Interim Privacy Lawyer / Privacy Analyst
Interim Privacy Lawyer / Privacy Analyst
6 Month Contract, 2 days in office.
The Opportunity
MLA is partnering with a rapidly scaling UK fintech that is transforming the way businesses move and manage money. Operating at the intersection of payments, technology and financial services, the organisation has built a reputation for innovation, agility and customer-centric solutions, supporting thousands of businesses across the UK and Europe.
As the business continues to grow, the legal and privacy team is experiencing a significant increase in workload and is looking to appoint an interim Privacy professional to provide hands-on support across a broad range of data protection and privacy matters.
The team is open to both:
- Qualified lawyers (approximately 1-5 PQE) with privacy experience; and
- Experienced Privacy Analysts / Privacy Managers with strong operational GDPR expertise.
This is an excellent opportunity to join a collaborative and highly regarded legal function, working closely with stakeholders across product, compliance, security, risk and operations within a fast-paced regulated environment.
Key Responsibilities
Privacy Compliance & Governance
- Draft, review and maintain DPIAs, LIAs and other privacy risk assessments.
- Support the ongoing development and maintenance of GDPR and UK GDPR compliance frameworks.
- Assist with Records of Processing Activities (ROPA) and wider privacy governance processes.
- Help maintain privacy policies, procedures, templates and documentation.
- Monitor privacy compliance obligations and support business-wide privacy initiatives.
Privacy Operations
- Conduct privacy reviews of new products, services and internal projects.
- Support privacy-by-design initiatives, working closely with Product, Technology, Security and Compliance teams.
- Review data flows and identify privacy risks and mitigation measures.
- Assist with vendor privacy reviews and third-party due diligence exercises.
- Support DSAR processes and wider data subject rights obligations where required.
Incident & Risk Management
- Assist with the investigation and documentation of personal data incidents.
- Maintain incident records and support regulatory reporting assessments.
- Coordinate information gathering across business functions during privacy-related investigations.
- Escalate higher-risk issues to senior legal and compliance stakeholders as appropriate.
Regulatory & Stakeholder Support
- Provide practical privacy guidance to internal stakeholders.
- Support responses to regulatory enquiries and audits.
- Help deliver privacy awareness initiatives and training across the business.
- Work closely with Legal, Risk, Compliance and Information Security teams on data protection matters.
About You
We are interested in speaking with candidates from either a legal or privacy operations background who can demonstrate:
- Experience working with GDPR and UK GDPR in a commercial, technology, fintech, financial services or regulated environment.
- Strong practical experience preparing and reviewing DPIAs, LIAs and privacy assessments.
- Experience maintaining privacy governance frameworks and compliance documentation.
- An understanding of privacy-by-design principles and operational privacy processes.
- Excellent stakeholder management and communication skills.
- Strong organisational skills with the ability to manage multiple workstreams simultaneously.
- A pragmatic and solutions-oriented approach to privacy risk management.
Additional Experience That Would Be Beneficial
- 1-5 PQE privacy, commercial technology or regulatory lawyer.
- Experience within fintech, payments, banking or other regulated sectors.
- IAPP qualification (CIPP/E, CIPM or equivalent).
- Experience supporting vendor contracting, data processing agreements or international data transfer arrangements.
- Experience working in a fast-growth technology business.
If this role is of interest please apply for additional information.