Data Protection Officer

3 weeks ago


London, United Kingdom Hays Full time

Group Data Protection Officer, FTSE Organisation


Reporting to:


Group General Counsel & Company Secretary.


Role Objectives:

Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and take a lead on data protection within the Group. Within this role you will monitor compliance and data practices internally to ensure the business and its functions comply with the applicable requirements under the GDPR and other relevant legislation. As well as this, you will be responsible for advising on, and where required carrying out, staff training, data protection impact assessments, data transfer impact assessments, and internal audits.


Given this is a newly created role for a Global FTSE organisation, it will give you the ability to shape the function and make a huge difference to the organisation. The company is constantly evolving, and you will be a key part of that, as well as being expected to contribute strategically. The responsibility of the data protection function across the Group is within 30+ countries and the company have a fantastic, inclusive culture and are always striving to do the right thing.


Requirements, Skills and Competencies:

In this role, you will work closely with the Legal and Compliance function, as well as other group functions, to develop and monitor policies and standards applicable to the business and in compliance with the GDPR and other relevant legislation. Your responsibilities will include, but not be limited to:

  • Implementing measures and a privacy governance framework to manage data use in compliance with the GDPR and other relevant legislation, including developing templates for data collection.
  • Working with key internal stakeholders in the review of operations and projects and related data processing to ensure compliance with data privacy laws, and where necessary, advising on and monitoring data protection privacy impact assessments.
  • Serving as the primary point of contact and liaison for the relevant supervisory authority on all data protection related matters under the GDPR and other relevant legislation.
  • Serving as the primary point of contact for data protection queries in the business.
  • Reviewing vendor contracts (including relevant standard contractual clauses and transfer impact assessments for international data transfers) and other third-party data processing and data sharing arrangements in partnership with the organisation's Legal and Information Security functions.
  • Ensuring fee requirements with the relevant supervisory authority are achieved.
  • Advising on and assisting with data mapping and records of data processing, and vendor management reviews.
  • Managing and conducting ongoing reviews of the Group’s privacy governance framework and regular and ad hoc reporting on data privacy compliance within the organisation.
  • Monitoring changes to relevant privacy laws and making recommendations to the Executive Risk Committee when appropriate.
  • Setting standards and reviewing policies and procedures globally that meet the requirements under the GDPR and any localization requirements in countries of operation.
  • Developing and delivering privacy training to various business functions and collaborating with the Information Security function to raise employee awareness of data privacy and security issues.
  • Developing strategies and initiatives to ensure engagement with key internal and external stakeholders.
  • Coordinating, conducting, and monitoring data privacy audits and addressing any potential issues.
  • Collaborating with the Information Security function to maintain records of all data assets and exports and maintaining a personal data security incident management plan to ensure timely remediation of incidents impacting personal data including impact assessments, breach response, complaints, claims or notifications.
  • Responding to and advising on data subject rights requests, including data subject access requests (DSARs) and other requests from individuals.
  • Ensuring that the Group’s IT systems and procedures comply with all relevant data privacy and protection law, regulation and policy (including in relation to the retention and destruction of data).
  • Working with designated privacy lawyers, subject matter experts or champions across the Group’s offices and, where necessary, outside legal advisers to help advise on data privacy law issues.


Knowledge, Qualifications and Experience:


Education

  • Qualified lawyer preferred, but not essential
  • Holding at least one data protection and/or privacy certification, such as CIPP, CIPT, CIPM, ISEB, etc.


Work Experience

  • 5-10+ years (guideline only) data privacy experience or alternatively 5-10+ years’ experience within a compliance, legal, audit and/or risk function, with significant recent experience in privacy.
  • Experience in EU and International data privacy laws.
  • Experience in developing policy and compliance training.
  • Experience in setting up and improving data protection functions, across UK&I, Europe and Internationally.
  • Looking after the process Globally and advising key stakeholders.
  • Ideally experience within a FTSE/listed environment.


Required Knowledge, Skills, and Abilities

  • Expertise in data protection laws and practices, including strong knowledge of International and European data privacy and data protection regulation, and a good understanding of other major privacy frameworks and evolving legislation worldwide.
  • Well-developed and professional interpersonal skills; ability to interact effectively with people at all organisational levels of the firm.
  • A growth mindset, good commercial acumen and a pragmatic individual who is confident exercising judgment in a complex business environment.
  • Experience of working in a large, global organisation.
  • Ability to work unsupervised, exercise leadership and influence change.
  • Strong change and project management skills, including the ability to manage time well, prioritise effectively and handle multiple deadlines.
  • Ability to undertake large, long-term projects, develop alternative methods to complete them and implement solutions.
  • Ability to use independent judgement and discretion when making majority of decisions.
  • Detail-oriented approach needed to recommend and implement strategic improvements on a range of data privacy and data protection issues.
  • Ability to handle confidential and sensitive information with the appropriate discretion.


Additional Requirements

  • Some international travel may be required.
  • The statements contained in this role specification are not necessarily all-inclusive; additional duties may be assigned, and requirements may vary from time to time.



  • London, United Kingdom Data Idols Full time

    **Group Data Protection Officer**: **Salary: £100,000 to £110,000**: **Location: London - 2 days per week**: - We are currently looking for a Group Data Protection Officer to join one of the UK’s best-known brands and consumer platforms.**The Opportunity**: Data Idols is working with one of the UK’s best-known household brands that enables their...


  • London, United Kingdom La Fosse Associates Full time

    **Location**: - London - **Disciplines**: - Governance, Risk & Compliance (GRC) - **Job types**: - Contract Inside IR35 Remote Work - **Industry**: - Healthtech - **Salary**: £500 - £520 per day + Inside IR35 **Functions**: - Data Privacy Data Protection Data Protection Officer - **Seniority**: - Mid-level Senior - **Posted**: 4 hours ago **Job...


  • London, Greater London, United Kingdom Virgin Trains Full time

    Job Title: Data Protection OfficerLocation: London or BirminghamSalary: circa £60,000We are seeking a highly skilled Data Protection Officer to join our team. This role involves leading our organization's approach to data protection, ensuring compliance with relevant regulations and industry standards.About the Role:Develop and implement data protection...


  • London, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London, United Kingdom Christie's Full time

    The Role Christie’s is looking to recruit an experienced Data Protection Officer to lead the data governance and privacy strategy across our global business. As a key member of the Data & Insight team, the Data Protection Officer will play a pivotal role in shaping and implementing our data governance policies, processes and controls to ensure compliance...


  • East London, United Kingdom Pearson Whiffin Recruitment Full time

    **Salary: Circa £70k** **Location: East London** Our client, a highly reputable London University, is seeking an experienced Data Protection Officer to join their growing team. You will exercise the function of DPO, acting as first point of contact for Data Subjects, Regulators, Data Processors and other DPOs including advising on proposed reform to Data...


  • London, United Kingdom Department for Culture, Media and Sport Full time

    **Details**: **Reference number**: - 324013**Salary**: - £54,395 - £69,676- London: £59,774 - £69,676, National £54,395 - £63,405 + benefits.- A Civil Service Pension with an average employer contribution of 27%**Job grade**: - Grade 6- A(U)**Contract type**: - Fixed Term - Loan - Secondment**Length of employment**: - 2 years**Business area**: -...


  • London, United Kingdom Oakleaf Recruitment Full time

    Job title**:Data Protection Officer** Location: Randall Cl, London SW11 3TG Rate Of Pay**:£40000 per annum** Shift Patterns**:40 hour a week contract** **Information about the Role**: Our group consists of Mental Health facilities from Acute Mental Health Hospitals to Dementia Care Homes and Supported living facilities based across the UK. **Objectives...


  • London Area, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London Area, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • London Area, United Kingdom Insight Investment Full time

    Insight Investment is looking for a Data Proection Officer to join the Cyber Security team in London. As the designated Global Data Protection Officer and acting as the Data Security & Privacy subject matter expert, you will have a broad range of expertise across data privacy and security and be able to support and establish good practice data protection...


  • West London, United Kingdom Eames Consulting Full time

    **Job Details**: **Sector**: Technology- **Location**: West London- **Job Ref**: dataprotection12_1699550743- **Job Type**: Contract- **Salary**: £250.00 - £300.00 per day- **Contact**: Neelesh Maroo- **Duration**: 6 Months- **Start Date**: ASAP**Data Protection Officer - West London (Hybrid) 2-3 Days Per Week - £250 - £300 Per Day Inside IR35** My...


  • London, United Kingdom Munich Re Services Full time

    Data Protection Officer **Company** Munich Re Services **Location** London, United Kingdom - Job Purpose: A senior and principal role in data protection compliance and best practice within the Data Protection Team. This is across several worldwide MR Group entities and for various data privacy regulations. Serve as a primary contact and liaison on all data...


  • London, United Kingdom Howden Full time

    Job Description Who are we? Howden is a collective – a group of talented and passionate people all around the world. Together, we have pushed the boundaries of insurance. We are united by a shared passion and no-limits mindset, and our strength lies in our ability to collaborate as a powerful international team comprised of 18,000 employees spanning over...


  • London, United Kingdom Shaw Trust Full time

    “Shaw Trust promotes team spirit, inclusiveness and it is an organisation where everybody is somebody. I am proud to be part of this great organisation.” Purpose We are recruiting for a Data Protection Officer (DPO), working part time hours of 18.5 hours a week. This is a home-based role with travel required. The DPO reports to the Group Head of...


  • London, United Kingdom Hays Full time

    Group Data Protection Officer, FTSE Organisation Reporting to: Group General Counsel & Company Secretary. Role Objectives: Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and...


  • London,, UK, United Kingdom HAYS Full time

    Group Data Protection Officer, FTSE OrganisationReporting to: Group General Counsel & Company Secretary.Role Objectives: Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and take a...


  • London, United Kingdom HAYS Full time

    Group Data Protection Officer, FTSE OrganisationReporting to: Group General Counsel & Company Secretary.Role Objectives: Reporting to the Group General Counsel & Company Secretary, you will be responsible for overseeing the Group’s data protection function, including strategy and implementation on a Global scale. You will be a key decision maker and take a...