- Company Name
- Unite Students
- Job Title
- Data Protection Manager
- Job Description
-
**Job title:** Data Protection Manager
**Role Summary:**
Senior leader who designs, implements, and governs the organization’s data protection strategy. Oversees compliance with GDPR, the UK Data Protection Act 2018, and relevant overseas laws (e.g., PIPL). Cultivates a privacy‑first culture, guides the data protection team, and collaborates with business and technical stakeholders to embed privacy into systems and processes.
**Expectations:**
- Build credibility and trust across all levels, including senior management.
- Serve as a “critical friend,” providing objective privacy guidance.
- Deliver continuous improvement of the organization’s data protection maturity.
- Maintain up‑to‑date knowledge of evolving privacy regulations and best practices.
**Key Responsibilities:**
1. **Stakeholder Management** – Partner with internal teams and external partners to embed privacy in policies, processes, and technology.
2. **Data Protection Strategy** – Lead the development and execution of the data protection roadmap, aligning with Data Governance and InfoSec.
3. **Compliance Oversight** – Ensure adherence to GDPR, the Data Protection Act 2018, PIPL, and other applicable laws; manage risk exposure across jurisdictions.
4. **Policy & Notice Development** – Draft, update, and enforce privacy policies, procedures, and privacy notices that reflect legal and industry standards.
5. **Data Sharing Agreements** – Negotiate and maintain agreements that secure personal data when shared with third parties.
6. **DPIA Management** – Conduct or supervise Data Protection Impact Assessments for new projects, systems, or processing activities.
7. **Breach Management** – Optimize breach response plans, coordinate notifications to regulators and affected individuals, and conduct lessons‑learned reviews.
8. **Team Leadership** – Manage, mentor, and develop the data protection team; set priorities and allocate resources across initiatives.
**Required Skills:**
- Exceptional communication, presentation, and interpersonal skills to influence executive and cross‑functional stakeholders.
- Strong project‑management capability, able to oversee multiple privacy initiatives simultaneously.
- Proactive, self‑directed, with the ability to handle complex, competing demands.
- Analytical, risk‑assessment mindset and problem‑solving proficiency.
- Team orientation and collaborative leadership; experience managing and developing a team.
- Continuous learning orientation; stays current with privacy law evolution and industry practices.
**Required Education & Certifications:**
- CIPP/E and/or CIPM certification (or equivalent).
- Extensive experience in data protection (typically >5 years in a senior privacy role).
- In‑depth knowledge of UK GDPR, Data Protection Act 2018, and PIPL.
- Relevant university degree (e.g., Law, Computer Science, Information Security) is preferred but not mandatory if compensated by professional experience.