Data Protection Lead - CIPP/E, CIPM, CIPT, UK GDPR practitioner
Job Description
Location: London, Bristol or Manchester (Hybrid - typically 1 day per week onsite)Contract: 6 MonthsIR35: £650 daily Inside IR35Clearance: BPSS
The Opportunity\nWe are seeking an experienced Data Protection Lead to join a high-profile digital delivery environment, supporting the development of innovative digital products and services.
\nThis is a hands-on role for a privacy professional who enjoys working closely with product, technology, analytics and delivery teams to ensure privacy requirements are embedded from the outset. You will play a key role in delivering practical data protection solutions, conducting risk assessments, and enabling teams to deliver at pace while maintaining compliance.
\nThis is not a strategic leadership or people management position. We're looking for a practitioner who is comfortable getting into the detail of complex digital services, privacy risks and DPIAs.
Key Responsibilities\n- \n
- Lead and deliver Data Protection Impact Assessments (DPIAs) for new and existing digital services. \n
- Provide expert advice on UK GDPR, Data Protection Act requirements and privacy best practices. \n
- Embed Privacy by Design principles throughout the product and delivery lifecycle. \n
- Support the creation and maintenance of:\n
- \n
- Privacy Notices \n
- Records of Processing Activities (ROPAs) \n
- Data-sharing documentation \n
- Risk assessments \n
\n - Work closely with product managers, delivery teams, engineers and stakeholders to identify and mitigate privacy risks. \n
- Analyse digital products, data flows and technical architectures to assess compliance implications. \n
- Provide pragmatic, risk-based guidance that enables delivery while maintaining regulatory compliance. \n
- Support governance activities relating to emerging technologies and AI-enabled solutions. \n
- \n
- Minimum 3 years' experience in a Data Protection, Privacy or Information Governance role. \n
- Strong experience conducting and reviewing DPIAs. \n
- Proven expertise in UK GDPR and Data Protection legislation. \n
- Experience embedding Privacy by Design within digital products or services. \n
- Strong risk assessment and problem-solving capabilities. \n
- Experience working with technical stakeholders, digital teams and delivery environments. \n
- Excellent communication and stakeholder engagement skills. \n
- Ability to work collaboratively within multidisciplinary teams. \n
- \n
- Experience working within digital delivery organisations. \n
- Knowledge of PECR, cookies and tracking technologies. \n
- Exposure to analytics platforms and privacy considerations surrounding digital analytics. \n
- Experience supporting AI governance or AI-related risk assessments. \n
- Public sector or government experience. \n
- Experience working within Agile delivery environments. \n
One or more of the following would be highly desirable:
\n- \n
- CIPP/E \n
- CIPM \n
- CIPT \n
- Data Protection Practitioner Certificate \n
- UK GDPR Practitioner Certificate \n
- Equivalent privacy or data protection qualification \n
Equivalent practical experience will also be considered.
Personal Attributes\nWe are particularly interested in individuals who are:
\n- \n
- Personable and collaborative \n
- Pragmatic in their approach to compliance and risk \n
- Detail-oriented and analytical \n
- Comfortable working in fast-paced environments \n
- Able to build strong relationships across technical and non-technical teams \n
- Focused on delivery and outcomes rather than high-level strategy \n
