More jobs:
Data Protection Officer & Compliance Manager
Job in
Luton, Bedfordshire, EX14, England, UK
Listed on 2026-07-20
Listing for:
Carlisle Support Services
Full Time
position Listed on 2026-07-20
Job specializations:
-
Business
Regulatory Compliance Specialist
Job Description & How to Apply Below
** The benefits
** Health and Wellbeing Plans
23 days paid holiday increasing to 25 after 2 years
Discounts and Cashbacks Paid Volunteering days Employee Assistance Program Refer a Friend Scheme Cycle to Work Scheme Bonus
** The role
** Carlisle Support Services is looking for a Data Protection Officer & Compliance Manager who will be responsible for leading the organisation's data protection, privacy, and compliance framework, ensuring compliance with UK GDPR, the Data Protection Act 2018, and other relevant regulatory obligations. Acting as the designated Data Protection Officer (DPO), the role provides expert advice and guidance across the business, drives a culture of compliance, manages data subject rights requests, and ensures robust governance processes are maintained.
** Your core role will include but not be limited to the following activities:
*** Act as the formally appointed Data Protection Officer for Carlisle Support Services, ensuring all statutory responsibilities under UK GDPR and the Data Protection Act 2018 are effectively discharged.
* Serve as the primary point of contact for the Information Commissioner's Office (ICO) and other regulatory bodies on all privacy and data protection matters.
* Provide independent and expert advice to the Executive Team, senior management, and operational stakeholders on data protection obligations, privacy risks, and compliance requirements.
* Promote and embed a culture of data privacy, accountability, and responsible data handling throughout the organisation.
* Maintain oversight of the organisation's privacy governance framework and ensure data protection considerations are incorporated into strategic business decisions.
* Develop, implement, review, and maintain GDPR policies, standards, procedures, and guidance documents.
* Monitor legislative developments and regulatory guidance, assessing organisational impacts and implementing required changes.
* Maintain the Record of Processing Activities (ROPA).
* Lead and coordinate Data Protection Impact Assessments (DPIAs).
* Take full ownership and accountability for all Subject Access Requests and data subject rights requests.
* Manage SARs internally wherever possible and within statutory timescales.
* Provide guidance to managers responding to privacy-related enquiries.
* Identify opportunities to streamline SAR processes and reduce external support costs.
* Monitor compliance and adherence to GDPR requirements across the business.
* Identify areas of non-compliance and support corrective actions.
* Produce an annual GDPR and Data Protection Report outlining risks, incidents, trends and areas of concern.
* Develop and present an annual Data Protection Strategy and Improvement Plan for the following 12 months.
* Report compliance performance and emerging risks to senior leadership.
* Lead investigations into data protection incidents, complaints, breaches and near misses.
* Assess incidents against regulatory reporting thresholds.
* Coordinate root cause analysis and corrective actions.
* Maintain the Data Breach Register.
* Review privacy risks and implement proportionate controls.
* Develop and deliver GDPR and data protection training programmes.
* Create awareness campaigns, guidance notes and supporting materials.
* Provide practical advice to operational teams.
* Build effective relationships with internal stakeholders, clients, suppliers, auditors and regulators.
* Support tenders, audits, questionnaires and due diligence activities.
* Partner with HR, IT, Operations, Commercial, Finance and Procurement teams.
* Provide subject matter expertise on data protection and compliance matters.
* Identify opportunities to improve compliance controls and governance processes.
* Benchmark practices against industry standards and best practice.
** The ideal candidate
** Essential* Significant experience in Data Protection, Compliance, Risk or Governance.
* Strong knowledge of UK GDPR and Data Protection legislation.
* Experience acting as a DPO or leading data protection programmes.
* Proven experience managing Subject Access Requests.
* Excellent…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×