Data Protection Manager - 2nd line oversight
- Location
- Swindon, ENG, GB
- Salary
- £65,000 to £80,000
- Employment type
- Full time
- Experience level
- Mid level
- Posted
What you’ll be doing
You'll provide independent oversight and challenge across a broad range of Data Protection risks and processing activities. You'll review high-risk impact assessments and assess whether Data Protection risks are being identified, managed and mitigated appropriately, providing constructive challenge where weaknesses, non-compliance or opportunities for improvement are identified.
You'll undertake thematic oversight and assurance reviews, assess the effectiveness of Data Protection controls and frameworks, and form clear, evidence-based opinions on complex Data Protection matters. You'll also monitor incidents, regulatory developments and wider risk information to identify emerging themes and areas requiring further oversight.
Working with stakeholders across the organisation, you'll produce concise reports and opinions for senior leaders and governance committees, helping to support effective decision making and risk management. You'll also contribute to incident oversight activities and the ongoing development of Nationwide's Data Protection oversight framework.
About you
This role requires an experienced Data Protection professional with current and demonstrable subject matter expertise.
As a minimum, you’ll have:
Strong, up-to-date knowledge of UK GDPR, the Data Protection Act 2018, PECR and relevant regulatory expectations
Broad practical experience across a range of Data Protection areas, including experience beyond the operation of individual Data Protection processes
Experience providing independent oversight, challenge, assurance or compliance monitoring within a second-line, DPO, risk or regulatory environment
Experience of independently overseeing and challenging the effectiveness of Data Protection processes, frameworks and controls
Experience assessing complex or high-risk processing activities and forming clear, reasoned conclusions on residual risk
Experience assessing Data Protection frameworks and controls, identifying weaknesses and producing evidence-based opinions
Experience engaging with and constructively challenging senior stakeholders, including where further action or escalation was required
Strong written and verbal communication skills, including experience producing concise reports and governance updates for senior audiences
Experience managing work independently and prioritising activity according to risk and business impact
Experience working within financial services or another highly regulated environment
A recognised Data Protection qualification (for example, CIPP/E, CIPM or equivalent) or equivalent demonstrable professional Data Protection expertise
Our customer first behaviours put customers and members at the heart of how we work together. They are the set of behaviours that every colleague needs to display, in every role:
Feel what customers feel - We step into our customers’ shoes, using their feedback and insights to empathise with them and to understand their needs, so that every decision we make starts and finishes with our customers in mind
Say it straight - We are brave in speaking out and saying what we think – we’re honest and direct with good intent, openly sharing diverse perspectives to reach the best conclusions and using language everyone can understand
Push for better - We don’t settle for mediocrity, we challenge the status quo, taking responsibility for continuous improvement and personal development
Get it done - We prioritise what will have the greatest impact, we are decisive, and we take accountability for delivering brilliant customer outcomes
You can strengthen your application by showing how our customer first behaviours resonate with you, and where you may have already demonstrated these.