We are looking for an experienced data protection manager to join our Compliance team to act as our main data protection and privacy colleague and to continue the development and maturation of the Group’s privacy function.
The successful candidate will have full responsibility for continuing the development of our data protection and privacy framework, further enhancing our existing posture, and continuing its ongoing development, in line with regulatory, technical, and other developments. This role reports directly to the Group Head of Compliance/Chief Risk Officer and has responsibilities covering all of the Group’s entities.
Key responsibilities:
- Assessing projects, new initiatives, products, and services for Data Protection/Privacy compliance, and conducting Data Protection Impact Assessments (DPIAs) and other privacy risk assessments as necessary.
- Supporting the maintenance and enhancement of the Group’s Data Protection/Privacy framework to ensure compliance with applicable laws, regulations, and internal policies, while fostering a privacy-respecting and trust-building corporate culture.
- Collaborating with business areas to identify, document, and track Data Protection/Privacy risks, recommending and reporting on risk mitigation actions through formal organisational processes.
- Leading the response to any Data Protection/Privacy breaches, in line with ICO guidance.
- Liaising with the ICO and data subjects where notification has been deemed necessary
- Conducting Root Cause Analyses (RCAs) on Data Protection/Privacy breaches and recommending enhancements.
- Supporting the firm in developing and maintaining its Record of Processing Activities (RoPA).
- Leading the production of information for Data Subject Access Requests (DSARs), in collaboration with Compliance and IT teams.
- Leading the delivery of regular Data Protection/Privacy training for the firm.
- Maintaining and enhancing the firm’s Data Protection/Privacy Policies and Procedures.
- Advising on proposed projects or supplier engagement where there may be Data Protection/Privacy considerations.
- Horizon-scanning and monitoring of regulatory developments and changes.
- Assessing contracts, DSA’s, and other legal documentation which involves Data Protection/Privacy stipulations.
Necessary
- Comfortable working autonomously as the sole data protection colleague
- Extensive experience with the UK GDPR, DPA 2018, and PECR
- Experience managing complex DSAR’s and other information rights requests
- Motivated individual who can work to tight deadlines and balance competing priorities
- Excellent written and verbal communication skills, particularly communicating
- Strong time management and organisational skills
Desirable Attributes
- Experience with AI impact assessments
- CIPM certification
- CIPP/E certification
- Previous project management experience
- DPO/deputy DPO experience