Data Protection Manager

East Midlands
Derby, UK
4 days ago
Apply on jobs.eastmidlandsrailway.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Data Sharing Decision Support Systems Information Lifecycle Management Privacy Controls Data Processing ISO-14001

Job description

Ten times accredited as a Top Employer and Gold accredited for Inclusive Employers Standards, we value our people and are dedicated to making sure that everybody feels empowered to bring their authentic self to work. At EMR we want to proactively embrace diversity across our workforce and recognise that we are under-represented in some areas. We’re therefore taking positive steps to promote a positive and inclusive culture and we welcome applications from everyone to help us better represent our communities. We have an exciting opportunity to join #TeamEMR as a Data Protection Manager. This pivotal role leads and manages EMR’s privacy framework to ensure full compliance with the UK GDPR, the Data Protection Act 2018, and related legislation. Providing expert, pragmatic advice and, embedding privacy by design across all business processes, and promote a strong internal culture of accountability and compliance. Key Roles and Responsibilities Data Protection Strategy & Governance - Own the organisation’s data protection and privacy framework, ensuring compliance with UK GDPR, the Data Protection Act 2018, PECR and related legislation, and that policies, procedures and standards remain current and effective. Advisory & Decision Support - Act as the organisation’s principal source of data protection expertise, advising senior leadership and project teams on complex privacy matters, challenging proposals where risks or non-compliance arise, and embedding privacy by design across change initiatives and DPIAs. Individual Rights & Breach Management - Own the end-to-end handling of data subject rights requests and personal data breaches, ensuring both are managed lawfully, efficiently and within statutory timescales, with regulatory notification where required. Information Governance & Third-Party Assurance - Maintain oversight of the organisation’s records of processing activities, and ensure data protection provisions are properly reflected in contracts, data processing and data sharing agreements with suppliers and partners. Assurance, Risk & Retention - Provide ongoing assurance that data protection risks are identified, assessed and mitigated, that compliance actions are implemented, and that a robust retention and disposal framework keeps personal data held only as long as necessary and disposed of securely. Culture, Capability & Awareness - Build organisational capability and awareness through training and campaigns, ensuring managers and stakeholders understand their responsibilities and a culture of privacy and accountability is embedded. Regulatory Horizon Scanning - Monitor developments in data protection law, regulatory guidance and best practice, translating these into practical recommendations for the organisation. Reporting & Governance Assurance - Produce accurate, timely reporting and management information for senior leadership, governance committees and the Board, providing assurance on compliance performance and the effectiveness of the data protection framework. Stakeholder & Group Relationships - Build effective relationships with internal stakeholders, regulators and the Group Data Protection Officer, ensuring alignment with group-wide privacy strategy and consistent application of standards, and acting as or supporting the DPO role where required. The above list is not exhaustive, and on occasion, the role may need to undertake other reasonable requests as required by their line manager, in line with grade and competence All staff have a responsibility and accountability to ensure that their day-to-day activities support our commitments under the Sustainability Policy Statement and relevant management systems (e.g. ISO14001 or ISO50001); and to act in a sustainable manner and minimise impact on the environment., Please be advised that all responses to questions on this application form will be carefully monitored for indications of AI assistance. It is important to us that you are being your authentic self so please base your answers on your personal knowledge and experience. Any detected use of AI-generated content will result in disqualification from the application process. We value integrity and transparency in all applications and appreciate your cooperation in maintaining these standards. Supporting Our Frontline If you’re successful in this role, you’ll be expected to support our frontline colleagues at some points throughout the year. This might be undertaking safety critical work, for which you’ll receive training, but it could just be helping out with Customer Service when our stations are busy. We’re One Team, and that means our managers step up for the frontline, not just manage from a distance. Supporting frontline colleagues is part of our DNA at EMR. We welcome applicants from diverse backgrounds, we promote equal opportunities for all. East Midlands Railway is a non-discriminatory employer committed to the recruitment and promotion of all on the basis of ability and merit irrespective of disability, race, gender, health, social class, sexual preference, marital status, nationality, religion, employment status or age. We’ll treat your application fairly and assess you for the job based on merit and skills.

Requirements

We’re looking for a confident and capable individual who brings: o Certified Information Privacy Professional/Europe (CIPP/E) or a BCS Practitioner certificate o Knowledge of UK GDPR, Data Protection Act 2018, PECR, ICO guidance, and information security principles. Desirable certification in Data Protection o Understanding of privacy by design, information lifecycle management, data sharing, and supplier governance. o Experience managing DPIAs, Data Subject Rights Requests, personal data breaches, and privacy risk assessments. o Experience reviewing commercial contracts, Data Processing Agreements (DPAs), and Data Sharing Agreements. o Experience producing Board-level reports and performance metrics to provide compliance assurance to senior leadership. o Ability to interpret complex legislation and translate it into strategic, risk-based, and proportionate business solutions. o Excellent communication (written and verbal), negotiation, and influencing skills to challenge and advise confidently at all organisational levels and committees within a diverse workforce. o Experience of leading a GDPR governance programme (continuous improvement against minimum standards)

Benefits & conditions

As well as a competitive salary, we’ll also offer you: o 32 days annual leave (including bank holidays), rising to 34 days after 2 years of service o Free travel on East Midlands Railway and other train companies operated by Transport UK o 75% discount on other national rail train companies, including for partners and dependants o Discounted friends and family tickets on the EMR network o Various personal development and progression opportunities o Excellent pension scheme This position is based in our Derby Head office, but we’ve adopted a flexible hybrid working model that creates the opportunity to work in your own way at home but also provides great spaces for in-person collaboration.

About the company

We are proud to be One Team at East Midlands Railway (EMR). We are passionate about keeping people safe, delighting our customers, doing the right thing and putting customers at the heart of our sustainable railway for the East Midlands. With over 2,600 employees, our people are the reason we are so successful, and our employees make a crucial contribution to this.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.eastmidlandsrailway.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

3:18 min

Utilizing AI and public data sharing for urban planning

Christian Wiegand +3 ¡ World Congress 2024

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 ¡ World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger ¡ LIVE

3:42 min

Applying the satellite architecture for machine learning isolation

Christoph Fassbach Christoph Fassbach +1 ¡ World Congress 2024

2:11 min

Addressing security audits and regional data compliance legislation

Videos

See all

Related articles

See all