Looking to make a real impact with your data protection expertise?
Join a purpose-driven charity as our fully remote Data Protection Officer, working 35 hours per week, where your work will directly support strong governance, protect sensitive data, and help shape organisational resilience.
We’re looking for a confident, independent professional to lead on compliance, privacy, and information governance, ensuring we meet the highest standards under UK GDPR while supporting teams across the organisation.
What you’ll be doing
You’ll be the go-to expert on all things data protection, balancing strategy with hands-on delivery:
- Lead and oversee our data protection compliance programme and audit framework
- Act as the key contact for regulators, including the ICO
- Manage data subject rights (DSARs, erasure, rectification, restriction requests)
- Advise on Data Protection Impact Assessments (DPIAs) and third-party due diligence
- Support incident response, including breaches and corrective actions
- Deliver engaging training and awareness programmes across the organisation
- Maintain compliance records and monitor adherence to UK GDPR
- Provide expert input into business continuity and organisational resilience
- Collaborate with stakeholders at all levels, including senior leadership and Board
You’ll sit within our Governance team, reporting to the Executive Director of Governance & Quality Assurance, with the autonomy to escalate directly to senior leadership and trustees where needed.
What we’re looking for
Essential:
- Strong experience in data protection, compliance, audit, IT/security, or legal roles
- Expert knowledge of UK GDPR and data privacy legislation
- Proven experience handling complex DSARs, DPIAs, and data incidents
- Experience working with regulators and managing compliance responses
- Ability to influence, challenge, and collaborate across all levels
- Highly organised, independent, and able to manage competing priorities
- Strong judgement when assessing and managing risk
Qualifications:
- Degree-level education (or equivalent experience)
- Recognised certification (e.g. GDPR Practitioner, CIPP/E, CIPM, C-DPO or similar)
Desirable:
- Experience working with Boards or non-executives
- Background in the charity, public sector, NHS, MOJ, or local authorities
- Knowledge of ISO 27001 or working with sensitive/vulnerable data
This is a rare opportunity to take on a high-impact, autonomous role in a collaborative, mission-led organisation. You’ll have the flexibility of fully remote working while influencing how data protection is embedded across the charity at every level. If you’re looking to shape best practice, work closely with senior leadership, and make a meaningful contribution to a cause that matters, this role offers both challenge and purpose in equal measure.
Ready to lead on data protection where it truly matters? Apply now and help us build a culture of trust, compliance, and accountability.
Please see attached Job Description for full details