Data Protection Officer

Card Factory plc

Wakefield

Hybrid

GBP 59,000 - 72,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Card Factory plc is seeking a UK & Ireland Data Protection Officer to shape and safeguard the privacy framework across cardfactory, funkypigeon.com and Garlanna.

You will ensure compliance with UK GDPR, EU GDPR, PECR and related legislation, acting as an independent advisor to embed privacy by design and accountability.

Qualifications

  • Substantial experience as a DPO or equivalent in privacy operations (GDPR/PECR).
  • Experience leading teams and coordinating across multiple units.
  • Familiarity with DSAR tooling and data processing technologies.
  • Knowledge of ISO 27001/27701 or related information security frameworks.
  • Ability to balance privacy requirements with commercial objectives.

Responsibilities

  • Develop and maintain a Data Protection Strategy aligned with business goals.
  • Maintain DPIAs, privacy notices, breach logs, SAR logs and related documentation.
  • Lead audits and regulatory compliance activities for UK/EU GDPR and PECR.
  • Act as primary liaison with ICO, DPC and other regulators and manage inquiries.
  • Oversee training and awareness initiatives on data protection across the organisation.
  • Advise senior leaders on privacy risks and provide mentoring to the team.
  • Manage third‑party supplier governance and privacy risk assessments.
  • Collaborate cross‑functionally to ensure consistent data protection practices.

Skills

Risk management
Influencing
Security program
Commercial focus
People management

Tools

Microsoft Purview
OneTrust
DSAR tooling

Job description

About The Role

Salary c£65,000 + benefits package

Join us as the UK & Ireland Data Protection Officer and play a pivotal role in shaping and safeguarding the privacy framework across cardfactory, funkypigeon.com and Garlanna. In this influential position, you’ll act as a trusted, independent advisor—ensuring our organisation meets its obligations under UK GDPR, EU GDPR, PECR, ePrivacy and related legislation.

You’ll lead the way in embedding a strong culture of privacy by design, guiding stakeholders at all levels, and championing accountability across our UK and Ireland operations. As the primary contact for regulators, data subjects and internal teams, you’ll oversee compliance, identify and mitigate privacy risks, and ensure robust policies and controls are in place.

If you’re ready to make a significant impact by driving a proactive, risk‑aware approach to data protection, we’d love to hear from you.

At cardfactory, we believe in smart working. That means you’ll spend around two days a week at our Wakefield support centre, with the flexibility to work from home the rest of the time.

What you’ll do:
  • Data Protection Strategy: Develop, implement and maintain a comprehensive Data Protection Strategy aligned to organisational goals and legislation. Own and update the Record of Processing Activities (ROPA).
  • Policies & Documentation: Maintain all data protection policies, procedures and documentation, including DPIAs, privacy notices, breach logs and SAR logs. Support development of the Information Security Management System.
  • Compliance Management: Lead audits and compliance activities to meet UK/EU GDPR, PECR and other regulatory requirements. Run the GDPR and data privacy steering committee.
  • Monitoring & Audit: Conduct ongoing assessments and internal audits to ensure adherence to data protection standards. Review contracts to ensure appropriate legal and technical safeguards.
  • Regulatory Liaison: Act as the primary contact for the ICO, DPC and other regulatory bodies, managing enquiries, investigations and reporting duties.
  • Incident & Breach Management: Lead breach assessments, investigations and reporting, ensuring effective mitigation, documentation and communication.
  • Training & Awareness: Design and deliver training initiatives, keeping colleagues informed on data protection requirements, risks and emerging trends.
  • Leadership: Advise senior leaders and business units on privacy risks and compliance. Provide leadership and mentoring to the team.
  • Supplier Risk Management: Oversee governance and risk assessments for third‑party suppliers to ensure compliance and security standards are met.
  • Collaboration & Consultancy: Act as the first point of contact for data privacy queries. Work cross‑functionally to ensure a consistent, business‑aligned approach to data protection.
  • Risk Management: Identify, assess and mitigate data privacy risks, ensuring clear reporting to the appropriate stakeholders.
What you’ll need:
  • Strong risk management capability and ability to deliver practical, commercially‑aware solutions.
  • Strong influencing skills (soft / hard / active listening etc.) – and the ability to blend and adapt them to the situation and intended audience.
  • Able to implement a holistic security program of strategy, policies, processes and technologies.
  • Being able to balance legislative requirements taking into consideration a commercial viewpoint
  • People management skills to direct and manage a small team of data privacy specialists.
Experience:
  • Substantial experience in a DPO role, managing privacy operations complaints with the GDPR and PECR.
  • Experience leading, developing and managing teams.
  • Familiarity with Microsoft Purview, One Trust and other similar DSAR management and tooling.
  • Experience working in fast‑paced and complex environments, working across multiple business units.
  • Experience with ISO 27001, ISO27701, ISAE 3000/3402 or other information security standards and frameworks.

There is no fixed closing date for this role, so we encourage you to apply early as we may close the vacancy once we've received enough applications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Protection Officer
Data Protection Officer

QED Legal • Greater London

Hybrid
GBP 90,000 - 125,000
Hybrid working
Excellent benefits
Career progression
Global Data Privacy Officer
Global Data Privacy Officer

Navari Talent Limited • Greater London

Hybrid
GBP 120,000 - 150,000
Bonus
Benefits package
Data Protection Manager
Data Protection Manager

LHH • Cambridge

Hybrid
GBP 50,000 - 62,000
Data Protection Officer
Data Protection Officer

Fortius Clinic • Greater London

On-site
GBP 90,000 - 120,000
Data Protection Officer
Data Protection Officer

Careers Plus • Newcastle upon Tyne

On-site
USD 53,000 - 108,000
Data Protection Consultant - DPO
Data Protection Consultant - DPO

Evalian® • United Kingdom

Hybrid
GBP 40,000 - 55,000
25 days annual leave
5% employer contribution pension scheme
Life insurance including employee assistance program
+1
Data Protection Manager
Data Protection Manager

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
In-house Data Privacy Lawyer - Part time 4 days p/w - East Mids
In-house Data Privacy Lawyer - Part time 4 days p/w - East Mids

BCL Legal • East Midlands

Hybrid
GBP 70,000 - 110,000
Deputy Data Protection Officer
Deputy Data Protection Officer

LHH • Leeds

Hybrid
GBP 47,000 - 79,000
Discretionary bonus (10% on target, up
Pension contribution up to 11%
Private medical insurance
+4
Senior Data Privacy Consultant
Senior Data Privacy Consultant

Anson McCade • Greater London

Hybrid
GBP 60,000 - 90,000
Flexible & hybrid
Competitive salary
Certifications support