Data Protection Lead/Privacy Manager
2 days ago
Kidderminster
Responsible for managing the organisation’s data protection and privacy compliance in an SME environment with fewer than 250 employees operating across the UK EU and Switzerland. This role provides pragmatic, proportionate GDPR compliance. The focus is on practical risk management, operational compliance and acting as the internal point of contact for data protection matters. \n\n MAIN DUTIES AND RESPONSIBILITIES: \n\n Responsible for the following activities, including but not limited to: \n\n GDPR Compliance & Governance \n\n\n\t • Maintain proportionate GDPR policies, notices, and procedures suitable for an SME.\n\t, • Maintain Records of Processing Activities (RoPA) in line with Article 30 requirements applicable to SMEs.\n\t, • Support privacy-by-design principles in new projects and systems.\n\t, • Act as the primary contact for data subject rights requests (including DSARs).\n\t, • Coordinate responses across HR, IT, and business teams.\n\t, • Maintain a personal data breach register.\n\t, • Coordinate initial assessment and response to suspected data breaches.\n\t, • Conduct GDPR due diligence on key suppliers and processors.\n\t, • Ensure appropriate Article 28 processor agreements are in place.\n\t, • Maintain oversight of EU,UK and Swiss data transfers and reliance on UK adequacy.\n\t, • Deliver practical GDPR awareness training for staff.\n\t, • Monitor compliance with internal controls and policies.\n\t, • Practical working knowledge of UK GDPR and EU GDPR\n\t, • Knowledge of Swiss data protection law an advantage\n\t, • Experience managing DSARs, basic DPIAs, and data breach response Ability to apply GDPR proportionately in a commercial SME environment\n\t, • Strong organisational and stakeholder management skills\n\t, • Experience operating across UK and EU jurisdictions Familiarity with processor management and international data transfers Privacy, compliance, or risk management certification (or equivalent experience)\n\t, • Achieving Results\n\t, • Communication\n\t, • Self-Awareness\n\t, • Risk Management\n\t, • Data Subject Rights\n\t, • Influencer\n\t, • Permanent position\n\t, • Location: Hartlebury or remote\n\t, • Schedule: Mon to Fri 37.5 hours per week\n\t, • Salary: £40 - £45k per annum\n\t, • Benefits: EAP, Pension, Company gifts for Long Service/Wedding/Adoption, Cycle to Work Scheme, Free Parking\n\n\n