Howden UK Broking Head of Data Protection

Company: Howden Group Holdings
Apply for the Howden UK Broking Head of Data Protection
Location: London
Job Description:

Overview

In this role, you will lead Howden UK Broking and UK Reinsurance’s Data Protection function, shaping a practical risk-based framework aligned with UK and EU data laws. You’ll work with senior leadership to drive strategy, governance, training, and by-design practices across the businesses. You will oversee regulatory interactions, reporting, and risk mitigation to protect personal data at scale. This is an opportunity to influence data protection at a fast-growing, employee-owned insurer with a strong culture and global reach.

Pay / Benefits

  • flexible hours
  • hybrid working
  • volunteering and charity
  • diversity and inclusion
  • reasonable adjustments
  • employee ownership

Responsibilities

  • Develop and drive a data protection strategy aligned with UK Broking and UK Reinsurance operating models
  • Create and maintain an annual Data Protection Plan and ensure regulatory alignment
  • Establish and maintain a data protection risk and control framework, policies, and monitoring
  • Implement horizon scanning to identify and act on new data protection legislation
  • Produce updates and reports to governance committees on data protection risks and compliance
  • Maintain data protection tooling and promote consistent use across the businesses
  • Raise awareness and deliver training to employees on data protection topics
  • Oversee interactions with the Information Commissioner’s Office and other authorities
  • Ensure correct data protection registrations and licences across entities
  • Embed data protection by design within business processes
  • Develop and maintain strong relationships with senior leadership, information security, internal controls, and group data protection functions
  • Provide risk-based advisory support on data protection matters across marketing, DPIAs, subject rights, notices, and data security
  • Ensure DPIAs, ROPAs, data protection risk assessments, and KRIs/KCIs are developed and reported
  • Prioritise high-risk processing activities and manage data subject rights requests
  • Lead and develop the data protection team, with succession planning and staff development
  • Deliver data protection training across employee levels and report to governance committees

Key requirements

  • Experience building, implementing and managing enterprise data protection programmes
  • Knowledge of UK GDPR, UK Data Protection Act 2018, PECR and related laws
  • Experience with monitoring compliance and risk management frameworks
  • Ability to manage multi-stakeholder projects and negotiations
  • Strong communication skills across boards, IT staff, and external regulators
  • Experience in reporting to senior governance committees
  • Financial services experience preferred
  • CIPP/E or Certified Data Protection Practitioner (PC.dp) preferred but not essential
  • Experience in handling data subject rights requests
  • Familiarity with data protection by design and data security controls
  • Strategic leadership
  • Cross-functional stakeholder management
  • Effective communication
  • Knowledge of GDPR, UK DPA, PECR
  • DPIA methodology
  • ROPA maintenance

…

Posted: October 10th, 2026