SonicJobs Logo
Left arrow iconBack to search

Sr. Privacy Compliance Specialist

Edible Arrangements, LLC
Posted a day ago, valid for 12 days
Location

Atlanta, GA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Edible Brands® is seeking a Sr. Privacy Compliance Specialist with a Bachelor's degree and 3-5 years of experience in privacy, compliance, or data governance roles.
  • The role involves managing the privacy compliance platform, handling Data Subject Access Requests (DSARs), and ensuring regulatory compliance across various brands.
  • Candidates should have hands-on experience with privacy platforms like OneTrust and knowledge of GDPR, CCPA, and state privacy laws.
  • The position is based in Sandy Springs, GA, and requires strong project management skills and the ability to collaborate across multiple teams.
  • Salary information is not provided, but the role emphasizes technical ownership and proactive risk management in privacy compliance.

Sr. Privacy Compliance Specialist

Edible Brands® was launched in 2022 to bring together powerful, purpose-led brands under one unified purpose: to enrich everyday life through celebration, nourishment, and wellness. Today, Edible Brands powers three bold and growing concepts across 700+ locations worldwide.

Our portfolio spans Edible Arrangements®, the iconic gifting brand; Rōti®, a Mediterranean-inspired fast-casual restaurant; edibles.com™, a trusted marketplace for low-dosage THC & CBD wellness products; and BerryDirect®, our robust supply chain infrastructure. Together, these brands are fueled by The Edible Way—a set of employee-driven values that keep us committed, collaborative, adaptable, results-driven, and always ready to celebrate.

The Big Picture:

Edible Brands® is committed to maintaining the highest standards of privacy compliance and regulatory adherence as we scale our operations across our portfolio of brands and geographies. The Privacy Compliance Specialist is a hands-on technical ownership role for our privacy and consent management platform (currently OneTrust), and the operational backbone of our Data Subject Access Request (DSAR) and consent management programs. This role strategically bridges Legal, Information Security, Engineering, Marketing Operations, and Data Analytics to establish and maintain enterprise-wide privacy governance, data subject request management, and regulatory compliance.

As privacy regulations expand (GDPR, CCPA, state privacy laws, and emerging frameworks), this role ensures our organization has clear ownership of Data Subject Access Requests (DSARs), deletion workflows, consent management, and cross-system compliance. The ideal candidate is detail-oriented, technically hands-on, systems-minded, and comfortable navigating ambiguity while coordinating across technical, legal, and business teams. This role reports to Legal/Compliance leadership and is essential to our post-Shopify migration strategy.

Location: This position will work onsite out of our Corporate Office in Sandy Springs, GA Monday – Friday.

What this looks like day to day:

  • Own the implementation, administration, and optimization of the privacy compliance platform (e.g., OneTrust), including consent management, preference centers, cookie categorization, regulatory settings, workflows, user permissions, integrations, testing, and deployments.
  • Serve as the primary point of contact and relationship owner for the privacy platform vendor, managing support escalations, tracking contract terms and renewal timelines, and coordinating any implementation or professional services engagements.
  • Define, document, and continuously improve privacy operations, including consent governance, Data Subject Access Request (DSAR) intake, identity verification, deletion workflows, cross-functional execution procedures, and audit-ready documentation. 
  • Manage end-to-end DSAR and data deletion processes across all business systems, meeting statutory response deadlines and other applicable laws, ensuring timely completion, regulatory compliance, and maintenance of audit trails and proof of deletion. 
  • Monitor DSAR response timelines, coordinate execution with internal teams and third-party vendors, verify request completion across systems, and escalate risks or delays as needed. 
  • Maintain a complete inventory of cookies, tags, third-party vendors, and data integrations across all digital properties, ensuring proper categorization and alignment with user consent preferences. 
  • Conduct ongoing cookie, tag, and tracking technology audits (including via Google Tag Manager) to identify undocumented technologies and partner with Marketing to ensure analytics and marketing tools honor consent signals. 
  • Serve as the primary privacy operations partner to Legal, Engineering, Marketing, Information Security, Data Analytics, and external vendors by coordinating governance meetings, compliance initiatives, vendor privacy reviews, and cross-functional projects.
  • Partner with Legal to support privacy notices, data processing agreements, regulatory interpretation, and broader privacy governance initiatives. 
  • Stay current on GDPR, CCPA, and emerging U.S. state privacy laws; prepare compliance reports and audit documentation while identifying, mitigating, and escalating privacy risks and compliance gaps. 
  • Support the development of privacy policies, data governance standards, and best practices for data collection, processing, retention, and deletion across the organization.
  • Maintain and continuously update the organization’s data inventory / Records of Processing Activities (RoPA) across business systems.

What you bring:

  • Bachelor's degree required; background in privacy, compliance, legal operations, or data governance preferred. 
  • Minimum 3–5 years of experience in privacy, compliance, legal operations, or data governance roles, including direct hands-on configuration (not just use) of consent management or privacy platforms (OneTrust, TrustArc, Termly, or similar)
  • Hands-on experience with Shopify, e-commerce platforms, or retail-specific privacy compliance. 
  • Demonstrated knowledge of GDPR, CCPA, and state privacy laws; experience managing Data Subject Access Requests (DSARs) or data deletion requests against statutory deadlines.
  • Experience partnering directly with vendors including support escalation, contract renewals and negotiations, and evaluation of vendor performance.
  • Familiarity with engineering/development workflows and the ability to work with technical teams. 
  • Proficiency with Microsoft 365, data inventory/mapping tools, and analytics platforms. 
  • Preferred: 
  • CIPP (Certified Information Privacy Professional) certification or willingness to pursue. 
  • Experience with data inventory or data governance platforms (Collibra, Traction, Alation).
  • Background in a multi-brand, regulated, or scaled legal/compliance function.

How you work:

  • Strong project management and organizational skills, with the ability to manage multiple priorities and coordinate across teams. 
  • Excellent written and verbal communication skills, with the ability to translate technical and legal concepts for diverse audiences. 
  • Strong attention to detail, discretion, and the ability to handle confidential information.
  • Comfortable being the in-house technical owner of a critical compliance system, proactively flagging risk rather than being asked.

We are proud to be an EEO/AA employer. Applicants for employment are considered without regard to race, creed, color, religion, sex, sexual orientation, marital status, national origin, age, disability, or veteran status.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.