Group Data Compliance Manager

Company: PureGym
Apply for the Group Data Compliance Manager
Location: London
Job Description:

Overview

As Group Data Compliance Manager, you will lead PureGym’s global privacy and data protection strategy across markets, acting as the primary privacy advisor to the business. You will oversee compliance governance, regulatory engagements, and risk-based decisions to enable growth and innovation. You’ll drive a culture of responsible data use and ensure DPIAs, data mappings, and data subject rights are effectively managed. This role combines strategic leadership with hands-on governance, offering a meaningful chance to shape data protection practices at scale.

Pay / Benefits

  • Free nationwide gym membership for you + 1
  • Hybrid working
  • Private healthcare including digital GP
  • Life insurance x4
  • Company pension contribution
  • 25 days annual leave + 1 personal day

Responsibilities

  • Lead the Data Protection Officer function and governance
  • Oversee regulatory engagement and privacy compliance programme management
  • Coordinate Data Protection Impact Assessments (DPIAs)
  • Manage data subject rights handling and complaints processes
  • Govern cross-border data transfers and third-party data processor oversight
  • Lead incident and breach management activities
  • Maintain Group Policies and Standards for data protection
  • Drive training, awareness, and data protection culture
  • Maintain ROPA, retention schedules, and data mapping activities

Key requirements

  • Significant experience leading data protection/privacy programmes in a multi-jurisdictional environment
  • Demonstrable experience as Data Protection Officer or senior privacy professional
  • Expert knowledge of UK GDPR, EU GDPR, Swiss FADP, applicable US privacy laws, and international transfer requirements
  • Experience managing regulatory interactions and investigations
  • Strong understanding of privacy by design, DPIAs, and privacy risk assessments
  • Experience handling data subject rights requests and supplier privacy reviews
  • Knowledge of information governance and records management
  • Ability to balance regulatory compliance with commercial objectives
  • Strong stakeholder management, communication, and influencing skills
  • Ability to work independently and travel internationally when required
  • Stakeholder management
  • Influencing skills
  • Excellent communication and presentation
  • DPIAs and privacy risk assessments
  • Privacy by design principles
  • Data mapping and ROPA maintenance

…

Posted: October 10th, 2026