Reporting to: Director of Regulatory Compliance & Data Protection Officer
Department: Compliance
Location: London
Purpose of role: This role will advise and assist in dealing with regulatory compliance and data protection matters
Hours: Permanent, full-time
Reviewed: August 2026
The role:
We are looking for an experienced data protection lawyer or professional to join our Compliance team, supporting the firm's data protection, regulatory compliance and risk management functions.
This is an opportunity to work at the intersection of data protection, AI governance, confidentiality, professional conduct and regulatory compliance within a leading law firm.
Job responsibilities:
Data Protection & Privacy
- Supporting the Data Protection Officer in the delivery of the firm’s data protection
- Day to day responsibility for delivering the data protection framework compliance programme under the DPO’s supervision including:
- Maintaining the firm’s records of processing activities, related data inventories and other required data protection records and registers, policies, notices and procedures.
- Managing data breaches, incidents and regulatory risk assessments.
- Managing data subject rights requests and ensuring timely responses.
- Monitoring compliance with the firm’s data protection framework, testing controls, identifying gaps and tracking improvement actions, with regular reporting to the DPO and relevant governance bodies
- Advising on and supporting compliance with data minimisation, retention and secure deletion requirements.
- Advising on data protection matters for new and existing systems, projects, technology and suppliers, including:
- Assessing supplier (privacy-related) due diligence and keeping under review where applicable.
- Reviewing and advising on DPIAs, LIAs, international transfer, appropriate safeguards and Transfer Risk Assessments as applicable.
- Reviewing commercial and supplier contracts, including data processing and data sharing arrangements.
- Advising generally on UK GDPR and Data Protection Act 2018 related queries.
- Delivering data protection training, guidance and compliance improvement initiatives.
- Advise on the responsible use of AI and emerging technologies.
- Assess AI-related privacy, confidentiality and regulatory risks.
- Support AI governance, supplier assessments and control frameworks.
- Advise on the overlap between AI, data protection and SRA regulatory obligations
General Advisory and Regulatory Support
- Support client engagement, retainer and complaint-related matters, assist with regulatory engagement and compliance projects and support audits, reporting, training and continuous improvement activities, with a focus on data protection and AI governance.
Essential skills and qualifications:
We welcome applications from qualified lawyers or experienced privacy professionals with appropriate privacy, information governance, risk or compliance experience.
Candidates should be able to demonstrate:
- Experience taking day to day ownership of and driving forward an organisational data protection programme at managerial level.
- Strong hands-on experience managing data breaches, subject rights requests, privacy risk assessments and data protection records, policies, controls and procedures.
- Experience reviewing and advising on contracts in relation to data protection and AI considerations.
- Awareness of AI governance and the legal, ethical and regulatory issues arising from AI use.
- Understanding of confidentiality, professional conduct and regulatory obligations within a regulated environment.
- A proactive, self-starting approach with the confidence to work with minimal supervision.
- Ability to manage competing priorities, exercise sound judgement on when to escalat matters and coordinate data protection input across relevant business
- and operational teams.
- Strong analytical skills, sound judgement.
- Excellent communication with the ability to deliver pragmatic, commercially focused advice and work effectively with colleagues at all levels.
- Experience within a law firm, legal services, professional services or other regulated environment.
- Experience supporting compliance audits, regulatory reviews or governance programmes.
- Familiarity with recognised governance and risk frameworks, such as ISO 27001, LOCS, ISO 42001, NIST AI RMF.
- A recognised data protection or privacy qualification, such as CIPP/E, CIPM or an equivalent qualification.
This is an excellent opportunity to develop a broad compliance practice spanning data protection and AI governance as it intersects with professional regulation and risk management within a highly respected law firm. You will work closely with senior stakeholders and play a key role in supporting the firm's regulatory and compliance objectives.
Outstanding candidates who may not meet some or all of the listed skills may still be considered if they can demonstrate proven, comprehensive, and relevant experience that aligns to the role.