk, customer expectations, regulatory requirements, business priorities, and operational feasibility.