
Data Privacy Manager
zopa · London
About The Role
Our Story
Hello there. We’re Zopa.
We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank. A bank that listens to what our customers don’t like about finance and does the opposite. We’re redefining what it feels like to work in finance. Our vision for a new era of banking puts people front and centre — we’ve built a business that empowers everyone to aim high, every day, to move finance forward. Find out more about our fantastic offerings at <Zopa.com>!
We’re incredibly proud of our achievements and none of it would be possible without the amazing team here. It’s not just industry awards we’re winning, we’ve also been named in the top three UK’s Most Loved Workplaces.
If you embrace unconventional challenges, are unafraid to think differently and are driven to make an outsized impact, you’ll thrive here at Zopa, so join us, and make it count. Want to see us in action? Follow us on Instagram @zopalifeThe TeamYou’ll join the Data Privacy function within Operational Risk & Compliance. The function serves the whole of Zopa, helpingteams across the business make confident, well-reasoned decisions about customer data. Within the wider function, theOperational Risk & Compliance teams also support product and business activity including current accounts, savings,investments and marketing.The Role
As Data Privacy Manager, you’ll lead the team’s strategic and day-to-day work, managing a Data Privacy Associate andpartnering closely with product, technology, legal, risk, security and commercial colleagues. You’ll help evolve a privacycapability that is rigorous where it needs to be and practical everywhere it can be. There is also an opportunity to help buildthe function’s PCI DSS capability over time.
Key Responsibilities
- Advise product and business teams on privacy implications of new products, changes and customer journeys.
- Translate UK privacy law into clear, proportionate recommendations that enable responsible decisions.
- Support the development of the data privacy governance framework, from DPIAs and privacy by design to retention, ROPA and third-party diligence.
- Manage complex privacy incidents, including regulatory notification and engagement with affected individuals where required.
- Oversee high-quality, timely handling of DSARs, erasure requests and objections.
- Build trusted partnerships across technology, legal, risk, security and commercial functions.
- Develop your direct report and strengthen privacy awareness across the business.
- Contribute to the Bank’s approach to data risk across a broad range of business activity
Experience
- Bring deep practical knowledge of UK GDPR, the Data Protection Act 2018 and wider UK privacy regulation.
- Apply privacy law proportionately in a commercial environment and give pragmatic, business-enabling advice.
- Make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs the actual privacy risk.
- Have helped develop a data protection function in an organisation with evolving privacy maturity.
- Design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA and third-party due diligence.
- Manage data breaches and privacy incidents end-to-end, including ICO notification where required.
- Handle data-subject rights requests with quality, timeliness and defensible decisions.
- Build credibility with business, technology, legal, risk and security stakeholders.
- Lead and develop high-performing teams with accountability and continuous improvement.
- Nice to haves
- Bring hands-on PCI DSS knowledge and want to help build this capability across the function.
- Know PCI DSS requirements and their practical application in financial services or payments.
- Assess cardholder-data flows, scope boundaries and control gaps as part of broader data-risk reviews.
- Have contributed to PCI DSS compliance programmes.
- Understand regulated financial services and how privacy obligations interact with FCA and PRA expectations.
- Comfortably influence senior executives and handle challenging conversations.
- Bring exposure to another risk discipline, such as compliance or operational risk
- Experience using OneTrust to manage data privacy obligations
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
