Data Protection Officer

2 weeks ago


London Area, United Kingdom Hays Full time

Group Data Protection Officer, FTSE Organisation


Reporting to:


Group General Counsel & Company Secretary.


Role Objectives:

Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and take a lead on data protection within the Group. Within this role you will monitor compliance and data practices internally to ensure the business and its functions comply with the applicable requirements under the GDPR and other relevant legislation. As well as this, you will be responsible for advising on, and where required carrying out, staff training, data protection impact assessments, data transfer impact assessments, and internal audits.


Given this is a newly created role for a Global FTSE organisation, it will give you the ability to shape the function and make a huge difference to the organisation. The company is constantly evolving, and you will be a key part of that, as well as being expected to contribute strategically. The responsibility of the data protection function across the Group is within 30+ countries and the company have a fantastic, inclusive culture and are always striving to do the right thing.


Requirements, Skills and Competencies:

In this role, you will work closely with the Legal and Compliance function, as well as other group functions, to develop and monitor policies and standards applicable to the business and in compliance with the GDPR and other relevant legislation. Your responsibilities will include, but not be limited to:

  • Implementing measures and a privacy governance framework to manage data use in compliance with the GDPR and other relevant legislation, including developing templates for data collection.
  • Working with key internal stakeholders in the review of operations and projects and related data processing to ensure compliance with data privacy laws, and where necessary, advising on and monitoring data protection privacy impact assessments.
  • Serving as the primary point of contact and liaison for the relevant supervisory authority on all data protection related matters under the GDPR and other relevant legislation.
  • Serving as the primary point of contact for data protection queries in the business.
  • Reviewing vendor contracts (including relevant standard contractual clauses and transfer impact assessments for international data transfers) and other third-party data processing and data sharing arrangements in partnership with the organisation's Legal and Information Security functions.
  • Ensuring fee requirements with the relevant supervisory authority are achieved.
  • Advising on and assisting with data mapping and records of data processing, and vendor management reviews.
  • Managing and conducting ongoing reviews of the Group’s privacy governance framework and regular and ad hoc reporting on data privacy compliance within the organisation.
  • Monitoring changes to relevant privacy laws and making recommendations to the Executive Risk Committee when appropriate.
  • Setting standards and reviewing policies and procedures globally that meet the requirements under the GDPR and any localization requirements in countries of operation.
  • Developing and delivering privacy training to various business functions and collaborating with the Information Security function to raise employee awareness of data privacy and security issues.
  • Developing strategies and initiatives to ensure engagement with key internal and external stakeholders.
  • Coordinating, conducting, and monitoring data privacy audits and addressing any potential issues.
  • Collaborating with the Information Security function to maintain records of all data assets and exports and maintaining a personal data security incident management plan to ensure timely remediation of incidents impacting personal data including impact assessments, breach response, complaints, claims or notifications.
  • Responding to and advising on data subject rights requests, including data subject access requests (DSARs) and other requests from individuals.
  • Ensuring that the Group’s IT systems and procedures comply with all relevant data privacy and protection law, regulation and policy (including in relation to the retention and destruction of data).
  • Working with designated privacy lawyers, subject matter experts or champions across the Group’s offices and, where necessary, outside legal advisers to help advise on data privacy law issues.


Knowledge, Qualifications and Experience:


Education

  • Qualified lawyer preferred, but not essential
  • Holding at least one data protection and/or privacy certification, such as CIPP, CIPT, CIPM, ISEB, etc.


Work Experience

  • 5-10+ years (guideline only) data privacy experience or alternatively 5-10+ years’ experience within a compliance, legal, audit and/or risk function, with significant recent experience in privacy.
  • Experience in EU and International data privacy laws.
  • Experience in developing policy and compliance training.
  • Experience in setting up and improving data protection functions, across UK&I, Europe and Internationally.
  • Looking after the process Globally and advising key stakeholders.
  • Ideally experience within a FTSE/listed environment.


Required Knowledge, Skills, and Abilities

  • Expertise in data protection laws and practices, including strong knowledge of International and European data privacy and data protection regulation, and a good understanding of other major privacy frameworks and evolving legislation worldwide.
  • Well-developed and professional interpersonal skills; ability to interact effectively with people at all organisational levels of the firm.
  • A growth mindset, good commercial acumen and a pragmatic individual who is confident exercising judgment in a complex business environment.
  • Experience of working in a large, global organisation.
  • Ability to work unsupervised, exercise leadership and influence change.
  • Strong change and project management skills, including the ability to manage time well, prioritise effectively and handle multiple deadlines.
  • Ability to undertake large, long-term projects, develop alternative methods to complete them and implement solutions.
  • Ability to use independent judgement and discretion when making majority of decisions.
  • Detail-oriented approach needed to recommend and implement strategic improvements on a range of data privacy and data protection issues.
  • Ability to handle confidential and sensitive information with the appropriate discretion.


Additional Requirements

  • Some international travel may be required.
  • The statements contained in this role specification are not necessarily all-inclusive; additional duties may be assigned, and requirements may vary from time to time.



  • London, United Kingdom Data Idols Full time

    **Group Data Protection Officer**: **Salary: £100,000 to £110,000**: **Location: London - 2 days per week**: - We are currently looking for a Group Data Protection Officer to join one of the UK’s best-known brands and consumer platforms.**The Opportunity**: Data Idols is working with one of the UK’s best-known household brands that enables their...


  • London Area, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London Area, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London Area, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London Area, United Kingdom Howden Full time

    Who are we? Howden is a collective – a group of talented and passionate people all around the world. Together, we have pushed the boundaries of insurance. We are united by a shared passion and no-limits mindset, and our strength lies in our ability to collaborate as a powerful international team comprised of 18,000 employees spanning over 100...


  • London Area, United Kingdom Hays Full time

    Group Data Protection Officer, FTSE OrganisationReporting to: Group General Counsel & Company Secretary.Role Objectives: Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and take a...


  • London Area, United Kingdom Hays Full time

    Group Data Protection Officer, FTSE OrganisationReporting to: Group General Counsel & Company Secretary.Role Objectives: Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and take a...


  • London Area, United Kingdom Barclay Simpson Full time

    Barclay Simpson is seeking a Chief Data Protection Officer to lead the development of their data protection programme from scratch. As a key figure in launching their B2C proposition, you will be responsible for ensuring compliance with DPA 2018 and GDPR regulations. Your duties will include monitoring internal data and compliance practices, ensuring...


  • London Area, United Kingdom Anson McCade Full time

    About the RoleAnson McCade is seeking an experienced Chief Data Protection Officer to lead our data protection and privacy efforts.The ideal candidate will have proven experience with data protection and privacy laws (e.g., CCPA, EU GDPR, Privacy Shield) and familiarity with industry standards (GAPP, BCR).Key ResponsibilitiesDevelop and implement data...


  • London Area, United Kingdom Barclay Simpson Full time

    Would you like to join a UK challenger bank as their first Data Protection Officer? They are a fully licensed scaleup launching consumer financial products and services the market at rapid pace. This is an opportunity for you to build a DP programme from scratch. You'll be a figurehead in launching their B2C proposition as every day will be different. You'll...


  • London, United Kingdom La Fosse Associates Full time

    **Location**: - London - **Disciplines**: - Governance, Risk & Compliance (GRC) - **Job types**: - Contract Inside IR35 Remote Work - **Industry**: - Healthtech - **Salary**: £500 - £520 per day + Inside IR35 **Functions**: - Data Privacy Data Protection Data Protection Officer - **Seniority**: - Mid-level Senior - **Posted**: 4 hours ago **Job...


  • London, Greater London, United Kingdom Virgin Trains Full time

    Job Title: Data Protection OfficerLocation: London or BirminghamSalary: circa £60,000We are seeking a highly skilled Data Protection Officer to join our team. This role involves leading our organization's approach to data protection, ensuring compliance with relevant regulations and industry standards.About the Role:Develop and implement data protection...


  • London Area, United Kingdom Barclay Simpson Full time

    Would you like to join a UK challenger bank as their first Data Protection Officer? They are a fully licensed scaleup launching consumer financial products and services the market at rapid pace.This is an opportunity for you to build a DP programme from scratch. You'll be a figurehead in launching their B2C proposition as every day will be different.You'll...


  • London Area, United Kingdom Commerzbank AG Full time

    A leading corporate banking and capital markets organisation, Commerzbank AG, is seeking a Data Protection Expert to support their Data Protection Officer in London.Main Purpose of this role:Supporting the Data Protection Officer with General Data Protection Regulation ('GDPR'), Group policy frameworks, and any other relevant privacy law or regulation to...


  • London Area, United Kingdom Insight Investment Full time

    Job Title: Data Protection OfficerInsight Investment is seeking a highly skilled Data Protection Officer to join its Cyber Security team in London. As the designated Global Data Protection Officer, you will be responsible for ensuring the organization's compliance with data protection regulations and laws.Key Responsibilities:Ensure personal information is...


  • London Area, United Kingdom Ventula Consulting LTd Full time

    Data Protection Officer and Information Security Manager One of the UK’s largest hospitality groups (owner or leading global restaurant brands) is recruiting for a Data Protection and Information Security Manager. The Head of Information Security & Data Protection Officer (DPO) will be responsible for leading the company’s information security strategy,...


  • London Area, United Kingdom Ventula Consulting LTd Full time

    Data Protection Officer and Information Security ManagerOne of the UK’s largest hospitality groups (owner or leading global restaurant brands) is recruiting for a Data Protection and Information Security Manager.The Head of Information Security & Data Protection Officer (DPO) will be responsible for leading the company’s information security strategy,...


  • London Area, United Kingdom Ventula Consulting LTd Full time

    Data Protection Officer and Information Security ManagerOne of the UK’s largest hospitality groups (owner or leading global restaurant brands) is recruiting for a Data Protection and Information Security Manager.The Head of Information Security & Data Protection Officer (DPO) will be responsible for leading the company’s information security strategy,...


  • London, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...