Data Protection Officer, Director

Company: Oxford Nanopore Technologies
Apply for the Data Protection Officer, Director
Location: Oxford
Job Description:

Data Protection Officer – Oxford (Hybrid – 3 days per week in the office)

Reporting to the General Counsel, the successful candidate will be responsible for maintaining and developing Oxford Nanopore’s data protection and privacy compliance framework across all countries in which the company operates, including the UK, GDPR, US, Canada, Australia and Singapore.

This is a hands‑on operational role that directly executes core privacy compliance activities. The role manages assessments, completes records and coordinates end‑to‑end data protection processes across the business while working closely with Legal, Information Security, HR, Commercial, Clinical/Regulatory, and R&D teams.

Responsibilities

  • Act as the primary contact for day‑to‑day data protection and privacy matters and collaborate with the external Data Protection Officer on complex issues.
  • Conduct and review Data Protection Impact Assessments (DPIAs), Legitimate Interest Assessments, Transfer Risk Assessments and other risk‑based assessments on an ongoing basis.
  • Maintain all data protection documentation and records, such as policies, notices, RoPA, breach logs and rights‑request registers.
  • Support the creation of Data Sharing Agreements with partner organisations.
  • Lead and manage responses to individuals exercising personal data rights, including access, erasure and correction requests.
  • Lead the company’s response to personal data breaches and coordinate with IT, Information Security and other stakeholders on the breach aspects of wider cybersecurity incidents.
  • Monitor and reply to internal or external data protection queries, including those received via the DPO email account.
  • Define and deliver regular staff awareness training on data protection and privacy through the company’s internal platform and in person where required.
  • Maintain and develop guidance content (FAQs, etc.) on the Data Protection subsite of the resource centre.
  • Provide input and guidance on supplier management and assurance processes.
  • Monitor changes to data protection and privacy laws, healthcare information governance policies and other emerging trends relevant to the business.
  • Update and maintain registrations with regulatory authorities, including the ICO.
  • Engage and manage specialist external consultants or privacy advisors for complex assessments, DPIAs, transfer analyses, cloud architecture reviews or emerging regulatory requirements.
  • Schedule and oversee independent external assessments to validate the company’s privacy posture and benchmark against industry standards.
  • Assist in responding to customer questionnaires and lead initiatives toward HIPAA compliance.

Key Requirements

  • Degree‑level education or equivalent experience.
  • Strong working knowledge of UK GDPR and international data protection frameworks.
  • Proven experience in a data protection, privacy or compliance role within a multinational organisation.
  • Experience within life sciences, biotechnology, healthcare or technology sectors.
  • Experience supporting international data transfers and global compliance programmes.
  • Experience interacting with regulators (e.g., ICO or EU supervisory authorities).
  • Experience conducting DPIAs and advising on privacy risk mitigation.
  • Experience managing data subject rights requests and breach processes.
  • Experience reviewing and negotiating data protection clauses in commercial agreements.
  • Ability to translate regulatory requirements into pragmatic business guidance.

Other Requirements

  • Passion for data protection and privacy.
  • Strong communication skills with the ability to engage stakeholders at all levels.
  • Pragmatic, commercially aware and solutions‑focused.
  • Strong organisational skills and attention to detail.
  • Capacity to work autonomously in a fast‑paced environment.
  • Collaborative approach with strong influencing skills.

Please note that no terminology in this advert is intended to discriminate on the grounds of a person’s gender, marital status, race, religion, colour, age, disability or sexual orientation. Every candidate will be assessed only in accordance with their merits, qualifications and abilities to perform the duties of the job.

#J-18808-Ljbffr…

Posted: April 20th, 2026