Qualifications
- 5–10+ years of experience in privacy compliance, data protection, or privacy risk management.
- Demonstrated expertise in UK GDPR and the Data Protection Act 2018.
- Delivery support experience for HCM/HRIS implementations, migrations, or digital transformation programmes.
- Track record of negotiating DPAs and supplier privacy terms.
- Hands-on experience leading DPIAs and privacy risk assessments.
- Healthcare or hospital client experience, including handling special category (health) data and HR data.
Preferred Qualifications
- CIPP/E, CIPM, or equivalent privacy certification.
- Familiarity with public sector information governance expectations and standards.
- Experience with Workday, Oracle HCM, or SAP SuccessFactors environments.
- Multi-vendor and subcontracting engagement experience.
Key Skills
- Contract negotiation and commercial awareness.
- Ability to operationalise legal and regulatory requirements into practical controls.
- Effective stakeholder management across technical and non-technical audiences.
- Strong written and verbal communication.
Reporting Line and Interfaces
- Reports to: Engagement Leadership/DPO/or Designate Identified by DPO
- Key interfaces: Client Privacy/IG, Security, HR Transformation; Internal Programme/Delivery, Security, Legal/Commercial; Third-party suppliers and subprocessors.
Success Measures
- DPIAs completed and updated on schedule for all in-scope processing activities.
- Privacy risk mitigations tracked and closed within agreed timelines.
- DPA and subprocessor negotiations concluded within project timelines.
- Positive stakeholder feedback from client Privacy/IG and programme
#J-18808-Ljbffr…
