Head of Data Protection
Benefits of working at Together26 days holiday, and a day off for your birthday (increasing with service to 30 days), plus bank holidaysFree access to company holiday homesBuy & sell holidaysDiscretionary annual bonus plus an additional Shared Reward BonusMatched pension contributionHealth cash plan plus Private medical insuranceLife assurance and Critical illness coverTravel season ticket loans and Ride to work schemeFree local gym accessLocal bar / restaurant discounts–––––––––––––Company Description We’re Together. For over 50 years, we’ve helped thousands of people, businesses and professionals unlock their property ambitions with our common-sense approach to mortgages and secured loans.We take the time to understand our customers and our door is always open, so we can often help when other lenders can’t or won’t. Based in Cheadle, Cheshire, our 750 colleagues help our customers throughout the UK, backed by the power of a £7 billion loan book. As the Head of Data Protection you will be responsible for overseeing Together Money's Data Protection Framework, ensuring compliance with UK General Data Protection Regulations (UK GDPR), the Data Protection Act 2018 (DPA) and the Privacy and Electronic Communication Regulations (collectively “Data Protection Laws”), Consumer Duty, and other relevant regulatory expectations. The role provides strategic leadership on privacy, data protection, data governance, and information risk, acting as the primary subject matter expert and advisor to senior management and the Board.As the Head of Data Protection we are looking for someone to: Lead the development and implementation of Together Money’s data protection strategyServe as the organisation’s Data Protection Officer under UK GDPRMonitor compliance with data protection laws, internal policies, and regulatory obligationsProvide advice on, and monitor the completion and outcomes of, Data Protection Impact Assessments (DPIAs) for high‑risk processing and change initiativesCooperate with, and act as the main point of contact for, the Information Commissioner’s Office (ICO), including supporting any prior consultation activitiesAct as a contact point for data subjects on the exercise of their rights and privacy queries, and support timely, compliant responsesDrive continuous improvement of data protection and privacy controlsDrive continuous improvement of data protection training and awareness programmesProvide expert advice on new products, systems, and change initiativesInform and advise the organisation (including employees) on obligations under UK GDPR, DPA 2018 and related data protection lawsMonitor compliance with data protection laws and internal policies, including assigning responsibilities, overseeing audits, and driving awareness and trainingProvide assurance and oversight of data retention, archiving, and disposal practicesEnsure privacy by design and default is embedded across all change initiativesLead ...