Overview
As Data Privacy Manager at Zopa, you lead the Data Privacy function within Operational Risk & Compliance, guiding strategic and day-to-day decisions on customer data. You partner with product, tech, legal, risk, security and commercial teams to evolve a compliant and pragmatic privacy capability, with potential to develop PCI DSS capabilities. You drive governance, incident management, and data subject rights while building a high-performing team that supports business growth.
Responsibilities
- Advise product and business teams on privacy implications of new products and journeys
- Translate UK privacy law into practical, business-friendly recommendations
- Develop and mature the data privacy governance framework (DPIAs, privacy by design, retention, ROPA, third-party diligence)
- Manage complex privacy incidents and regulatory notifications as needed
- Oversee DSARs, erasure requests and objections with quality and timeliness
- Foster trusted partnerships across technology, legal, risk, security and commercial functions
- Develop direct reports and raise privacy awareness across the business
- Contribute to the Bank’s approach to data risk across activities
- Help build PCI DSS capability within the function over time
Key requirements
- Deep practical knowledge of UK GDPR, Data Protection Act 2018 and related privacy regulation
- Ability to apply privacy law proportionately in a commercial environment
- Experience making risk-based decisions with commercial impact in mind
- Experience developing a data protection function in evolving privacy maturity
- Design and implement governance for DPIAs, privacy by design, retention, ROPA and third-party due diligence
- End-to-end data breach and privacy incident management, including ICO notification
- Handle data-subject rights requests with high quality and defensible decisions
- Build credibility with business, technology, legal, risk and security stakeholders
- Lead and develop high-performing privacy teams with continuous improvement
- Influencing senior stakeholders
- Strong communication
- Collaborative mindset
- UK GDPR and DPA 2018 expertise
- DPIA design and privacy by design
- Data retention and ROPA governance
…
