Purpose
The Compliance & Data Protection Officer reporting to the Group Data Protection Officer / Health, Safety and Compliance Manager. The Compliance & Data Protection Officer is responsible for supporting and maintaining the organisation's compliance, governance, and data protection framework. The role will lead day-to-day GDPR and data protection activities, oversee supplier compliance and due diligence processes, support ISO management systems, maintain compliance documentation, and assist with ESG reporting and governance requirements.
The post holder will work closely with the Group Data Protection Officer / Health, Safety and Compliance Manager. And the internal stakeholders, suppliers, and external auditors to ensure the organisation meets its legal, regulatory, contractual, and ethical obligations while promoting a culture of continuous improvement, accountability, and compliance.
Main Tasks, Objectives & Key Responsibilities
GDPR & Data Protection
- Act as the organisation's lead for day-to-day GDPR and Data Protection compliance activities.
- Maintain Records of Processing Activities (RoPA), data inventories, data asset registers, and compliance documentation.
- Ensure personal and business data is collected, processed, stored, retained, and disposed of in accordance with UK GDPR and Data Protection legislation.
- Conduct DPIA screening and complete Data Protection Impact Assessments (DPIAs) where required.
- Support Data Subject Access Requests (DSARs), data deletion requests, and information rights enquiries.
- Investigate data breaches, privacy incidents, and non-conformities, ensuring appropriate escalation and corrective actions are implemented.
- Monitor compliance with data protection policies and identify opportunities for improvement.
- Promote Privacy by Design and Privacy by Default principles across projects and business activities.
- Deliver awareness training and guidance on data protection responsibilities.
Supplier Assurance & Due Diligence
- Manage supplier compliance onboarding processes and pre-qualification assessments.
- Conduct supplier due diligence reviews to assess:
- GDPR and Data Protection compliance
- Information Security arrangements
- Health & Safety compliance
- ESG and sustainability standards
- Professional accreditations and certifications
- Insurance and regulatory compliance requirements
- Review supplier documentation, policies, certifications, and compliance evidence.
- Ensure suppliers meet organisational requirements before approval and onboarding.
- Maintain supplier assurance records and risk assessments.
- Support ongoing supplier compliance reviews and monitoring activities.
- Identify, assess, and escalate supplier-related compliance risks.
ISO Compliance & Incident Management
- Support the maintenance and continual improvement of ISO Management Systems, including ISO 9001, ISO 14001, ISO 45001 and ISO 27001 where applicable.
- Coordinate internal audits and support external certification audits.
- Maintain compliance records and evidence required for certification and regulatory reviews.
- Manage compliance incidents, non-conformities, and corrective action processes.
- Monitor action plans arising from audits, inspections, incidents, and risk assessments through to completion.
- Support the investigation of compliance failures and recommend corrective and preventative measures.
ESG (Environmental, Social & Governance)
- Support ESG data collection, validation, and reporting activities.
- Maintain ESG records, evidence, and supporting documentation.
- Assist with sustainability initiatives and corporate social responsibility programmes.
- Support ESG audits, assessments, and assurance reviews.
- Monitor ESG action plans and performance indicators.
- Assist with responding to customer and stakeholder ESG questionnaires.
Audits & Compliance Monitoring
- Prepare audit documentation and evidence for internal and external audits.
- Monitor compliance against policies, procedures, regulatory requirements, and contractual obligations.
- Conduct routine compliance monitoring activities and identify opportunities for improvement.
- Complete customer, supplier, and regulatory questionnaires and compliance submissions.
- Track audit findings and corrective actions to ensure timely completion.
- Support the development of compliance reports, dashboards, and management information.
Data Management & Document Control
- Maintain effective document control and information governance processes.
- Ensure accurate filing, retention, security, and disposal of business records.
- Maintain structured electronic filing systems and document repositories.
- Conduct regular data quality and compliance reviews.
- Ensure controlled documents remain current and accessible.
- Drive continuous improvement in document control and record management processes.
Policies & Procedures
- Support the development, review, implementation, and communication of organisational policies and procedures.
- Maintain document version control and policy review schedules.
- Assist in drafting new policies, standards, guidance notes, and work instructions.
- Ensure compliance documentation reflects current legislation, standards, and business requirements.
- Promote consistent application of policies and procedures across the organisation.
Skills, Knowledge & Experience
Essential
- Experience working within Compliance, Data Protection, Governance, Risk, Quality, Information Governance, or a similar environment.
- Good understanding of UK GDPR and Data Protection legislation.
- Experience maintaining compliance records and management systems.
- Experience supporting audits and compliance monitoring activities.
- Strong organisational, administrative, and document control skills.
- Excellent attention to detail and accuracy.
- Ability to identify and assess compliance risks.
- Strong communication and stakeholder management skills.
- Proficient in Microsoft Office applications and document management systems.
- Experience conducting supplier due diligence and third-party risk assessments.
- Experience supporting ISO Management Systems and certification audits.
- Knowledge of ESG reporting and sustainability requirements.
- Experience within Health & Safety or Information Security environments.
- Data Protection, Compliance, ISO Internal Auditor, or Governance related qualification.
- Understanding of ISO 9001, ISO 14001, ISO 45001 and ISO 27001 requirements.
Personal Attributes
- Proactive and self-motivated.
- Highly organised with excellent time management skills.
- Professional, trustworthy, and discreet when handling sensitive information.
- Approachable, collaborative, and supportive.
- Strong analytical and problem-solving abilities.
- Able to work independently and prioritise competing demands.
- Committed to continuous learning and professional development.
- Demonstrates sound judgement and accountability.
Vista Values
The post holder will actively demonstrate and promote Vista's values:
- Customer Focused
- Teamwork
- Professional Standards
- Creative and Innovative
- Passionate and Proud
- Responsible and Accountable
- Ethical
- Honest
- Trust and Respect
- Environmental Sustainability
- Socially Responsible
Benefits
- Free On-Site Parking
- Private Healthcare
- Group Income Protection
- Life Assurance
- Pension Scheme
- Employee Assistance Programme
- Professional Training and Development Opportunities
Pay: £35,000.00-£40,000.00 per year
Benefits:
- Casual dress
- Company pension
- Free flu jabs
- Free parking
- On-site parking
- Private medical insurance
- Referral programme
Work Location: In person