Data Protection and Compliance Officer

Maintel

Greater London

Hybrid

GBP 65,000 - 100,000

Full time

38 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

25 days holiday, rising to 28
Company pension scheme
Life assurance
Health care cash plan
Private medical scheme

Job summary

Maintel seeks a Data Protection and Compliance Officer to lead the Integrated Management System, drive ISO certifications, and oversee data protection governance across the organisation in the UK. You will coordinate internal/external audits, manage risk, and report compliance to senior leadership.

Ideal candidates will have strong knowledge of UK GDPR, privacy by design, DPIAs, and cross-functional governance.

Qualifications

  • Management of an Integrated Management System.
  • Maintaining multiple ISO certifications across the business.
  • Coordinating multiple internal and external audits.
  • Security Schedule management: Cyber Essentials, PCI-DSS, NHS-DSP.
  • Data protection governance including DPO responsibilities and DPIAs.

Responsibilities

  • Lead the management, maintenance, and continual improvement of the IMS.
  • Coordinate external audits, regulatory submissions and data protection activities.
  • Develop and maintain governance policies, controls and records.
  • Produce compliance dashboards and risk reporting for leadership.
  • Support supplier/customer due diligence and portal compliance.

Skills

ISO certifications
Data protection
Governance reporting
Audit coordination
Regulatory compliance

Education

Relevant degree in Law/IS/Compliance

Tools

GRC tools
Microsoft 365

Job description

The Data Protection and Compliance Officer is responsible for the development, implementation, maintenance, and continual improvement of Maintel Integrated Management System (IMS), ensuring compliance with multiple international standards, regulatory requirements, customer obligations, data protection obligations, privacy governance requirements, and governance frameworks.

The role provides leadership across certification management, corporate governance, regulatory compliance and reporting, supplier assurance, environmental reporting, information security programmes, and data protection governance. The postholder will act as the primary coordinator for internal and external audits (excluding financial audit), certification bodies, regulatory submissions, supplier assurance portals, and data protection compliance activities, ensuring that risks are managed and compliance obligations are met.

The role is accountable for maintaining certification, compliance activities and reporting relating to multiple ISO standards, Cyber Essentials, Cyber Essentials Plus, PCI-DSS, NHS-DSP, NHS Evergreen Assessment, Ecovadis, UNGC, CDP, SECR, ESOS, UK GDPR, Data Protection Act 2018, PECR, privacy governance requirements, and customer assurance requirements and portals.

  • Lead the management, maintenance, and continual improvement of the Integrated Management System.
  • Ensure effective integration of business processes across all management system standards, certifications and customer supplier portals.
  • Provide oversight of data protection governance as Data Protection Officer (DPO) ensuring privacy obligations and records are embedded across relevant business processes.
  • Develop, review, and maintain policies, procedures, standards, forms, and registers.
  • Manage document control processes and governance requirements.
  • Coordinate management reviews and continual improvement activities.
  • Produce compliance dashboards, KPI reports, and performance metrics for senior leadership.
  • Lead Operational risk management and corporate risk review and reporting
  • Management of team member focussed on Environmental aspects

ISO Certification Management

Maintain and support certification activities for:

  • ISO 9001 – Quality Management
  • ISO 14001 – Environmental Management
  • ISO 45001 – Health and Safety
  • ISO 22301 – Business Continuity Management
  • ISO 27001 – Information Security Management
  • ISO 27701 – Privacy Information Management
  • ISO 42001 – Artificial Intelligence Management Systems

Responsibilities include:

  • Internal audit planning and delivery.
  • Certification audit coordination.
  • Corrective action management.
  • Risk and opportunity management.
  • Objectives and performance monitoring.
  • Management review preparation.
  • Evidence gathering and audit readiness activities.

Governance & Compliance

  • Maintain governance frameworks, compliance registers, legal registers, and regulatory obligations.
  • Monitor relevant legislation, standards, and industry requirements.
  • Support Board, Operating Board, and management governance reporting.
  • Lead compliance improvement initiatives and governance projects.
  • Manage risk registers and compliance controls.
  • Provide subject matter expertise on regulatory and certification requirements.

Information Security & Cyber Compliance

  • Coordinate annual Cyber Essentials and Cyber Essentials Plus assessments.
  • Support PCI-DSS compliance activities and certification requirements.
  • Coordinate annual NHS-DSP submission and external audit.
  • Maintain security policies, standards, and awareness programmes.
  • Assist with customer assurance requests and security questionnaires.
  • Support security incident investigations and corrective actions.
  • Monitor control effectiveness and governance requirements.

Data Protection, Privacy Governance & DPO

  • Undertake Data Protection Officer (DPO) responsibilities in line with UK GDPR requirements, including acting independently and providing advice on data protection obligations.
  • Monitor compliance with UK GDPR, Data Protection Act 2018, PECR, organisational privacy policies, and related data protection standards.
  • Advise on and monitor Data Protection Impact Assessments (DPIAs), privacy risk assessments, records of processing activities, lawful basis assessments, and privacy by design requirements.
  • Act as a point of contact for data subjects, internal stakeholders, customers, suppliers, and the Information Commissioner’s Office (ICO) on data protection matters, where required.
  • Oversee data subject rights request processes, personal data breach assessment, investigation, reporting, remediation, and lessons learned activities.
  • Maintain data protection policies, privacy notices, retention schedules, training materials, awareness programmes, and governance reporting.
  • Support supplier and customer due diligence by reviewing data processing agreements, privacy clauses, international transfer requirements, and data protection assurance evidence.

Environmental Compliance & Sustainability Reporting

Lead the organisation's environmental compliance programme including:

  • Streamlined Energy and Carbon Reporting (SECR).
  • Energy Savings Opportunity Scheme (ESOS).
  • United Nations General Council (UNGC).
  • CDP (Formally Carbon Disclosure Project)
  • Carbon emissions data collection and reporting.
  • Climate-related reporting requirements.
  • Carbon reduction plans and Net Zero initiatives.
  • Environmental objectives, targets, and performance monitoring.
  • Customer compliance programmes, i.e. NHS Net Zero

Responsibilities include:

  • Data collection and validation.
  • Regulatory submissions.
  • Environmental performance reporting.
  • Sustainability programme support.

Manage compliance activities across multiple customer and supplier portals, including:

  • Supplier onboarding and assurance programmes.
  • Risk Ledger.
  • EcoVadis.
  • Customer compliance portals.
  • Public sector framework compliance requirements including NHS Evergreen assessment and NHS-DSP.

Responsibilities include:

  • Maintaining organisational profiles.
  • Coordinating evidence uploads.
  • Managing renewal cycles.
  • Responding to customer due diligence requests.

    Audit & Assurance

    • Develop and maintain annual internal audit programmes.
    • Arrange internal audits across business functions using external partner.
    • Coordinate external audits and regulatory inspections.
    • Track findings, non-conformities, observations, and actions.
    • Report compliance performance trends.
    • Deliver audit training and awareness activities to audit attendees.

    Stakeholder Management

    • Work with business leaders to ensure compliance requirements are embedded.
    • Liaise with certification bodies, auditors, regulators, customers, and suppliers.
    • Provide guidance and training to employees.
    • Support bids and public sector tender submissions requiring compliance evidence.

    Vacancy Type Permanent/Full Time Location Blackburn / London Job Profile Job Profile document

    Hours per week 37.5

    About Us
    Solid solutions for a dynamic world
    About us

    Maintel is a communications managed services provider. We empower our clients across the public and private sector to deliver mission critical services and achieve their workplace, service and customer experience goals.

    We consult on the design, deploy and manage network infrastructures, platforms and software, including our own, that keep ongoing operations running smoothly and dependably, protecting business as usual, at the same time being flexible enough to adapt.

    When customer, employee, the general public and regulatory expectations are ever-changing, choose Maintel. We provide progressive, solid solutions that help you succeed in a demanding, dynamic world.

    A brief history

    Maintel, founded in 1991 by Tim Mason and Angus McCaffery, started as a small operation providing telephone maintenance contracts.

    Over the years, we have grown into a major player in communications technology, achieving significant milestones such as floating on the London Stock Exchange in 2004 and completing numerous strategic acquisitions.

    These acquisitions, including Azzurri Communications and Intrinsic Technology, expanded our expertise in unified communications, cloud, and networking.

    Today, Maintel continues to transform businesses with cutting‑edge solutions like Cloud Contact Centres, Security & Connectivity and Unified Communications, positioning us as a leader in the digital‑first era.

    Purpose
    Why we exist

    Using technology to create customer experiences, services and workplaces that inspire and empower people.

    Vision
    Where we want to be

    To be the first-choice technology services partner of ambitious brands and public services, chosen because of our dependable enablement of their vision and operations.

    Mission
    How we will achieve our vision:

    We become trusted insiders within our clients’ organisations. An embedded partner working in close collaboration to deliver their workplace, service and customer experience strategies.

    We consult on the design, deploy and manage solid technology solutions – mission critical infrastructure, platforms and applications that ensure our clients businesses run efficiently and securely, achieving their ambitions, while always being ready to adapt.

    Benefits

    Your Benefits

    Standard Benefits

    • 25 days holiday, rising to 28 days, plus bank holidays
    • Company pension scheme
    • Life assurance
    • Enhanced sick pay
    • Health care cash plan
    • Private medical scheme (self and family)*
    • Income protection scheme
    • Employee assistance line
    • Discounts and cashback on shopping
    • Discounted YorkTest home kits
    • Free car parking (Blackburn site)

    Flex Benefits

    • Holiday trading
    • Critical illness cover
    • ULEV car leasing scheme
    • Cycle to work scheme
    • Gym membership
    • Car breakdown cover
    • Will writing service

    Compensation

    • Annual salary review
    • Bonus and commission arrangements*
    • Car allowances*
    • Recruitment referral scheme
    • Various recognition schemes (e.g. long service awards)

    * Role Dependent

    Working Environment

    • Modern offices with collaboration/meeting spaces
    • Agile/remote working
    • Technology to support agile/remote working
    • Free tea, coffee, juices and snacks at offices

    Development

    • Supported study
    • Apprentice schemes
    • Levy funded learning opportunities
    • Individual development plans
    Skills
    • Strong compliance and governance knowledge.
    • Excellent audit and investigative skills.
    • Ability to interpret standards and legislation and align to practical business requirements.
    • Strong understanding of UK GDPR, Data Protection Act 2018, PECR, DPO responsibilities, privacy governance, DPIAs, data subject rights, and personal data breach management.
    • Strong report writing and documentation skills.
    • Excellent stakeholder engagement skills.
    • Project management capability.
    • Analytical and data-driven approach.
    • Strong attention to detail.
    • Ability to influence and drive continual improvement.

    Essential

    • Management of an Integrated Management System.
    • Maintaining multiple ISO certifications.
    • Coordinating multiple internal and external audits.
    • Security Schedule management: Cyber Essentials, Cyber Essentials Plus, PCI-DSS, NHS-DSP
    • Data protection governance experience, including undertaking DPO responsibilities, DPIAs, data subject rights, privacy notices, records of processing activities, and personal data breach processes.
    • Risk management and governance reporting.
    • Regulatory compliance interpretation and implementation.

    Desirable

    • Supplier assurance and customer compliance portals.
    • Environmental reporting including SECR, UNGC, CDP and ESOS.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Protection and Compliance Officer
Data Protection and Compliance Officer

Maintel • Blackburn

Hybrid
GBP 70,000 - 110,000
Security & Systems Account Manager
Security & Systems Account Manager

Mitie Cleaning & Hygiene Services • Greater London

On-site
GBP 70,000 - 110,000
Assistant Manager – Information Security
Assistant Manager – Information Security

Jobtailor • Greater London

Hybrid
GBP 70,000 - 95,000
Compliance & IMS Lead
Compliance & IMS Lead

TVS SCS • Euxton

Hybrid
GBP 70,000 - 110,000
Pension scheme
Life assurance
25 days holiday + 8 bank holidays
+5
Senior Data Privacy Consultant
Senior Data Privacy Consultant

Beyond • Manchester

On-site
GBP 85,000 - 125,000
Private medical Insurance
Death in Service (4x salary)
Flexible working options
Senior Data Privacy Consultant
Senior Data Privacy Consultant

Bynd Limited • Manchester

Hybrid
GBP 50,000 - 70,000
Competitive base salary
Matching pension scheme
Discretionary company bonus
+3
Account Manager
Account Manager

Mitie Cleaning & Hygiene Services • Gloucester

On-site
GBP 24,000 - 40,000
Salary Finance
Choices lifestyle benefits
MiDeals discounts
+1
Head of IT Services
Head of IT Services

Jobtailor • Harlow

On-site
GBP 90,000 - 130,000
Security Systems & ICT Infrastructure Engineer
Security Systems & ICT Infrastructure Engineer

MOTT MACDONALD • Birmingham

On-site
GBP 85,000 - 110,000
Private medical insurance
Pension scheme
Annual bonus scheme
+3
IT Operations Manager
IT Operations Manager

METCloud • Birmingham

On-site
GBP 65,000 - 90,000
Salary negotiable
25 days annual holiday + bank holidays
Company pension scheme (after the quar
+1