Data Protection Officer
Location: Manchester (hybrid), with a global remit Type: Full time, permanent Department: Information Security / Data Protection Governance Reports to: Head of Information Security
About the business
Our client is a global foreign exchange and payments group with operations across the UK, EU, Canada, the US and Singapore. The business is FCA-authorised and handles personal data across multiple entities and jurisdictions. This is a newly-scoped, standalone DPO role owning the group's data protection governance framework end to end.
The role
As Data Protection Officer you will provide independent, expert data protection oversight and practical guidance across the group's international operations. Based in Manchester with a global remit spanning the UK, EU, Canada, the US and Singapore, you will be capable of being formally notified or registered as the DPO with relevant supervisory authorities, including the Spanish AEPD where required.
You will own and mature the data protection governance framework: DPIAs, Records of Processing Activities, data subject rights, breach governance, policies, training, regulatory liaison and risk-based assurance.
Key responsibilities
- Act as the appointed Data Protection Officer for the relevant group entities, maintaining independence, professional judgement and direct access to senior management where required.
- Provide expert advice on UK GDPR, EU GDPR, the UK Data Protection Act 2018, PECR, Spanish LOPDGDD, Dutch privacy requirements, Canadian privacy requirements (including PIPEDA and Quebec Law 25), applicable US privacy requirements and Singapore PDPA obligations.
- Be eligible and willing to be notified or registered with supervisory authority registers, including the ICO and Spanish AEPD, and support equivalent DPO or contact-point requirements in other jurisdictions.
- Own and improve the global data protection governance framework: policies, standards, procedures, registers, templates, guidance notes and evidence packs.
- Lead, review and advise on DPIAs, Privacy Impact Assessments, Legitimate Interest Assessments and Transfer Risk Assessments for new suppliers, systems, products, AI use cases, projects and material changes to processing.
- Create, maintain and periodically review Records of Processing Activities, data inventories, data-flow maps, lawful basis records, retention references and records of international data transfers.
- Support privacy by design and default by engaging early with technology, product, change, procurement and operational initiatives.
- Advise on and oversee global personal data breach governance, including risk assessment, regulatory notification, data subject communications, evidence retention and lessons learned.
- Maintain and improve data subject rights procedures (access, erasure, rectification, restriction, portability, objection, consent withdrawal and rights related to automated decision-making and profiling), coordinating responses across jurisdictions.
- Review and advise on supplier data protection due diligence, Data Processing Agreements, controller/processor assessments, subprocessor governance, international transfer mechanisms and contract clauses, working with Legal, Procurement and Information Security.
- Monitor internal compliance through risk-based reviews, audits, control testing, issue tracking and management reporting.
- Design and deliver staff awareness, role-based training and targeted guidance for teams handling personal data.
- Act as a point of contact for data subjects and supervisory authorities, coordinating with Legal, Compliance and regional specialists where local nuance or external counsel is required.
- Maintain a data protection risk register, track remediation and provide clear, risk-based reporting to senior management and governance forums.
- Keep up to date with changes in privacy law, regulator guidance, enforcement trends and industry practice, translating them into practical actions.
Autonomy
- Works independently and exercises professional judgement in line with DPO independence requirements.
- Escalates material data protection risks, regulatory matters and unresolved conflicts to senior management as appropriate.
- Contributes proactively to departmental plans, priorities, control improvements and governance reporting.
What we are looking for
- Significant hands-on experience in data protection, privacy governance, regulatory compliance or information governance in a regulated or complex international environment.
- Deep working knowledge of UK GDPR and EU GDPR, including Articles 30, 35, 37, 38 and 39, and practical experience applying them in business operations.
- Strong practical experience completing DPIAs, ROPAs, LIAs, DSRs, privacy notices, breach assessments, transfer assessments and supplier reviews.
- Proven ability to draft, review and implement data protection policies, procedures, training and governance reporting at a global level.
- Good understanding of information security, third-party risk management, data classification, retention, access management, incident management and privacy-by-design.
- Ability to translate legal and regulatory requirements into clear operational controls and pragmatic, business-friendly guidance.
Skills and attributes
- Leads by example, demonstrating integrity, discretion, professional independence and sound judgement.
- Able to influence senior stakeholders and constructively challenge decisions where data protection risk is not adequately addressed.
- Credible working across different cultures, jurisdictions and business functions in a complex global organisation.
- Able to prioritise competing demands, manage sensitive matters confidentially and maintain clear decision-making records.
- Strong communication, presentation, training and stakeholder-management skills.
Systems
- Microsoft Office, SharePoint, Teams and Outlook.
- Experience with privacy management, GRC, ticketing, workflow, risk or control-management tools is desirable.
- Comfortable working with data inventories, ROPA tools, registers and reporting dashboards.
Qualifications and experience
- Degree or equivalent experience in law, compliance, information security, risk management, data governance, technology, business or a related discipline.
- Minimum 8 to 10 years' relevant experience in data protection, privacy, compliance, information governance or related regulatory roles, with demonstrable international exposure.
- CIPP/E, CIPM, CIPT, EU GDPR Practitioner, ISEB/BCS Data Protection, AEPD DPO certification or equivalent.
- Experience in financial services, payments, FX, regulated technology or another regulated sector is highly desirable.
- Commitment to continuing professional development and maintaining expert knowledge of data protection law and practice.
Languages
- A high standard of written and spoken English is essential.
- Fluency in another European language (Spanish, Dutch, French and similar) is desirable.
Conduct
This is a Code of Conduct role under the Senior Managers and Certification Regime. The successful candidate will be expected to act in line with the firm's code of conduct and related policies, and to maintain the independence required of the DPO role.