About this role
Key responsibilities
This is an exciting opportunity within the General Counsel & Risk team as part of our global Data Privacy team.
The individual will work closely with the UK and Australia-based teams in the following primary areas of responsibility:
- Providing assurance to external stakeholders, including: Client information requests;
- Negotiating client and supplier agreements; and
- Supplier due diligence.
- Supporting the delivery of the privacy management framework, in particular: Conducting risk assessments and data protection impact assessments;
- Managing and maintaining privacy tools, documentation and registers;
- Supporting internal audit activities;
- Monitoring compliance with global privacy laws; and
- Assisting with framework certification activities.
- Assisting with data subject rights requests, such as data subject access requests.
- Supporting the delivery and management of privacy education and awareness.
- Providing privacy advice to the business.
- Ensuring privacy is built into the firm's data handling operations.
- Assisting with day-to-day operational privacy issues and personal data incidents.
- Building lasting and valuable relationships with internal stakeholders, especially Procurement, IT, HR and of course lawyers.
- Monitoring evolving privacy risks together with associated laws and regulation.
Please note this role is concerned with governance, risk and compliance elements of privacy; it is not a technical role albeit a strong appreciation of IT and information security concepts is undoubtedly required for this role to be successful.
Qualifications, skills and experience
- An innovative mindset, curious about AI and emerging technologies.
- Degree educated (technical degree or similar).
- We would expect the successful candidate to have around two years' experience in privacy but may consider those with less experience providing they can demonstrate they meet the required competencies.
- Strong knowledge of global data protection requirements and legislation, especially those applicable to the UK and EMEA.
- CIPP/E certification or similar preferable.
- Professional Services experience preferable.
- Ability to identify and analyse complex privacy risks and controls.
- Adaptable, diligent and works with initiative.
- Strong relationship builder - internal and external.
Competencies
- Personal leadership
- Collaborates with others
- Ownership and accountability
- Achieves Results