Data Governance, Privacy & Enablement Counsel
- Regulatory Compliance
- GDPR
- AI
- Machine Learning
Job Description
The Role
The role provides expert legal advice and strategic support on all aspects of data protection, privacy and information governance across the Group. The role ensures that the organisation's data strategy, governance framework and commercial initiatives are underpinned by robust legal and regulatory compliance while enabling the responsible and innovative use of data.
As a member of the wider legal team, working closely with the Data Enablement Officer, Data Protection, Information Security, Compliance, Technology and Business teams, the role embeds privacy by design, supports enterprise data governance, facilitates secure data sharing, and provides day-to-day legal advice on privacy and contractual data protection matters across our operating companies. The role acts as a trusted legal partner to the business, enabling commercial initiatives through practical, solutions-oriented advice.
Key Responsibilities
- Provide legal support in the development and maintenance of the Group Data Enablement Framework.
- Ensure legal and privacy requirements are embedded within enterprise data governance standards, policies and processes.
- Advise on accountability obligations, lawful processing principles and privacy-by-design requirements across data initiatives.
- Support governance committees and decision-making forums on legal aspects of data management.
- Review, draft and negotiate contracts involving the processing or sharing of personal data.
- Ensure contractual arrangements appropriately allocate privacy obligations and regulatory responsibilities.
- Provide legal support on supplier, customer and technology agreements involving personal data.
- Act as the primary legal contact for operational data protection and privacy queries from business stakeholders.
- Provide timely advice on subject access requests, retention, lawful basis, marketing, customer complaints, employee data and operational privacy issues.
- Support business projects by providing practical legal solutions to day-to-day data protection matters.
- Provide legal advice on new data flows, system integrations and enterprise data architecture initiatives.
- Advise on privacy implications relating to data minimisation, purpose limitation, retention, security and lawful processing.
- Review new technologies and transformation programmes to ensure privacy risks are appropriately managed.
- Advise on legal requirements relating to Records of Processing Activities (ROPAs), data inventories and data classification.
- Support documentation of ownership, lawful basis, retention periods and processing purposes for key business data assets.
- Ensure accountability obligations under GDPR are appropriately embedded within enterprise data cataloguing initiatives.
- Provide legal advice on the lawful use of customer data for analytics, profiling, segmentation, AI and commercial initiatives.
- Advise on consent requirements, legitimate interests assessments and direct marketing obligations.
- Support responsible innovation while protecting customer rights and maintaining regulatory compliance.
- Provide privacy and data protection legal advice on the Group's AI initiatives, including generative AI tools, machine learning models and automated decision-making systems.
- Advise on the lawfulness of AI-driven processing.
- Support the development of internal AI governance frameworks and policies, ensuring privacy-by-design principles are embedded from the outset.
- Monitor developments in AI regulation and advise on their implications for the Group's activities.
- Lead the legal response to personal data incidents and breaches, including severity assessment and advising on regulatory notification obligations.
- Manage notifications to the ICO within statutory timeframes and coordinate any required communications to affected data subjects.
- Coordinate breach response with Information Security, Compliance and Communications teams to ensure a timely and legally robust response.
- Manage proactive and reactive engagement with the ICO, including regulatory investigations and formal inquiries.
- Design and deliver privacy training and awareness programmes tailored to business stakeholders across the Group.
- Support embedding a culture of data protection across the organisation through accessible, practical guidance and communications.
Knowledge, Skills and Behaviours
Essential
- Extensive knowledge of UK GDPR and the Data Protection Act 2018.
- Extensive knowledge of the Data (Use and Access) Act 2025 and its implications for data sharing, smart data schemes and research exemptions.
- Extensive knowledge of the Privacy and Electronic Communications Regulations (PECR).
- Extensive knowledge of UK Information Commissioner's Office (ICO) guidance and regulatory expectations.
- Extensive knowledge of EU GDPR and international privacy frameworks where applicable.
- Extensive knowledge of Data Processing Agreements, International Data Transfer Agreements (IDTAs) and Standard Contractual Clauses (SCCs).
- Extensive knowledge of Records of Processing Activities (ROPAs), Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs).
- Extensive knowledge of customer data governance, profiling, marketing permissions and consent management.
- Extensive knowledge of emerging technologies including Artificial Intelligence, automated decision-making and data ethics.
- Extensive knowledge of enterprise data governance frameworks and the interaction between legal, compliance, technology and business functions.
- Ability to provide pragmatic, commercially focused legal advice on complex data protection issues.
- Ability to draft, review and negotiate contracts involving personal data processing and sharing.
- Ability to interpret legislation and regulatory guidance and translate it into practical business solutions.
- Ability to influence senior stakeholders and communicate complex legal concepts in a simple and accessible manner.
- Ability to build collaborative relationships across Legal, Data Protection, Technology, Information Security, Compliance and Commercial teams.
- Ability to analyse complex data processing activities and identify legal and privacy risks.
- Ability to support strategic data governance initiatives and privacy-by-design programmes.
- Ability to manage multiple priorities and provide responsive legal support across a diverse business.
- Ability to exercise sound judgement when advising on new or high-risk data initiatives.
- Ability to demonstrate a solutions-first mindset, identifying compliant pathways to commercial objectives.
- Qualified Solicitor (England & Wales) or equivalent legal qualification.
- Minimum 5 years' post-qualification experience advising on UK data protection and privacy law.
- Strong experience leading or supporting enterprise data transformation or digital transformation programmes.
- Significant experience reviewing and negotiating commercial contracts involving personal data in multiple jurisdictions.
- Significant experience leading the drafting and negotiation of Data Processing Agreements, Data Sharing Agreements, International Data Transfer Agreements, Standard Contractual Clauses, technology and outsourcing agreements, and Transfer Risk Assessments.
- Experience advising on customer data, marketing, profiling and consent management.
- Experience responding to day-to-day operational privacy queries from business stakeholders.
- Deep experience in providing advice under pressure on breach assessment, notification thresholds, ICO/regulatory reporting, data subject communications, internal investigations, remediation and post-incident governance.
- Substantial experience gained within an in-house legal function.
- Experience advising on personal data breach response, including regulatory notification obligations to the ICO and management of third-party and data subject notifications.
Desirable
- Considerable APAC experience in reviewing and negotiating commercial contracts involving personal data.
- Experience advising on AI governance, machine learning or automated decision-making.
- Experience supporting international organisations and cross-border data transfers.
- Experience implementing or supporting enterprise data governance frameworks.
- Experience working with data cataloguing tools, metadata management or Records of Processing Activities (ROPAs).
- Experience training non-lawyers, influencing stakeholders and embedding privacy controls into business processes.
- Experience engaging with the ICO or other data protection regulators, including managing regulatory investigations or formal inquiries.
- Relevant privacy certification such as CIPP/E (IAPP) or equivalent.
Reward & Benefits: What's in it for me?
We want our people to feel recognised, supported and able to thrive both at work and beyond it.
We offer a competitive reward package designed to support your financial, physical and mental wellbeing, alongside opportunities to learn, develop and be recognised for the contribution you make. Benefits vary by role and location, and full details will be shared as part of the application process.
Equal opportunities: Our commitment to inclusion
Collinson Group is an equal opportunities employer. We welcome applications from people of all backgrounds, identities and experiences, and believe that different perspectives make our business stronger.
Data Governance, Privacy & Enablement Counsel ยท Collinsongroup