- Company Name
- hackajob
- Job Title
- Data Protection Officer
- Job Description
-
Job Title: Data Protection Officer
Role Summary
Lead and manage the organisation’s data protection compliance, ensuring full adherence to UK GDPR, Data Protection Act 2018, DUAA, PECR, and relevant ICO guidance. Collaborate with legal, compliance, audit, engineering, product, security, HR, and commercial teams to embed privacy‑by‑design, maintain records, and foster a privacy‑first culture across all product and service lines.
Expectations
- Act as principal liaison with the Information Commissioner’s Office (ICO).
- Develop, implement, and update the data‑protection strategy, policies, and internal controls.
- Maintain comprehensive Records of Processing Activities and lead all DPIAs, LIAs, and TRAs.
- Oversee data‑subject rights processes and ensure timely response to access, erasure, rectification, and objection requests.
- Advise on vendor due diligence, DPAs, and DSAs with third parties.
- Design and deliver privacy training and awareness programmes to embed a privacy‑first mindset.
- Conduct regular audits, risk assessments, and horizon scanning to identify and mitigate privacy risks.
- Report on compliance status, incidents, and programme maturity to senior leadership.
- Support security incident management, including breach investigation and ICO reporting where necessary.
- Provide guidance on AI‑related privacy considerations and emerging regulatory developments.
Key Responsibilities
- Regulatory compliance: Monitor UK data‑protection landscape, address changes, and maintain GDPR‑compliant processes.
- Governance & advisory: Create and enforce governance frameworks, privacy‑by‑design principles, and consent management strategies.
- Training & culture: Develop training modules, campaigns, and resources; champion privacy literacy organization‑wide.
- Monitoring & risk management: Perform audits, assess third‑party compliance, manage privacy risk register, and deliver regular reports.
- Incident response: Lead breach investigations, coordinate with Information Security, and manage ICO reporting requirements.
Required Skills
- Proven experience as a DPO, Privacy Manager, or equivalent within a UK tech or data‑rich organisation.
- In‑depth knowledge of UK GDPR, DPA 2018, DUAA, PECR, and ICO guidance.
- Strong practical experience with DPIAs, risk assessments, audits, and compliance framework implementation.
- Familiarity with technical and organisational security controls, SSDLC, data architecture, and modern data ecosystems.
- Expertise in cookie compliance, tracking technologies, and consent management.
- Excellent communication and stakeholder‑management skills; ability to translate legal requirements into actionable business practices.
- Leadership experience and a proactive, “privacy first” mindset.
- Knowledge of AI technologies and associated privacy implications.
Required Education & Certifications
- Bachelor’s degree in Law, Information Security, Computer Science, or related field (or equivalent practical experience).
- Professional privacy certifications preferred: CIPP/E, CIPM, CIPT, BCS DPO, or equivalent.
- Experience with cloud platforms (AWS, GCP, Azure) and modern data tooling is a plus.