SW5 Consulting logo
SW5 ConsultingPosted 3 weeks ago

Data Protection Officer

HybridManchester, England, United Kingdom

Full Time

Job Summary

Provide independent, expert data protection oversight and practical guidance across the group's international operations in the UK, EU, Canada, the US, and Singapore. Own and mature the data protection governance framework, including DPIAs, Records of Processing Activities, breach governance, and regulatory liaison. Lead reviews on supplier due diligence, Data Processing Agreements, and international transfer mechanisms while maintaining a data protection risk register. Act as the point of contact for data subjects and supervisory authorities, including the ICO and Spanish AEPD, and design staff awareness training. Monitor internal compliance through risk-based reviews and audits, translating regulatory requirements into operational controls for senior management.

Required Qualifications

  • Significant hands-on experience in data protection, privacy governance, regulatory compliance or information governance in a regulated or complex international environment
  • Deep working knowledge of UK GDPR and EU GDPR, including Articles 30, 35, 37, 38 and 39
  • Practical experience applying UK GDPR and EU GDPR in business operations
  • Strong practical experience completing DPIAs, ROPAs, LIAs, DSRs, privacy notices, breach assessments, transfer assessments and supplier reviews
  • Proven ability to draft, review and implement data protection policies, procedures, training and governance reporting at a global level
  • Good understanding of information security, third-party risk management, data classification, retention, access management and incident management
  • Ability to translate legal and regulatory requirements into clear operational controls and pragmatic, business-friendly guidance
  • Leads by example, demonstrating integrity, discretion, professional independence and sound judgement
  • Able to influence senior stakeholders and constructively challenge decisions where data protection risk is not adequately addressed
  • Credible working across different cultures, jurisdictions and business functions in a complex global organisation
  • Able to prioritise competing demands, manage sensitive matters confidentially and maintain clear decision-making records
  • Strong communication, presentation, training and stakeholder-management skills
  • Degree or equivalent experience in law, compliance, information security, risk management, data governance, technology, business or a related discipline
  • Minimum 8 to 10 years' relevant experience in data protection, privacy, compliance, information governance or related regulatory roles
  • Demonstrable international exposure
  • CIPP/E, CIPM, CIPT, EU GDPR Practitioner, ISEB/BCS Data Protection, AEPD DPO certification or equivalent
  • A high standard of written and spoken English
  • Commitment to continuing professional development and maintaining expert knowledge of data protection law and practice
  • Eligible and willing to be notified or registered with supervisory authority registers, including the ICO and Spanish AEPD
  • Support equivalent DPO or contact-point requirements in other jurisdictions
  • Act as the appointed Data Protection Officer for the relevant group entities
  • Maintain independence, professional judgement and direct access to senior management
  • Own and mature the data protection governance framework: DPIAs, Records of Processing Activities, data subject rights, breach governance, policies, training, regulatory liaison and risk-based assurance
  • Lead, review and advise on DPIAs, Privacy Impact Assessments, Legitimate Interest Assessments and Transfer Risk Assessments
  • Create, maintain and periodically review Records of Processing Activities, data inventories, data-flow maps, lawful basis records, retention references and records of international data transfers
  • Support privacy by design and default by engaging early with technology, product, change, procurement and operational initiatives
  • Advise on and oversee global personal data breach governance, including risk assessment, regulatory notification, data subject communications, evidence retention and lessons learned
  • Maintain and improve data subject rights procedures (access, erasure, rectification, restriction, portability, objection, consent withdrawal and rights related to automated decision-making and profiling)
  • Review and advise on supplier data protection due diligence, Data Processing Agreements, controller/processor assessments, subprocessor governance, international transfer mechanisms and contract clauses
  • Monitor internal compliance through risk-based reviews, audits, control testing, issue tracking and management reporting
  • Design and deliver staff awareness, role-based training and targeted guidance for teams handling personal data
  • Act as a point of contact for data subjects and supervisory authorities
  • Maintain a data protection risk register, track remediation and provide clear, risk-based reporting to senior management and governance forums
  • Keep up to date with changes in privacy law, regulator guidance, enforcement trends and industry practice
  • Works independently and exercises professional judgement in line with DPO independence requirements
  • Escalates material data protection risks, regulatory matters and unresolved conflicts to senior management as appropriate
  • Contributes proactively to departmental plans, priorities, control improvements and governance reporting
  • Experience with privacy management, GRC, ticketing, workflow, risk or control-management tools
  • Comfortable working with data inventories, ROPA tools, registers and reporting dashboards
  • Experience in financial services, payments, FX, regulated technology or another regulated sector

Desired Qualifications

  • Experience with privacy management, GRC, ticketing, workflow, risk or control-management tools is desirable
  • Experience in financial services, payments, FX, regulated technology or another regulated sector is highly desirable
  • Fluency in another European language (Spanish, Dutch, French and similar) is desirable

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce