Toast is driven by building the all-in-one restaurant platform that helps restaurants operate their business, increase sales, engage guests, and keep employees happy. We’re seeking an experienced Privacy Attorney to join Toast’s Legal & Compliance team who will be a cornerstone of our global privacy strategy, serving as a key legal advisor on complex data initiatives and international growth.
As a member of our collaborative Privacy team, you will bridge the gap between legal theory and operational reality. You won’t just be spotting risks; you’ll be building the legal frameworks that allow Toast to scale safely and ethically. This is an opportunity to handle high-stakes negotiations and privacy product counseling in a fast-paced, tech environment with both B2B and B2C exposure.
About this roll* (Responsibilities)
- Vendor & Integration Excellence: Lead the legal review and negotiation of Data Processing Agreements (DPAs) with high-value vendors and strategic integration partners, ensuring alignment with Toast’s global privacy standards.
- Privacy Engineering & DPIAs: Conduct and oversee Data Protection Impact Assessments (DPIAs) for new products and complex data processing activities, providing actionable legal guidance to mitigate risk.
- Strategic Product Counseling: Act as a dedicated privacy partner to Product and Engineering teams. Review new features—from guest loyalty programs to fintech solutions—ensuring "Privacy by Design" is baked into the development lifecycle.
- International Expansion & Compliance: Help drive the legal strategy for Toast’s expansion into new markets, with a specific focus on the India DPDP Act, GDPR, and evolving US state laws.
- Cross-Functional Advocacy: Collaborate with the Privacy Program Management team to translate legal requirements into technical specifications and operational workflows.
- Data Governance & Transfers: Advise on complex cross-border data transfer mechanisms and contribute to the evolution of Toast's internal data governance policies and classification schemes.
- Individual rights support: advise on and support Toast’s individual rights process (including access, deletion and objection requests). Partner closely with Toast’s Operations team to ensure efficient responses to individual rights requests globally.
- Legal Expertise: LL.B. or LL.M. from a reputable university and a license to practice law in India.
- Experience: 7+ years of post-qualification experience (PQE) preferably specializing in privacy and data protection, ideally within a high-growth SaaS, Fintech, or global technology company. We will also consider commercial experience in negotiating DPAs and partnerships that would transfer well to our environment.
- Subject Matter Mastery: Deep understanding of the India DPDP Act, GDPR, and CCPA/CPRA. Experience navigating the intersection of privacy and financial regulations is a significant plus.
- Contractual Fluency: Proven track record of negotiating complex DPAs and privacy clauses in commercial contracts with global counterparties.
- Product Acumen: Ability to "speak tech." You should be comfortable discussing data flows, APIs, and privacy concepts such as controller/processor and DPIAs with engineers to identify privacy touchpoints.
- Communication & Influence: Exceptional drafting skills and the ability to communicate nuanced legal risks to non-legal stakeholders in a clear, concise, and solution-oriented manner.
- Certifications: CIPP/E, CIPP/A, or CIPP/US are highly encouraged
At Toast, we believe in "empathy with candor." You’ll join a team that values your legal expertise but also your ability to be a pragmatic business partner. We move fast, we celebrate wins together, and we are obsessed with the success of the restaurants we serve.
AI at Toast
At Toast, one of our company values is that we're hungry to build and learn. We believe learning new AI tools empowers us to build for our customers faster, more independently, and with higher quality. We provide these tools across all disciplines, from Engineering and Product to Sales and Support, and are inspired by how our Toasters are already driving real value with them. The people who thrive here are those who embrace changes that let us build more for our customers; it’s a core part of our culture.
Our Total Rewards Philosophy
We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.
How Toast Uses AI in its Hiring Process
Throughout the hiring process, our goal is to get to know you. We use AI tools to support our recruiters and interviewers with tasks like note-taking, summarization, and documentation of interviews to ensure they can be fully focused on your conversation. All hiring decisions are made by people.
Diversity, Equity, and Inclusion is Baked into our Recipe for Success
At Toast, our employees are our secret ingredient—when they thrive, we thrive. The restaurant industry is one of the most diverse, and we embrace that diversity with authenticity, inclusivity, respect, and humility. By embedding these principles into our culture and design, we create equitable opportunities for all and raise the bar in delivering exceptional experiences.
We Thrive Together
We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the restaurant community. To learn more about how we work globally and regionally, check out: https://careers.toasttab.com/locations-toast.
Apply today!
Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact [email protected].
------
For roles in the United States, it is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

