Overview
In this role, you will lead Howden UK Broking and UK Reinsurance’s Data Protection function, shaping a practical risk-based framework aligned with UK and EU data laws. You’ll work with senior leadership to drive strategy, governance, training, and by-design practices across the businesses. You will oversee regulatory interactions, reporting, and risk mitigation to protect personal data at scale. This is an opportunity to influence data protection at a fast-growing, employee-owned insurer with a strong culture and global reach.
Pay / Benefits
- flexible hours
- hybrid working
- volunteering and charity
- diversity and inclusion
- reasonable adjustments
- employee ownership
Responsibilities
- Develop and drive a data protection strategy aligned with UK Broking and UK Reinsurance operating models
- Create and maintain an annual Data Protection Plan and ensure regulatory alignment
- Establish and maintain a data protection risk and control framework, policies, and monitoring
- Implement horizon scanning to identify and act on new data protection legislation
- Produce updates and reports to governance committees on data protection risks and compliance
- Maintain data protection tooling and promote consistent use across the businesses
- Raise awareness and deliver training to employees on data protection topics
- Oversee interactions with the Information Commissioner’s Office and other authorities
- Ensure correct data protection registrations and licences across entities
- Embed data protection by design within business processes
- Develop and maintain strong relationships with senior leadership, information security, internal controls, and group data protection functions
- Provide risk-based advisory support on data protection matters across marketing, DPIAs, subject rights, notices, and data security
- Ensure DPIAs, ROPAs, data protection risk assessments, and KRIs/KCIs are developed and reported
- Prioritise high-risk processing activities and manage data subject rights requests
- Lead and develop the data protection team, with succession planning and staff development
- Deliver data protection training across employee levels and report to governance committees
Key requirements
- Experience building, implementing and managing enterprise data protection programmes
- Knowledge of UK GDPR, UK Data Protection Act 2018, PECR and related laws
- Experience with monitoring compliance and risk management frameworks
- Ability to manage multi-stakeholder projects and negotiations
- Strong communication skills across boards, IT staff, and external regulators
- Experience in reporting to senior governance committees
- Financial services experience preferred
- CIPP/E or Certified Data Protection Practitioner (PC.dp) preferred but not essential
- Experience in handling data subject rights requests
- Familiarity with data protection by design and data security controls
- Strategic leadership
- Cross-functional stakeholder management
- Effective communication
- Knowledge of GDPR, UK DPA, PECR
- DPIA methodology
- ROPA maintenance
…
