This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Through the effective day-to-day management of the UK Data Protection team, and collaborative engagement with other regional DPOs and their teams (or DPO equivalents): Enable the UK Compliance function to manage data protection risk and regulatory compliance with applicable data privacy and data protection laws and regulation across the UK entities' global licensed footprint including through effective Horizon Scanning and Training. Ensure all UK entity, and any applicable global, controls for DP are fit for purpose and adhered to. Contribute to, and enable the embedding of, a global DP framework to include all relevant Data Protection/Privacy policies, notices, systems, processes and controls. Support the effective and consistent management of cross-border data protection activities in collaboration with the regional DPOs, including through the Group sub-committee for Data Protection. Contribute to the development and delivery of high-quality reporting including through the use of relevant KPIs and KRIs across all relevant formal committees and forums internally, either as stand-alone DP papers or as part of the broader UK Compliance agenda and reporting.
Job Responsibility
Ensure that the UK entities' legal and regulatory obligations for data privacy and protection across their licensed footprint are mapped to a comprehensive set of activities, processes and controls to enable compliance
Ensure that the global Horizon Scanning framework is embedded in the UK DP team's BAU with appropriate contributions to formal UK Compliance reporting including to the Change Committee
Manage the UK DP team, tracking and monitoring the effectiveness of delivery against key activities, in line with internal SLAs, to ensure regulatory compliance
Keep workloads and resource needs under close observation and proactively identify problems or inhibitors and escalate where appropriate for resolution
Identify development opportunities for direct reports and support the team pastorally
Engage closely with internal stakeholders in Infosec, IT and co-sourcing relationships in Claims to support the effective and efficient delivery of DSARs, e-discovery requests, and subpoenaed information as required
Oversee any externally outsourced DP provision for the UK entities in jurisdictions where they operate, working with regional DPOs as required where resources are shared
Where appropriate and within your expertise, provide advice and guidance on technical DP matters including DP contract clauses where the contract is governed by English law
Retain external advisors when needed to ensure appropriate levels of specialism are enlisted when required
Ensure UK DP-owned actions arising from all applicable audit, assurance and testing activities are completed on time
Maintain a Privacy Incident Reporting and Response process to address any Privacy incidents that might occur in the UK or impacting UK data
Proactively escalate data breaches to the Boards of the relevant UK entity through the applicable Chair of the Risk Committee
Lead on required notifications to the ICO where required and participate in any relevant incident response activity and lessons learned
Work closely with Heads of Compliance, regional DPOs and their teams, European branch regulatory counsel, as well as other internal stakeholders, to create a global DP strategy and operating model
In collaboration with regional DPOs as required, perform information privacy risk analysis on cross-border and UK initiatives
Assist the IT department as required in the development of all system-related security plans throughout the organisation's network
Undertake consent audits to validate consent is being obtained and retained as required under UK laws
In collaboration with regional DPOs undertake records retention audits to ensure the organisation is retaining data as required
Attend and contribute to formal committees, working groups and steering committees as required
Oversee the production of insightful and thorough reporting on matters pertaining to the UK entities and their global footprint as part of standalone DP engagement with committees or the broader Compliance papers
Requirements
Proven experience in Privacy and Data Protection
Previous DPO experience
Degree level educated
Excellent written and oral communications skills
The ability to prioritise work and deliver results in a pressurised environment, through tactical and strategic planning
The ability to manage significant client contact, providing expert advice which demonstrates judgement and an understanding of the business
A demonstrated ability to develop strong relationships with internal clients
The ability to provide support to more senior roles in developing key client relationships through the design of leading-edge technologies
Self-motivated, with an ability to work with high degree of autonomy and to be results-driven with a flexible approach to working
The ability to work collaboratively with a broad range of constituencies
A thorough understanding of UK Data Protection laws and regulations
An unblemished career history holding positions requiring trustworthiness and personal integrity
The ability to communicate technical and security-related concepts to a broad range of technical and non-technical staff and management
Nice to have
Knowledge of information systems
Experience in financial services is highly desirable, but not required
Experience in the insurance industry is desirable but not required
Multi-country experience (i.e., beyond UK, and ideally including APac) is highly desirable, but not required
Experience with model contractual clauses for international data transfers is highly desirable, but not required