Privacy Manager
Role details
Job location
Tech stack
Job description
We are seeking an experienced and pragmatic Privacy Manager to support the Group Legal Counsel and DPO in delivering Brigade's global privacy programme across all group companies and international operations.
This role will play a key part in ensuring compliance with applicable data protection laws (including UK GDPR, EU GDPR, and other relevant regulations), embedding privacy-by-design principles, and supporting the business in managing privacy risks effectively., * Support the DPO in maintaining and evolving the Group's privacy framework, policies, and procedures
- Provide day-to-day privacy advice to business stakeholders across multiple jurisdictions, group companies and SaaS/service teams
- Assist in ensuring compliance with UK GDPR, EU GDPR, and other global data protection laws
- Lead or support Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs)
- Maintain and oversee Records of Processing Activities (RoPA) for group entities and departments, ensuring consistency and completeness
- Support data subject rights processes, including handling complex requests and escalations
- Assist with the management and investigation of personal data breaches, including regulatory notifications where required
- Review and negotiate data protection clauses in contracts, including Data Processing Agreements (DPAs)
- Deliver privacy training and awareness programmes across the organisation
- Monitor global regulatory developments (including those impacting digital services and SaaS) and advise on their impact to the business
- Support vendor risk management and third-party due diligence from a privacy perspective across international suppliers and service providers
- Contribute to internal audits and continuous improvement of privacy controls
- Review, draft, and maintain external privacy notices (including for websites and SaaS platforms) and internal data protection policies to ensure consistency, accuracy, transparency, and ongoing compliance across all group companies and territories
Requirements
The ideal candidate will combine strong technical knowledge of data protection with a commercial mindset the ability to work collaboratively across functions and geographies., * Proven experience in a privacy/data protection (in-house or consultancy) within a multinational organisation
- Strong working knowledge of UK GDPR, EU GDPR, and broader global privacy frameworks, including e-privacy regulations (e.g. PECR)
- Experience supporting or working closely with a DPO
- Experience with DPIAs, RoPA, breach management, and data subject rights handling across multiple jurisdictions
- Professional privacy qualifications (e.g., CIPP/E, CIPM, CIPT or equivalent)
- Understanding of information security principles and frameworks (eg ISO 27001)
- Experience reviewing, drafting and advising on data protection provisions in commercial contracts, including DPAs
- Experience advising on digital products, SaaS platforms, or technology-driven services from a privacy perspective
- Understanding of privacy risks in cloud environments, data processing roles (controller/processor), and cross-border data transfers
- Ability to translate privacy/data protection requirements into practical business solutions
- Strong stakeholder management and communication skills (both verbal and written)
- Ability to work independently and manage multiple priorities in a fast-paced environment
- High attention to detail with a risk-based, pragmatic approach
- Decision-making skills, especially in high-pressure situations.
- Proactive, enthusiastic, and driven.
- Flexibility to work beyond normal business hours when required