Collinson is a global loyalty and benefits company.
We use our expertise and products to craft customer experiences which enable some of the world's best-known brands to acquire, engage and retain the most demanding and choice-rich customers. In particular, our unique expertise and insight into high earning, frequent travellers allow us to create products and solutions for our clients that inspire greater customer engagement to drive more profitable relationships, enrich their travel experiences, protect what matters, and assist in in times of need.
While specialising in Financial Services, Travel and Retail, we also support clients in multiple sectors. We have worked with over ninety airlines, twenty hotel groups and more than six hundred financial institutions and banks, with clients including Accor Hotels, Air France KLM, American Express, British Airways, Cathay Pacific, Diners Club, Mandarin Oriental, Mastercard, Radisson Hotel Group, Sephora, Visa and Vhi.
We take our 30 years' experience working with these kinds of household names in over 170 countries and help our clients to deliver the smarter experiences it takes to differentiate their propositions and help them win deeper devotion with their customers.
Collinson is a privately-owned entrepreneurial business with 2,000 passionate people working in twenty locations worldwide. Our solutions include Priority Pass, the world's best known airport experiences programme, while we are also the trusted partner behind many of the leading financial services, airline and hotel brand's reward programmes and loyalty initiatives.
Purpose of the job
The role provides expert legal advice and strategic support on all aspects of data protection, privacy and information governance across the Group, ensuring the organisation's data strategy, governance framework and commercial initiatives are underpinned by robust legal and regulatory compliance while enabling responsible, innovative use of data.
Working closely with the Data Enablement Officer, Data Protection, Information Security, Compliance, Technology and Business teams, the role embeds privacy by design, supports data governance, facilitates secure data sharing, and provides day-to-day legal advice on privacy and contractual data protection matters across our operating companies — acting as a trusted legal partner who enables commercial initiatives through practical, solutions-oriented advice.
Key Responsibilities
Group Data Enablement Framework
- Provide legal support in developing and maintaining the Group Data Enablement Framework.
- Embed legal and privacy requirements within enterprise data governance standards, policies and processes.
- Advise on accountability obligations, lawful processing principles and privacy-by-design requirements.
- Support governance committees and decision-making forums on legal aspects of data management.
Contracts and Commercial Arrangements
- Review, draft and negotiate contracts involving the processing or sharing of personal data.
- Ensure contractual arrangements appropriately allocate privacy obligations and regulatory responsibilities.
- Advise on supplier, customer and technology agreements involving personal data.
Day-to-Day Legal and Data Protection Advice
- Act as the primary legal contact for operational data protection and privacy queries from business stakeholders.
- Advise on subject access requests, retention, lawful basis, marketing, customer complaints, employee data and operational privacy issues.
- Support business projects with practical legal solutions to day-to-day data protection matters.
Enterprise Data Architecture and Data Pipelines
- Advise on new data flows, system integrations and enterprise data architecture initiatives.
- Advise on privacy implications relating to data minimisation, purpose limitation, retention, security and lawful processing.
- Review new technologies and transformation programmes to ensure privacy risks are appropriately managed.
Data Cataloguing and Accountability
- Advise on legal requirements relating to Records of Processing Activities (ROPAs), data inventories and data classification.
- Support documentation of ownership, lawful basis, retention periods and processing purposes for key business data assets.
- Ensure GDPR accountability obligations are embedded within enterprise data cataloguing initiatives.
Customer Insight and Commercial Opportunities
- Advise on the lawful use of customer data for analytics, profiling, segmentation, AI and commercial initiatives.
- Advise on consent requirements, legitimate interests assessments and direct marketing obligations.
- Support responsible innovation while protecting customer rights and regulatory compliance.
AI and Emerging Technology
- Advise on the Group's AI initiatives, including generative AI tools, machine learning models and automated decision-making systems, and on the lawfulness of AI-driven processing.
- Support development of internal AI governance frameworks and policies, embedding privacy-by-design from the outset.
- Monitor developments in AI regulation and advise on their implications for the Group.
Data Breach and Incident Response
- Lead the legal response to personal data incidents and breaches, including severity assessment and advising on regulatory notification obligations.
- Manage ICO notifications within statutory timeframes and coordinate communications to affected data subjects.
- Coordinate breach response with Information Security, Compliance and Communications teams.
- Manage proactive and reactive engagement with the ICO, including regulatory investigations and formal inquiries.
Privacy Training and Awareness
- Design and deliver privacy training and awareness programmes tailored to business stakeholders across the Group.
- Support a culture of data protection through accessible, practical guidance and communications.
Knowledge, Skills and Experience Required
Knowledge
- UK GDPR and the Data Protection Act 2018; the Data (Use and Access) Act 2025 and its implications for data sharing, smart data schemes and research exemptions.
- Privacy and Electronic Communications Regulations (PECR); ICO guidance and regulatory expectations.
- EU GDPR and international privacy frameworks where applicable.
- Data Processing Agreements, International Data Transfer Agreements (IDTAs) and Standard Contractual Clauses (SCCs).
- ROPAs, Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs).
- Customer data governance, profiling, marketing permissions and consent management.
- Emerging technologies including AI, automated decision-making and data ethics.
- Enterprise data governance frameworks and how legal, compliance, technology and business functions interact.
Skills
- Pragmatic, commercially focused legal advice on complex data protection issues.
- Drafting, reviewing and negotiating contracts involving personal data processing and sharing.
- Interpreting legislation and regulatory guidance and translating it into practical business solutions.
- Influencing senior stakeholders and communicating complex legal concepts simply and accessibly.
- Building collaborative relationships across Legal, Data Protection, Technology, Information Security, Compliance and Commercial teams.
- Analysing complex data processing activities and identifying legal and privacy risks.
- Supporting strategic data governance initiatives and privacy-by-design programmes.
- Managing multiple priorities and providing responsive legal support across a diverse business.
- Sound judgement on new or high-risk data initiatives, with a solutions-first mindset that finds compliant pathways to commercial objectives.
- Qualified Solicitor (England & Wales) or equivalent.
- Minimum 5 years' post-qualification experience advising on UK data protection and privacy law.
- Experience leading or supporting enterprise or digital transformation programmes.
- Experience reviewing and negotiating commercial contracts involving personal data across multiple jurisdictions (APAC experience preferred).
- Experience leading the drafting and negotiation of Data Processing Agreements, Data Sharing Agreements, International Data Transfer Agreements, Standard Contractual Clauses, technology and outsourcing agreements, and Transfer Risk Assessments.
- Experience advising on customer data, marketing, profiling and consent management.
- Experience responding to day-to-day operational privacy queries from business stakeholders.
- Experience advising under pressure on breach assessment, notification thresholds, ICO reporting, data subject communications, investigations and remediation.
- Substantial in-house legal experience, including breach response and ICO notification.
Collinson is an equal opportunity employer and welcomes differences in all their forms including: colour, race, ethnicity, gender identity, sexual orientation, neurodivergence, family status, age, individuals with disabilities and people from all backgrounds, cultures and experiences as we strongly believe this contributes to our on-going success.
We are focused on continually evolving our purpose driven, high performing culture, providing an environment where our people have the opportunity to achieve their full potential and do interesting and meaningful work. Our company values are: Take Action, Do the right thing, One team and Be insight led. These help guide everything we do internally in terms of how we think, act and interact, right through to how we deliver value to our customers and clients.
If you need any extra support throughout the interview process, then please email us at ukrecruitment@collinsongroup.com