Data Protection Manager
- Location
- Derby, England, United Kingdom
- Working arrangement
- Hybrid
- Salary
- £48,135 to £55,008
- Employment type
- Full time
- Experience level
- Mid level
- Posted
Data Protection Manager, Derby - Head Office, Permanent
Salary: £48,135 – £55,008
Closing Date: 7th October 2026 Reference: 0469-26
We have an exciting opportunity to join #TeamEMR as a Data Protection Manager.
This pivotal role leads and manages EMR’s privacy framework to ensure full compliance with the UK GDPR, the Data Protection Act 2018, and related legislation. Providing expert, pragmatic advice and, embedding privacy by design across all business processes, and promote a strong internal culture of accountability and compliance.
Key Roles and Responsibilities
Data Protection Strategy & Governance - Own the organisation's data protection and privacy framework, ensuring compliance with UK GDPR, the Data Protection Act 2018, PECR and related legislation, and that policies, procedures and standards remain current and effective.
Advisory & Decision Support - Act as the organisation's principal source of data protection expertise, advising senior leadership and project teams on complex privacy matters, challenging proposals where risks or non-compliance arise, and embedding privacy by design across change initiatives and DPIAs.
Individual Rights & Breach Management - Own the end-to-end handling of data subject rights requests and personal data breaches, ensuring both are managed lawfully, efficiently and within statutory timescales, with regulatory notification where required.
Information Governance & Third-Party Assurance - Maintain oversight of the organisation's records of processing activities, and ensure data protection provisions are properly reflected in contracts, data processing and data sharing agreements with suppliers and partners.
Assurance, Risk & Retention - Provide ongoing assurance that data protection risks are identified, assessed and mitigated, that compliance actions are implemented, and that a robust retention and disposal framework keeps personal data held only as long as necessary and disposed of securely.
Culture, Capability & Awareness - Build organisational capability and awareness through training and campaigns, ensuring managers and stakeholders understand their responsibilities and a culture of privacy and accountability is embedded.
Regulatory Horizon Scanning - Monitor developments in data protection law, regulatory guidance and best practice, translating these into practical recommendations for the organisation.
Reporting & Governance Assurance - Produce accurate, timely reporting and management information for senior leadership, governance committees and the Board, providing assurance on compliance performance and the effectiveness of the data protection framework.
Stakeholder & Group Relationships - Build effective relationships with internal stakeholders, regulators and the Group Data Protection Officer, ensuring alignment with group-wide privacy strategy and consistent application of standards, and acting as or supporting the DPO role where required.
About You
We’re looking for a confident and capable individual who brings:
- Certified Information Privacy Professional/Europe (CIPP/E) or a BCS Practitioner certificate
- knowledge of UK GDPR, Data Protection Act 2018, PECR, ICO guidance, and information security principles. Desirable certification in Data Protection
- understanding of privacy by design, information lifecycle management, data sharing, and supplier governance.
- experience managing DPIAs, Data Subject Rights Requests, personal data breaches, and privacy risk assessments.
- experience reviewing commercial contracts, Data Processing Agreements (DPAs), and Data Sharing Agreements.
- Experience producing Board-level reports and performance metrics to provide compliance assurance to senior leadership.
- Ability to interpret complex legislation and translate it into strategic, risk-based, and proportionate business solutions.
- Excellent communication (written and verbal), negotiation, and influencing skills to challenge and advise confidently at all organisational levels and committees within a diverse workforce.
- Experience of leading a GDPR governance programme (continuous improvement against minimum standards)
As well as a competitive salary, we’ll also offer you:
- 32 days annual leave (including bank holidays), rising to 34 days after 2 years of service
- Free travel on East Midlands Railway and other train companies operated by Transport UK
- 75% discount on other national rail train companies, including for partners and dependants
- Discounted friends and family tickets on the EMR network
- Various personal development and progression opportunities
- Excellent pension scheme
This position is based in our Derby Head office, but we've adopted a flexible hybrid working model that creates the opportunity to work in your own way at home but also provides great spaces for in-person collaboration.
We are open minded to applications from people who wish to have flexible working. Many of our staff work flexibly in many ways. Please talk to us at interview about the flexibility you need. We can’t promise to give you exactly what you want, but we do promise not to judge you for asking.
Ready to take on this exciting opportunity? Submit your online application form and upload your CV. As we operate a blind screening process, please remove all personal information including your name from your CV.
Supporting Our Frontline
If you're successful in this role, you'll be expected to support our frontline colleagues at some points throughout the year. This might be undertaking safety critical work, for which you'll receive training, but it could just be helping out with Customer Service when our stations are busy. We're One Team, and that means our managers step up for the frontline, not just manage from a distance. Supporting frontline colleagues is part of our DNA at EMR.