Data Protection Officer - Contract
London - 3 days per week onsite
£550 per day - Inside IR35
3-month initial contract
Key responsibilities:
- Lead and oversee the organisation's Data Protection and Privacy framework
- Provide expert advice on GDPR, data protection legislation and Privacy by Design
- Advise senior leadership on their responsibilities as a Data Controller and/or Processor
- Monitor compliance with Data Protection and Data Retention policies, standards and procedures
- Manage and oversee data protection incidents, breaches, complaints, Subject Access Requests and Rights of Access requests
- Lead Data Protection Impact Assessments (DPIAs) for projects and privacy-sensitive activity
- Maintain and support Registers of Processing Activities (ROPA)
- Act as the key point of contact for Data Protection Authorities and regulatory matters
- Provide guidance on data protection risks and appropriate mitigation controls
- Conduct and oversee third-party data protection due diligence and support supplier contract negotiations
- Maintain and develop the Data Protection Framework in alignment with GDPR and ISO 27001
- Work closely with Information Security colleagues to ensure appropriate privacy controls are incorporated across systems, applications and infrastructure
- Monitor upcoming changes to privacy legislation and advise the business on their potential impact
- Provide regular reporting around Data Protection and Data Retention compliance
Requirements:
- Strong experience operating within a Data Protection Officer, Privacy or senior Data Protection position
- Ideally 5+ years' experience working across privacy and data protection
- Expert knowledge of UK GDPR, Data Protection legislation and Privacy by Design
- Strong experience managing DPIAs, ROPAs, SARs, data breaches and regulatory compliance
- BCS Data Protection, CIPP/E or equivalent professional qualification
- Strong knowledge of Information Security Management Systems and ISO 27001
- Experience developing and maintaining data protection policies, standards and governance frameworks
- Comfortable advising and influencing senior stakeholders and management teams
- Experience managing third-party supplier risk and data protection due diligence