127 Privacy jobs in the United Kingdom
Privacy Specialist, Corporate Counsel
Posted 1 day ago
Job Viewed
Job Description
Standard (Mon-Fri)
**Environmental Conditions**
Office
**Job Description**
This role can be based in a remote location attached to any one of the following Strategic Legal Hubs: US (Morrisville, North Carolina; Pittsburgh, Pennsylvania; Hillsboro, Oregon); UK (Glasgow); Italy (Milan) or Bulgaria (Sofia).
When you are part of Thermo Fisher Scientific, you'll do exciting work and join a team that values performance, quality and innovation. As part of a successful, growing global organization you will be encouraged to perform at your best. With revenues of more than $40 billion and the largest investment in R&D in the industry, we give our people the resources and chances to create significant contributions to the world.
We help our customers accelerate life sciences research, solve sophisticated analytical challenges, improve patient diagnostics, deliver medicines to market and increase laboratory productivity!
To enable us to better support Thermo Fisher Scientific's growth strategy, we have invested in the creation of six Strategic Legal Hubs across the globe, where we are growing highly skilled, multi-disciplinary legal teams who are co-located to support multiple businesses and corporate functions. You'll be part of a dynamic environment with increased opportunity to collaborate with legal colleagues and grow your skills through exposure to the varied legal issues that the Thermo Fisher businesses face.
**What You Will Do:**
Thermo Fisher is seeking a motivated privacy professional to join the Global Privacy and Technology Office as a **Privacy Specialist, Corporate Counsel** . This position offers a unique opportunity to advise on privacy matters and support business activities across a leading multinational company. The ideal candidate will have foundational experience in global privacy laws and demonstrate the ability to provide pragmatic, thoughtful counsel in a fast-paced environment.
This is an ideal role for someone who is eager to learn, passionate about data protection, and wants to join a collaborative, global legal team that values creativity, critical thinking, and practical solutions.
**How You Will Make an Impact:**
In this role, you will support the organization's compliance with global privacy and data protection laws and help operationalize privacy across the business. You will work on a broad set of privacy topics, with a focus on delivering clear, actionable guidance to team members. Specific responsibilities include:
+ Provide legal support for the drafting, review, and negotiation of data protection terms in client, vendor, clinical trial, and data protection agreements, including the use of standard contractual clauses.
+ Support the maintenance and improvement of data protection agreement templates and negotiation playbooks.
+ Deliver foundational privacy guidance on global data protection laws, regulations, and standards to business partners across the enterprise.
+ Handle and respond to data subject rights requests (e.g., subject access requests) throughout their lifecycle.
+ Track and support privacy-related business requests through the TrustArc privacy management platform.
+ Engage proactively in team-based initiatives and cross-functional projects within the Global Privacy and Technology Office.
+ Assist with delivering privacy training and awareness initiatives across the organization.
+ Communicate directly with clients and vendors during contract negotiations.
+ Stay current on emerging global privacy developments and advise on implications for the business.
**Keys to Success:**
**Education and Knowledge**
+ Juris Doctor (JD) or equivalent international legal degree.
+ Current license to practice law in at least one jurisdiction.
+ Certifications such as IAPP (CIPP/E, CIPP/US, CIPM) desirable.
+ Fluency in business English required; proficiency in additional languages is an asset.
**Experience and Skills**
+ 3+ years of professional experience, including a focus on privacy, data protection, or related legal practice.
+ Familiarity with global privacy laws and frameworks (e.g., GDPR, CCPA/CPRA).
+ Experience negotiating data protection agreements or contract terms with data protection implications.
+ Comfortable handling data subject requests and using privacy tools like OneTrust or TrustArc.
+ Ability to handle multiple projects simultaneously.
+ Excellent communication skills; capable of explaining legal concepts to non-lawyers.
+ Diligent, well-organized, and adaptable in a fast-paced and evolving environment.
+ Strong collaboration skills and a proactive approach to problem-solving.
Thermo Fisher Scientific is an EEO/Affirmative Action Employer and does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability or any other legally protected status.
Global Privacy and Data Protection Specialist
Posted 53 days ago
Job Viewed
Job Description
Dentons is designed to be different. We are driven to always be the firm of the future, to challenge the status quo, and to provide holistic business solutions to our clients in new and innovative ways. We are the lightbulb moments. The bold ideas. We are the world's largest global law firm, with 12,000+ people across 80+ countries. Driven by the diverse perspectives of our people, our clients, and our communities, we combine local knowledge with global insight.
We are looking for a Global Privacy and Data Protection Specialist to join our global privacy team. This role reports to the Global Senior Data Protection Specialist and is ideal for a professional with hands-on experience in privacy operations, stakeholder support and emerging technologies. While the role involves a high degree of autonomy, it operates under the guidance of senior privacy leadership to ensure alignment with global strategy and escalation of complex matters as needed. The successful candidate will support a broad range of global compliance activities across all regions, collaborating with cross-functional teams to embed privacy-by-design into projects, manage data subject rights and incidents, and optimize the use of privacy tools like OneTrust.
Key Responsibilities
Privacy Operations & Governance
- Support the evolution of the global privacy program, including all relevant monitoring activities, in alignment with GDPR and other international data protection frameworks.
- Conduct and advise on DPIAs, vendor risk assessments, and manage Records of Processing Activities (RoPAs).
- Draft, review, maintain and harmonise privacy documentation, including internal procedures, notices, guidance, and training materials.
- Maintain and oversee the privacy risk register, coordinating with stakeholders the implementation of mitigation plans.
Privacy Advisory & Business Support
- Respond to day-to-day privacy queries and provide practical, risk-based privacy advice to internal teams (e.g., marketing, HR, IT, procurement) ensuring timely, accurate and business-relevant advice.
- Support client-facing teams with privacy-related contract terms reviews (e.g. DPAs, SCCs), other privacy questions and due diligence.
- Manage routine and moderately complex privacy queries independently, escalating high-risk or novel issues to senior privacy leadership as appropriate.
Privacy Tech & OneTrust (OT)
- Act as a central contact for OT: oversee implementation, ongoing management, reporting and quality control.
- Define and review workflows and processes, perform audits to identify and correct data gaps, errors or discrepancies (e.g. vendor names, documents, data processing details etc.).
- Develop and maintain user guidelines, manage access permissions, add vendors, processing activities, entities etc, and train users on OT functionality and best practices, including assessments, RoPAs, vendor risk, and incident tracking.
- Collaborate with InfoSec/IT teams to align privacy tech workflows with security controls within OT.
Incident Management
- Support the coordination, investigation and documentation of privacy incidents and breaches.
- Conduct root cause analyses, facilitate stakeholder engagement, and support regulatory reporting.
- Maintain and enhance the incident and breach logs; track metrics to support internal and regulatory reporting and continuous improvement.
Data Subject Rights & Compliance Requests
- Act as the initial point of intake for data subject access and rights requests received centrally; route requests to appropriate owners, track completion, and maintain oversight of the process to ensure compliance.
- Support development and automation of Data Subject Rights’ workflows.
- Manage DSARs and related rights requests in compliance with global privacy laws. Coordinate with Regions, IT, Legal, and other business stakeholders to gather data and prepare responses for globally owned requests, ensuring proper documentation.
- Maintain the data subject request log and ensure timely, accurate response in line with regulatory requirements.
Global Collaboration
- Collaborate with privacy professionals and stakeholders across global regions to align practices, share insights, and support cross-border compliance efforts.
- Support global training, awareness, and onboarding activities as needed.
Innovation & Emerging Technologies
- Collaborate with relevant teams to ensure privacy-by-design in the development and deployment of AI, analytics, and other emerging technologies.
- Contribute to risk assessments for AI and other innovative tech use cases, data sharing, and automation tools.
Analytics, KPIs & Reporting
- Define and maintain key privacy management information (PMI) dashboards and reporting tools, tracking key metrics such as number of DSARs, incident volumes and trends, DPIAs initiated and completed, vendor reviews etc.
- Generate and maintain regular privacy dashboards and team reports, providing quarterly insights on performance, trends, and compliance health.
- Support regulatory audits and internal reporting with accurate metrics and documentation.
Training & Awareness
- Coordinate and deliver privacy training and awareness initiatives across the Firm, ensuring global relevance and compliance with local regulations.
- Develop, update, and manage training materials tailored for different roles and risk levels (e.g., onboarding, IT, marketing, procurement) observing localization requirements as applicable.
- Monitor completion of mandatory privacy training and track participation metrics across regions.
- Assess training needs by engaging stakeholders, reviewing incidents/metrics, and staying current on regulatory requirements and organizational changes.
- Support the onboarding and upskilling of new privacy team members, especially in relation to internal tools and systems (e.g., OneTrust).
- Maintain documentation of training and awareness schedules, records, and compliance reporting.
Requirements
Experience & Knowledge
- 3–5 years in privacy and data protection that can be evidenced through work experience, preferably in a global law firm or other global or regulated environment.
- Strong understanding of the GDPR and other data protection laws, able to balance compliance with business enablement. Knowledge of global privacy frameworks or exposure to them preferable.
- Hands-on experience with OneTrust or equivalent privacy management platforms/tools.
- Proven experience in the provision of privacy advice, guidance, data protection compliance processes, including vendor assessments, incident management, DPIAs, and cross-functional privacy support.
- Exposure to privacy issues related to AI, data analytics, or other emerging technologies is a strong advantage.
- Privacy certification (e.g. CIPP/E, CIPM, or other IAPP, GDPR or DPA 2018) preferred.
Skills & Attributes
- Ability to deliver practical, pragmatic and creative privacy solutions.
- Strong analytical skills and experience using metrics to drive improvement.
- Excellent communication and stakeholder skills, both written and verbal, with an ability to explain complex privacy and data protection issues to lay audiences, to negotiate and to influence others.
- Comfortable working with cross-functional teams across legal, tech, security, fee earners and operations, able to interact positively at all levels and a good team player.
- High attention to detail, methodical approach to work with a strong focus on accuracy.
- Proactive, well-organised and resilient under pressure.
- Self-motivated and committed to continuous learning and development.
Desirable Competencies
- Experience supporting or leading ISO 27001/27701 alignment efforts.
- Understanding of AI ethics and data governance frameworks.
- Experient in privacy audit support and l compliance monitoring.
- Familiarity with programme or project management in a compliance or legal setting.
Benefits
Remuneration and benefits package will reflect the successful candidates experience and country where hired.
ACE Data Privacy/Data Protection Officer

Posted 9 days ago
Job Viewed
Job Description
Every member of Gilead's team plays a critical role in the discovery and development of life-changing scientific innovations. Our employees are our greatest asset as we work to achieve our bold ambitions, and we're looking for the next wave of passionate and ambitious people ready to make a direct impact.
We believe every employee deserves a great leader. People Leaders are the cornerstone to the employee experience at Gilead and Kite. As a people leader now or in the future, you are the key driver in evolving our culture and creating an environment where every employee feels included, developed and empowered to fulfil their aspirations. Join Gilead and help create possible, together.
**Job Description**
Gilead Sciences, Inc. is a research-based biopharmaceutical company founded in 1987. Together we deliver life-saving therapies to patients in need. With the commitment and drive you bring to the workplace every day, you will be part of a team that is changing the world and helping millions of people live healthier, more fulfilling lives. Our worldwide staff is a close community where you can see the tangible results of your contributions, where every individual matters, and everyone has a chance to enhance their skills through ongoing development. Our scientific focus has resulted in marketed products that are benefiting hundreds of thousands of people, a pipeline of late-stage drug candidates, and unmatched patient access programs to ensure medications are available to those who could otherwise not afford them. By joining Gilead, you will further our mission to address unmet medical needs and improve life by advancing the care of patients with life-threatening diseases.
**Position Posting Title** **: ACE Data Privacy & Data Protection Officer (DPO), Assoc. Director / Director**
**Specific Responsibilities and Skills**
The ACE Data Privacy & Data Protection Officer (DPO) is a key contributor to the global Privacy & Data Ethics ("PDE") Team, and is responsible for managing privacy compliance across Europe, the United Kingdom, Switzerland, Canada and Australia (ACE) region. The PDE team is responsible for Gilead's global privacy program, including but not limited to, daily operations of the program, implementation, maintenance of policies and procedures, monitoring program compliance, and training. The ACE DPO reports to the Gilead Chief Privacy Officer and may oversee the work of other team members from time to time. The PDE team is a global function and provides matrixed support to corporate business lines as well as country counsel within Gilead's ACE affiliates.
Responsibilities include, but are not limited to:
**Privacy Function**
+ Lead the Company's privacy programs for ACE to strategically manage potential privacy risks and develop appropriate privacy controls to support business initiatives and use of emerging technologies to ensure compliance with the General Data Protection Regulation (GDPR) and related data protection and privacy matters in accordance with laws and regulations in force in all ACE markets in which Gilead operates.
+ Serve as a resource to ACE country counsel for privacy-related issues and escalations and help maintain a harmonized, global approach to issues.
+ Manage appropriate privacy and confidentiality consents, authorization forms and information notices and materials.
+ Work with IT Security to manage procedures for vetting and auditing vendors for compliance with the privacy and data security policies and legal requirements.
+ Manage the process for addressing complaints and requests from data subjects with respect to the enforcement of their rights under applicable laws.
+ Provide advice on Data Protection Impact Assessments (DPIAs)
+ Manage the relationship with the appropriate regulating bodies to ensure that programs, policies and procedures are consistent with law and regulations.
+ Serve as registered Data Protection Officer for purposes of GDPR and other similar legal compliance requirements.
**Incident Response**
+ Evaluate and improve upon process for receiving, documenting, investigating and reporting unauthorized access or disclosure of protected information.
+ Manage breach response, including notification to data subjects, law enforcement and regulators as needed.
**Policies and Training**
+ Continue to implement, maintain and improve corporate privacy policies, procedures, and infrastructure.
+ Develop and deliver privacy training materials and other communications to increase employee understanding of company privacy policies, data handling practices and procedures and legal obligations.
+ Work with business teams and senior management to increase awareness of "best practices" on privacy and data security issues.
+ Serve as information privacy resource to the organization regarding release of information and to all departments for all privacy related issues.
**Qualifications**
+ Professional with strong privacy experience; experience in a life sciences industry preferred.
+ Qualified solicitor preferred.
+ CIPP certification (or equivalent) preferred.
+ Knowledge of European privacy laws regulations and best practices.
+ Proven track record of project and process development, implementation and project management.
+ Results oriented, proactive, responsible and pragmatic with a passion to solve complex problems in creative, efficient and cost-effective way and to translate global compliance environments into actionable policies, processes and programs that enable business objectives.
+ Proven track record of getting things done in complex organizational context, often without formal authority in a highly matrixed environment.
+ Strong knowledge and interest in emerging technologies.
+ Excellent communication skills and outstanding interpersonal skills.
+ Ability to work independently and demonstrated experience prioritizing conflicting demands from multiple business clients in an extremely fast-paced environment.
+ Strong people management skills
+ Self-starter with a high level of initiative and strong work ethic.
As an equal opportunity employer, Gilead Sciences Inc. is committed to a diverse workforce. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans' Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants who require accommodation in the job application process may contact for assistance. For more information about equal employment opportunity protections, please view the EEO is the Law poster
**Equal Employment Opportunity (EEO)**
It is the policy of Gilead Sciences, Inc. and its subsidiaries and affiliates (collectively "Gilead" or the "Company") to recruit select and employ the most qualified persons available for positions throughout the Company. Except if otherwise provided by applicable law, all employment actions relating to issues such as compensation, benefits, transfers, layoffs, returns from layoffs, company-sponsored training, education assistance, social and recreational programs are administered on a non-discriminatory basis (i.e. without regard to protected characteristics or prohibited grounds, which may include an individual's gender, race, color, national origin, ancestry, religion, creed, physical or mental disability, marital status, sexual orientation, medical condition, veteran status, and age, unless such protection is prohibited by federal, state, municipal, provincial, local or other applicable laws). Gilead also prohibits discrimination based on any other characteristics protected by applicable laws.
**For Current Gilead Employees and Contractors:**
Please apply via the Internal Career Opportunities portal in Workday.
Gilead Sciences, Inc. is a biopharmaceutical company that has pursued and achieved breakthroughs in medicine for more than three decades, with the goal of creating a healthier world for all people. The company is committed to advancing innovative medicines to prevent and treat life-threatening diseases, including HIV, viral hepatitis and cancer. Gilead operates in more than 35 countries worldwide, with headquarters in Foster City, California.
Privacy Counsel
Posted 3 days ago
Job Viewed
Job Description
We're Hiring: Privacy Counsel
Remote (with occasional travel to HO in Northampton or London offices)
Full-time | 37.5 hours/week | Mon–Fri / Salary £doe
Legal | Data Privacy | Global Scope
Join our Global Privacy Office and help shape a culture of data confidence across our organisation. As Privacy Counsel, you’ll provide expert legal guidance on global privacy laws (GDPR, CCPA, PECR), support vendor risk management, draft privacy documentation, and advise on data protection strategies across the business.
What You’ll Do:
- Advise on global privacy compliance and legal risks
- Draft and negotiate privacy terms in contracts
- Lead DPIAs, LIAs, and vendor assessments via OneTrust (software)
- Support privacy training, audits, and incident response
- Collaborate across legal, marketing, operations, and acquisitions
What You’ll Bring:
- Qualified lawyer (EU or US), 7+ years PQE
- Strong experience in data protection laws (GDPR, CCPA, etc.)
- IAPP certifications (CIPP/E, CIPM) preferred
- Excellent communication and stakeholder management skills
We’re committed to diversity, inclusion, and creating a workplace where everyone belongs. Enhanced DBS required.
Apply now to be part of a mission-driven team protecting data and empowering care, education, and family solutions.
#GlobalPrivacy #PrivacyProfessionals #IAPP #LegalCareers #RemoteLegalJobs
Privacy Analyst
Posted 3 days ago
Job Viewed
Job Description
Are you passionate about privacy, data protection, and making a real impact across a diverse organisation? We’re looking for a meticulous and proactive Privacy Analyst to join our team and help drive compliance, transparency, and trust across the Group.
About the Role
As Privacy Analyst, you’ll be at the forefront of our data protection efforts—managing the public-facing data protection account, responding to data subject requests, and supporting our operating companies with Subject Access Requests (SARs), Data Protection Impact Assessments (DPIAs), and incident responses. You’ll also work closely with the Data Protection Officer on strategic initiatives, data inventories, and awareness campaigns to strengthen our compliance posture.
Key Responsibilities
- Respond to all enquiries, requests, and complaints from data subjects
- Support SARs, DPIAs, and data breach incident management across the Group
- Assist with data protection audits of business areas and processes
- Collaborate with IT, Procurement, and process owners to map personal data processing activities
- Maintain detailed records of all data protection requests and processing activity
- Use Microsoft Purview to classify and manage data across the Group tenancy
- Work with Group InfoSec to implement data loss prevention policies
- Contribute to strategic compliance initiatives led by the Data Protection Officer
Key Objectives
- Deliver comprehensive data mapping and inventories
- Ensure efficient and compliant SAR processing
- Promote data minimisation across operating companies
- Raise awareness of data protection risks and responsibilities
About You
We’re looking for someone who is:
- Self-motivated and committed to continuous improvement
- Analytical, with strong problem-solving skills
- Detail-oriented and highly organised
- A clear and confident communicator
- Proficient in Microsoft 365 and comfortable working with data
Qualifications & Experience:
- A data protection qualification (or willingness to obtain one)
- Some experience in a data protection or compliance role is preferred
Why Join Us?
You’ll be part of a forward-thinking team that values integrity, innovation, and accountability. This is a fantastic opportunity to grow your career in privacy and compliance while making a tangible difference across the Group.
Please note that this is an onsite role with a minimum of 4 days per week in the office
Head of Data Privacy & Compliance
Posted 1 day ago
Job Viewed
Job Description
Key responsibilities include overseeing data protection impact assessments (DPIAs), managing data breach incident responses, and developing and delivering data privacy training to employees across the organisation. You will work closely with legal, IT, and business units to embed privacy-by-design principles into all aspects of the company's operations and product development. The successful candidate will act as the primary point of contact for data protection authorities and will be responsible for managing regulatory inquiries and audits.
The ideal candidate will possess a strong understanding of data privacy laws and frameworks, coupled with significant experience in developing and managing privacy programs. A relevant certification (e.g., CIPP/E, CIPM) is highly desirable. You must have exceptional analytical, problem-solving, and risk management skills, with the ability to translate complex legal and technical requirements into practical business solutions. Excellent leadership, communication, and stakeholder management skills are essential, as you will be required to influence and collaborate with individuals at all levels of the organisation. This role requires a proactive and diligent approach, with a strong commitment to ethical data handling and regulatory adherence. This is a high-impact, remote role where you can drive significant positive change in data protection strategy and implementation.
Data Privacy Counsel
Posted 2 days ago
Job Viewed
Job Description
Major UK retailer looking for a Data Privacy Lawyer for their UK operation.
12 month fixed term contract
Hybrid working arrangement (with flex)
Extremely varied role working across cutting edge tech/AI/machine learning etc.
Ideally looking for an experienced Data Privacy Lawyer (UK or EU qualified) with an interest in the retail/consumer sector.
Great opportunity to work for a major consumer retailer in the UK offering a broad role with exposure to some of the most advanced tech-related privacy initiatives available.
For further information, please contact Stuart Vines at Graff Search at:
Be The First To Know
About the latest Privacy Jobs in United Kingdom !
Data Privacy Counsel
Posted 2 days ago
Job Viewed
Job Description
Major UK retailer looking for a Data Privacy Lawyer for their UK operation.
12 month fixed term contract
Hybrid working arrangement (with flex)
Extremely varied role working across cutting edge tech/AI/machine learning etc.
Ideally looking for an experienced Data Privacy Lawyer (UK or EU qualified) with an interest in the retail/consumer sector.
Great opportunity to work for a major consumer retailer in the UK offering a broad role with exposure to some of the most advanced tech-related privacy initiatives available.
For further information, please contact Stuart Vines at Graff Search at:
Data Privacy Manager
Posted 3 days ago
Job Viewed
Job Description
Rev & Regs are recruiting for a 'Data Privacy Manager' vacancy on behalf of a leading UK Financial Services firm in Liverpool.
Role Overview
Support the Data Protection Officer (DPO) in implementing and maintaining the data protection framework across the, ensuring compliance with UK GDPR and related regulations. Provide expert advice and guidance on data protection risks, policies, and practices.
Key Responsibilities
- Support the DPO in embedding a strong data protection culture through advice, training, and awareness.
- Manage complex data protection queries and advise the business on compliance obligations.
- Conduct Data Protection Impact Assessments (DPIAs) and support policy development.
- Coordinate and respond to data subject rights requests in line with legal requirements.
- Investigate and manage data breaches, near misses, and remediation efforts.
- Maintain accurate Records of Processing Activities (RoPA).
- Support data protection complaints and identify root causes.
- Advise on data protection in change projects and supplier engagements.
- Produce data protection reports and analytics to inform risk management.
- Conduct periodic monitoring and reviews aligned with the ICO accountability framework.
Skills & Experience
- Strong knowledge of UK GDPR, DPA 2018, EU GDPR, and PECR.
- 5+ years’ experience in a data protection role, ideally in regulated financial services.
- Proven ability to manage SARs, breaches, and develop compliance processes.
- Clear, confident communicator with strong stakeholder engagement skills.
- Proficient in Microsoft 365 and risk management tools.
- Holds an industry-recognised data protection qualification.
- Committed to ongoing professional development and maintaining independence in the role.
Salary: £55,000 pa + bonus + benefits package.
Location: Hybrid (2-3 days per week in Liverpool office)
If you are interested, please apply today – /
Data Privacy Counsel
Posted today
Job Viewed
Job Description
- Providing expert legal advice on data protection laws and regulations, including GDPR, CCPA, and other relevant privacy frameworks.
- Developing, implementing, and maintaining data privacy policies, procedures, and training programs.
- Conducting Data Protection Impact Assessments (DPIAs) and Privacy Impact Assessments (PIAs).
- Advising on data breach response protocols and managing investigations.
- Reviewing and advising on data processing agreements and third-party vendor contracts from a privacy perspective.
- Collaborating with internal stakeholders across various departments to ensure privacy-by-design principles are embedded in projects and product development.
- Staying current with evolving privacy laws and best practices globally.
- Managing regulatory inquiries and interactions with data protection authorities.
- Assisting with the negotiation of data processing clauses in commercial agreements.
- Providing guidance on cross-border data transfers.