Privacy Programme Specialist
Listed on 2026-10-10
-
IT/Tech
Information Security & Data Protection, Data Analyst
REPORTING TO: VP, Technology UK&I and dotted line reporting to Head of Products, Partnerships & Innovation
LOCATION:
Heathrow
SHIFT PATTERN: 45 hours per week. Monday to Friday (Part-time: 3 days per week OR condensed working hours across 5 days.)
SALARY:
Competitive
ABM UK & Ireland is committed to maintaining high standards of data protection and privacy across its business. We are seeking an experienced Data Privacy Specialist to manage and continuously improve the UK & Ireland data privacy programme, ensuring that proportionate and effective controls are embedded across the organisation.
The role will support compliance with the UK GDPR and, for the Republic of Ireland, the EU GDPR, together with relevant internal policies and procedures. The Data Privacy Specialist will provide practical guidance to business stakeholders, maintain core privacy governance records, coordinate individual rights requests, oversee the management of data incidents, and ensure appropriate privacy training is delivered.
A key priority will be to align data privacy processes, controls, policies and working practices across acquired companies in Ireland, creating a consistent and efficient UK & Ireland approach while recognising applicable local requirements. This is a part-time role, offered either as three working days per week or through condensed working hours across five days.
Key Responsibilities Privacy Programme Governance- Manage the day-to-day UK & Ireland data privacy programme, ensuring activities are planned, tracked and completed in line with applicable data protection requirements and internal governance expectations
- Maintain an effective privacy governance framework, including clear ownership, records, controls, actions and reporting
- Provide regular updates on privacy activity, risks, incidents, requests and improvement priorities to relevant stakeholders
- Own and coordinate the ongoing maintenance of Records of Processing Activities (RoPAs), ensuring they are accurate, complete and kept up to date across the UK & Ireland business
- Work with business owners to validate processing purposes, categories of personal data, data subjects, recipients, retention periods, international transfers and security measures
- Identify gaps or inconsistencies in RoPAs and drive timely remediation with accountable business stakeholders
- Review and support Data Protection Impact Assessments (DPIAs) for new or changed systems, processes, suppliers and business initiatives involving personal data
- Provide practical challenge and guidance to ensure privacy risks are identified, assessed and appropriately mitigated before implementation
- Maintain an auditable record of DPIAs, actions, decisions and approvals
- Coordinate Data Subject Access Requests (DSARs) and other applicable individual rights requests in partnership with HR Business Partners and relevant business teams
- Ensure requests are logged, progressed, quality checked and completed within required timescales
- Provide guidance to stakeholders on evidence gathering, redaction, exemptions and appropriate response handling, escalating complex matters where required
- Record, assess and manage personal data incidents and suspected breaches from initial notification through investigation, containment, remediation and closure
- Coordinate input from relevant stakeholders to establish facts, assess risk to individuals and maintain complete incident records
- Ensure actions and lessons learned are captured and followed through, and elevate incidents promptly where regulatory assessment or senior review is required
- Arrange and coordinate annual HR data privacy training and any additional privacy training deemed necessary for specific teams, roles or business risks
- Maintain training records and support targeted awareness activity to reinforce privacy responsibilities and good data handling practices
- Review training content periodically to ensure it remains relevant, practical and aligned to the UK & Ireland privacy programme
- Review and update all policies, procedures, guidance and supporting documentation relating to GDPR and data privacy compliance
- Drive alignment of privacy processes and controls across acquired companies in Ireland, working with local stakeholders to establish…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).