Data Protection & Compliance Lead – Hybrid – Hampshire
I’m working with an early‑stage wellness technology company building a new healthtech product, the business is preparing for a 2026 product launch and is now hiring their first Data Protection & Compliance Lead.
This role will take full ownership of data protection, privacy governance and regulatory compliance across the organisation, ensuring the platform is built with privacy and compliance embedded from the start.
Key Responsibilities
- Own data protection and privacy governance across the business
- Conduct Data Protection Impact Assessments (DPIAs) for new features and integrations
- Ensure compliance with GDPR, UK GDPR and US privacy laws (including CCPA/CPRA)
- Manage vendor data processing agreements and third‑party platform reviews
- Audit analytics, attribution and subscription platforms to ensure no sensitive health data is exposed
- Act as the primary contact for external legal counsel
- Translate legal advice into practical product and engineering requirements
- Ensure compliance across subscription billing and auto‑renewal regulations
- Maintain ongoing compliance reviews and regulatory monitoring as the product evolves
What They’re Looking For
- Experience in data protection / privacy compliance roles
- Experience handling sensitive personal or health data
- Strong knowledge of GDPR and international privacy regulations
- Experience conducting DPIAs and vendor data reviews
- Ability to translate regulatory guidance into practical implementation
- Comfortable working independently in an early‑stage environment
- Experience within digital health, femtech or consumer health platforms
#J-18808-Ljbffr…
