- Company Name
- Rightmove
- Job Title
- Data Protection Officer
- Job Description
-
Job Title
Data Protection Officer
Role Summary
Lead and maintain the organization’s data‑protection compliance program, ensuring adherence to UK GDPR, Data Protection Act 2018, DUAA, PECR, and related regulations. Collaborate across legal, compliance, security, product, engineering, HR, and commercial functions to embed privacy‑by‑design principles and foster a culture of responsible data stewardship.
Expectations
- Serve as primary liaison with the Information Commissioner’s Office (ICO).
- Develop, implement, and update the data‑protection strategy, policies, and internal controls.
- Manage Records of Processing Activities (RoPA) and lead DPIAs, LIAs, and TRAs.
- Oversee data subject rights handling, including access, erasure, rectification, and objection requests.
- Provide privacy‑by‑design guidance, risk assessment, and vendor due diligence support.
- Deliver training and awareness initiatives to promote a “privacy first” mindset.
- Conduct audits, risk reviews, and compliance monitoring of internal and third‑party practices.
- Report on privacy risks, incidents, and program maturity to senior leadership.
- Stay informed on regulatory changes, AI Act implications, and evolving privacy technologies.
Key Responsibilities
- Regulatory compliance: maintain up‑to‑date RoPA; ensure UK GDPR, Data Protection Act 2018, DUAA, PECR compliance; respond to ICO queries and reporting.
- Data Protection Impact Assessments, Legitimate Interest Assessments, Transfer Risk Assessments.
- Data subject rights management: establish procedures for access, deletion, rectification, objection, and data portability.
- Governance & advisory: develop data‑protection policies; advise on privacy‑by‑design, data minimisation, storage limitation, consent, cookie compliance, and lawful bases.
- Security collaboration: support incident response, breach assessment, and ICO reporting.
- Vendor management: conduct due diligence, negotiate DPAs, and review DSAs.
- Training & culture: design and deliver privacy training; champion privacy awareness across the organization.
- Monitoring & risk: audit compliance, evaluate third‑party processor adherence, produce regular reports to leadership.
- Horizon scanning: track regulatory changes, AI developments, and emerging privacy technologies.
Required Skills
- Proven experience as a DPO, Privacy Manager, or equivalent in a UK organization, preferably in a tech‑driven or data‑rich environment.
- In‑depth knowledge of UK GDPR, DPA 2018, DUAA, PECR, ICO guidance, and best practices.
- Demonstrated expertise in DPIAs, risk assessments, audits, and compliance framework implementation.
- Understanding of technical security measures, SSDLC, data architecture, and modern data ecosystems.
- Knowledge of cookie compliance and tracking technologies.
- Strong communication skills – able to translate legal requirements into actionable business guidance.
- Leadership and stakeholder management abilities.
- Experience advising on AI technologies and data‑processing agreements.
Required Education & Certifications
- Bachelor’s degree in Law, Information Security, Data Governance, or related field (or equivalent experience).
- Professional privacy certification (e.g., CIPP/E, CIPM, CIPT, BSC DPO) – preferred but considered essential for a senior DPO role.