Data Protection Officer
Role Title Data Protection Officer
Client Domain Insurance
Location London, UK
Duration 3-8 months to start with, extendable after
How many days in a week Work from Office. Flexible. 1-2 times/ month
Inside IR35
JD:
Role Summary
We are seeking an experienced Data Protection Officer (DPO) to lead our privacy and data protection program across the UK and Europe, while providing advisory support to the Asia-Pacific region (primarily Singapore).
The successful candidate will serve as the primary advisor on data privacy matters, ensuring compliance with GDPR, the EU AI Act, and other applicable privacy and AI regulations. The role will work closely with Legal, Information Security, Risk, Compliance, HR, Technology, and Business teams to embed privacy-by-design into business processes and technology initiatives.
Key Responsibilities
Data Protection Officer
• Act as the designated Data Protection Officer for UK and European operations.
• Serve as the primary point of contact for data protection matters.
• Liaise with regulators and supervisory authorities as required.
• Advise senior leadership on privacy risks and compliance obligations.
Privacy Governance
• Maintain and enhance the enterprise privacy framework.
• Develop and update privacy policies, standards, and procedures.
• Ensure privacy-by-design principles are embedded into projects.
• Oversee Records of Processing Activities (RoPA).
Regulatory Compliance
• Ensure compliance with:
o UK GDPR
o EU GDPR
o EU AI Act
o Other applicable privacy and AI regulations
• Monitor emerging regulatory developments and assess business impact.
Risk Management
• Lead Privacy Impact Assessments (DPIAs/PIAs).
• Assess privacy risks associated with new technologies and business initiatives.
• Review cross-border data transfer mechanisms.
• Support third-party privacy risk assessments.
Incident Management
• Advise on personal data breach investigations.
• Support regulatory notification requirements.
• Coordinate privacy-related incident response.
Stakeholder Engagement
• Partner with Legal, Security, Compliance, Internal Audit, and Technology teams.
• Deliver privacy awareness and training programs.
• Support internal and external audits.
Asia-Pacific Support
• Provide advisory support to regional privacy initiatives, primarily in Singapore.
• Collaborate with regional business and compliance teams to ensure alignment with enterprise privacy policies.
Required Skills
Mandatory
• Extensive experience in Data Privacy and Data Protection.
• Deep knowledge of UK GDPR and EU GDPR.
• Working knowledge of the EU AI Act.
• Experience serving as a Data Protection Officer or Deputy DPO.
• Strong understanding of privacy governance.
• Experience conducting DPIAs.
• Experience with cross-border data transfers.
• Ability to engage with executive stakeholders.
Preferred
• Insurance or Financial Services experience.
• Knowledge of privacy regulations in Singapore/APAC.
• Familiarity with privacy tooling such as:
o OneTrust (Primary tool in use)
o Microsoft Purview
o Veronis
o Proofpoint
Experience
• 12–18+ years of professional experience.
• 5+ years in Data Privacy or Data Protection leadership.
• Previous experience acting as a DPO is highly desirable.