About Regenerus
Regenerus Labs is shaping the future of personalised healthcare. As an all-in-one platform and trusted practitioner community, our mission is to empower healthcare professionals to deliver faster, more accurate evidence-based care.
With a portfolio of 150+ tests, Regenerus is the UK’s go-to clinical partner for functional and integrative health practitioners. Built and designed for practitioners, we provide a comprehensive ecosystem of diagnostic lab testing, platform tools, education and clinical support that equips them at every stage of the clinical journey.
Role Summary
We are seeking a professional Compliance Officer to provide in-house ownership and coordination of Regenerus’ compliance, data protection and information governance framework, working closely with the Operations Director, external DPO, external IT provider, the Senior Management Team and department heads.
This role would support regulatory readiness, improve evidence and audit discipline, and make sure data protection, supplier due diligence, internal controls and compliance monitoring and relevant medical device requirements, including Software as a Medical Device, are properly embedded across the business.
Key responsibilities:
Data protection / UK GDPR
- Maintain and regularly review privacy notices, data protection policies, retention schedules and Records of Processing Activities (RoPA) to ensure ongoing compliance with data protection legislation.
- Coordinate and support Data Protection Impact Assessments (DPIAs), ensuring risks are identified, assessed and appropriately mitigated.
- Support the management and timely response of Data Subject Access Requests (DSARs) and other individual rights requests.
- Assist with the assessment, investigation, logging and management of data breaches, ensuring appropriate escalation and reporting procedures are followed.
- Liaise with the external Data Protection Officer (DPO) where specialist guidance, independent oversight or regulatory advice is required.
Software as a Medical Device
- Support regulatory assessments for software and AI-enabled products that may fall within the scope of Software as a Medical Device.
- Maintain relevant compliance records, risk assessments and supporting evidence, working with internal teams and external advisers where required.
- Support ongoing monitoring of regulatory requirements and help ensure appropriate controls are embedded throughout the product lifecycle.
CQC / quality support
- Support the collection, organisation and maintenance of evidence required for CQC readiness and regulatory reviews.
- Assist in maintaining governance records, policies and audit trails.
- Support ongoing compliance monitoring and quality assurance activities, while not holding formal Registered Provider responsibilities.
Information governance
- Maintain and update policies, SOPs and compliance documentation to ensure records remain accurate, organised and current.
- Support retention and access control reviews.
- Assist in promoting consistent and compliant information handling processes across departments and business functions.
Supplier due diligence
- Maintain accurate and up-to-date supplier compliance records, ensuring documentation is complete and readily accessible for audit and review purposes.
- Support the review of DPAs, SCCs/IDTAs/UK Addendum requirements and supplier security documentation to ensure compliance with data protection obligations.
Audit and compliance monitoring
- Conduct internal compliance checks against company policies and SOPs to support ongoing regulatory compliance.
- Monitor, track and maintain records of compliance gaps, corrective actions and supporting evidence to ensure timely resolution and accountability.
- Support preparations for CQC readiness and internal governance reviews.
Training and awareness
- Coordinate the delivery of compliance training across the organisation.
- Promote staff awareness and understanding of data protection, confidentiality, information security and incident reporting requirements.
Reporting
- Prepare and contribute to compliance reports and updates for SMT/Board reporting.
- Maintain accurate risk/action logs and progress trackers to support effective monitoring and governance.
Person Specification Skills & Experience
Essential:
- Previous experience in a compliance, governance, risk or regulatory role.
- Previous experience in medical compliance or regulation.
- Strong understanding of relevant legislation and regulatory requirements.
- Excellent attention to detail and analytical skills.
- Strong organisational and time management abilities.
- Ability to handle confidential and sensitive information professionally.
- Excellent written and verbal communication skills.
- Ability to work independently and manage multiple priorities.
- Competent in record management systems.
Desirable
- Professional compliance qualification or relevant certification.
- Knowledge of GDPR, data protection, health & safety, or employment legislation.
- Experience conducting audits or investigations.
Qualifications
- Educated to degree level or equivalent experience preferred.
- Relevant compliance, legal, business or governance qualification desirable.
Pay: £37,000.00 per year
Benefits:
- Casual dress
- Company pension
- Free parking
- Private medical insurance
Application question(s):
- Do you have experience in medical compliance or regulation?
Experience:
- Compliance management: 3 years (preferred)
Work authorisation:
- United Kingdom (required)
Work Location: In person