Overview
As Global Head of Privacy, you lead Ascot Group’s privacy strategy across multiple jurisdictions, ensuring compliance with GDPR, PIPA, CCPA/CPRA, HIPAA, and other data protection laws. You will shape policies, training, and governance to protect client and stakeholder data while enabling business growth. You’ll partner with Compliance, Legal, Cybersecurity, and business functions to manage regulatory risk and respond to data incidents. This role offers the chance to define enterprise privacy standards in a cross-border, cross-platform organization. You’ll be at the core of data protection leadership, driving trust and responsible data practices across Ascot’s global operations.
Responsibilities
- Develop and lead the global privacy strategy across multiple jurisdictions
- Draft, maintain, and roll out data protection policies and training programs
- Provide regulatory guidance to senior stakeholders on privacy matters
- Lead responses to data protection issues and breaches with cross-functional teams
- Oversee DPIAs and remediation activities
- Manage data privacy in vendor/third-party relationships and DSAR processes
- Oversee cross-border data transfer mechanisms and lawful transfer assessments
- Advise on data protection requirements specific to (re)insurance and market data standards
- Promote data protection awareness through training and education
- Monitor evolving privacy laws across applicable jurisdictions
- Coordinate with regulators and manage inquiries and examinations
- Collaborate with regional Compliance leads and Group GC on privacy matters
- Support enterprise risk assessments, M&A due diligence, and board reporting
Key requirements
- Degree (BA, MA, LLB, or equivalent) required
- Experience advising on UK GDPR, EU GDPR, multi-jurisdictional regimes
- Minimum 10 years in (re)insurance, financial services, law firm, or in-house
- CIPP/E, CIPM, CIPP/US, CIPT or equivalent preferred
- Excellent communication, organizational and time-management skills
- Proven track record of execution and delivering results
- Experience with AI governance and deploying AI/ML in regulated environments preferred
- communication excellence
- organizational and time-management skills
- commercial awareness
- GDPR knowledge (UK/EU)
- DPIA and DSAR management
- Data transfer mechanisms (SCCs, UK IDTA)
…
