Privacy & Data Governance Manager

Byoma

Glasgow

On-site

GBP 65,000 - 100,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

BYOMA in Glasgow, UK is seeking a hands-on Privacy & Data Governance Manager to own the day-to-day privacy programme and help build the governance framework as the data estate grows. You will manage the Record of Processing Activities, data mapping, DPIAs and vendor due diligence.

Working with the Head of Data & BI, you will translate complex legal requirements into practical processes and embed privacy across the business, including marketing, e-commerce and operations at a fast-growth beauty

Qualifications

  • Three+ years in privacy, data protection, or compliance.
  • Strong UK GDPR, EU GDPR, and PECR knowledge.
  • Experience handling DSARs end to end.
  • Experience maintaining ROPA and data inventories.
  • Ability to translate legal requirements into practical processes.

Responsibilities

  • Own and maintain privacy records, mappings and DPIAs.
  • Manage end-to-end data subject rights requests.
  • Coordinate cross-functional privacy controls and governance.
  • Lead vendor due diligence and DPAs.
  • Collaborate with Data & BI to evolve governance standards.
  • Develop data classification and retention practices.

Skills

Privacy
Data Governance
UK GDPR
DSARs
Vendor Due Diligence

Education

Relevant professional qualification in privacy/Data governance

Tools

Microsoft Purview
Microsoft 365

Job description

Hi, we’re BYOMA

We’re one of the world’s fastest growing beauty brands.We have applied the research, science, and credibility of dermatologist-backed brands and supercharged it with the efficiency and results of clinically effective, ingredient-led brands.

We’re** on **a mission to democratize and demystify beauty by empowering consumers to make smart, informed and educated choices.

BYOMA was built on four fundamental principles; Efficacy,Accessibility, Education, Engagement , and these inform, inspire and underpin everything we do. We’re committed to delivering the most efficacious products to our consumer and our dedication to accessibility and education have led to us becoming the #1 fastest growing skincare brand in the world, and a top 10 skincare brand across all our key retail partners.

Asapeoplepoweredbusiness,noneofthiswouldhavebeenpossible without our incredible teamwho are committed to achieving our BYOMA** **vision: to build better beauty and inspire positive change.

Join us as we build an inclusive community, because let’s face it, barriers aren’t beneficial for anything other than your skin.

Privacy & Data Governance Manager
IT, Data & Business Intelligence
Head of Data & BI / Data Protection Officer
Role Banding

3

Location

Glasgow, UK Head Office

Direct Reports (Number + Title)

0

BYOMA is growing quickly across multiple markets, systems and customer touchpoints. That makes privacy and data governance more than a compliance requirement. It is part of how we protect customer trust, make better decisions and scale responsibly.

BYOMA’s data function is young and growing. Although small, we deliver enterprise grade capability and transformation and were recently nominated for Data Team of the Year at the British Data Awards.As we scale, we need a hands‑on Privacy & Data Governance Manager to take operational ownership of our privacy programme and help build the governance framework around our growing data estate.

This is a delivery role, not a purely advisory one. You will own the day-to-day running of our privacy compliance, including our Record of Processing Activities, data subject and consumer rights requests, privacy notices, DPIAs, vendor due diligence and core privacy documentation. Alongside this, you will help define and maintain the governance standards that shape how BYOMA classifies, retains, accesses and controls data across the business. The role works closely with the Head of Data & BI, who is also BYOMA’s Data Protection Officer. The DPO sets direction and retains statutory responsibility. You make the programme run. Privacy and data governance are closely connected at BYOMA. A good ROPA, clear data maps and a useful data catalogue all depend on understanding what data we hold, where it moves, who has access to it, how long we keep it and why. This role brings those activities together, so our documentation, controls and ways of working stay current as the business grows.

RECORDS, DATA MAPPING AND PRIVACY DOCUMENTATION
  • Own and maintain BYOMA’s Record of Processing Activities, ensuring it reflects how the business uses personal data.
  • Maintain associated registers, including the sub-processor register and data protection documentation.
  • Map personal data flows across business areas, systems, vendors and jurisdictions.
  • Document what data we hold, where it is processed, who it is shared with, the lawful basis for processing and any international transfer considerations.
  • Keep documentation to the standard expected under UK GDPR Article 30 and equivalent consumer privacy disclosure expectations in relevant US markets.
  • Work with business teams so privacy documentation is updated as systems, vendors, processes and marketing activities change.
DATA GOVERNANCE
  • Own and maintain BYOMA’s data classification approach, ensuring the sensitivity of key data assets is documented and understood.
  • Develop and maintain retention schedules, working with system owners to ensure they are practical and applied.
  • Coordinate periodic access reviews across key platforms so permissions reflect current business roles and responsibilities.
  • Work with the DPO to define governance standards for classification, retention, access control, data ownership and documentation, and own them day to day once agreed.
  • Support the development of Microsoft Purview, or equivalent tooling, as the backbone for classification, retention, eDiscovery, DLP and data governance.
  • Coordinate a lightweight data governance forum so decisions about data are made deliberately and consistently.
  • Work closely with data engineering so governance requirements are understood and built into how the data platform operates.
USER RIGHTS AND CONSUMER REQUESTS
  • Own the end-to-end handling of data subject access requests and consumer rights requests.
  • Manage requests relating to access, deletion, correction, restriction, objection and relevant US consumer rights.
  • Ensure requests are handled within statutory timeframes and in line with BYOMA’s documented processes.
  • Verify requester identity and manage authorised agent requests appropriately.
  • Build and refine repeatable processes so request handling remains consistent as volumes grow.
  • Keep records of requests, decisions and outcomes.
POLICIES, NOTICES AND ASSESSMENTS
  • Maintain and update BYOMA’s privacy policies, notices and disclosures across the UK, EU and US, keeping them accurate as law and practice evolve.
  • Keep cookie notices, consent records and marketing consent documentation aligned with how the business operates.
  • Conduct DPIAs and legitimate interests assessments for new systems, tools, products, campaigns and processing activities.
  • Translate privacy requirements into practical business actions.
  • Work with the DPO and external advisers where specialist legal advice is required.
VENDORS, CONTRACTS AND THIRD PARTIES
  • Conduct privacy and data protection due diligence on vendors and processors.
  • Review data processing agreements and support contract review from a privacy and governance perspective.
  • Maintain oversight of processors and sub-processors.
  • Work with legal, procurement and business owners to ensure vendor processing is documented, risk‑assessed and appropriately controlled.
  • Support international transfer assessments where relevant.
US PRIVACY DEVELOPMENTS
  • Track US state privacy developments that may affect BYOMA, including CCPA/CPRA and other relevant consumer privacy laws.
  • Coordinate with the DPO and external advisers to understand the practical implications for BYOMA.
  • Translate US privacy requirements into practical process updates, notices and disclosures, working with the DPO and external advisers where needed.
  • Support a risk‑based approach to reducing privacy, regulatory and customer trust risks.
TRAINING, AWARENESS AND BUSINESS PARTNERSHIP
  • Work with teams across marketing, e-commerce, customer service, sales, operations, IT and data to embed privacy and good data practice into day‑to‑day work.
  • Design and deliver practical privacy and data‑handling training.
  • Help colleagues understand when to involve privacy, how to handle personal data and how to elevate issues.
  • Promote a culture where personal data and business data are managed responsibly.
RISK, INCIDENTS AND REGULATORY CHANGE
  • Support breach and incident response, including logging, initial assessment, evidence gathering and escalation to the DPO.
  • Assist the DPO with notification assessments and documentation.
  • Monitor relevant developments in UK, EU and US privacy law.
  • Flag changes that could affect BYOMA’s processes, policies, vendors or customer‑facing disclosures.
  • Support audit readiness and ongoing improvement of BYOMA’s privacy and governance controls.
What were looking for:
Essential
  • Three or more years’ experience in a privacy, data protection, information governance or compliance role.
  • Strong working knowledge of UK GDPR, EU GDPR and PECR.
  • Practical experience handling DSARs or equivalent rights requests end to end.
  • Experience maintaining a ROPA, data inventory, processing register or equivalent documentation.
  • Experience documenting how data moves through a business — systems, vendors, teams and purposes — rather than working from documentation someone else produced.
  • Ability to turn legal, technical or policy requirements into practical business processes.
  • Comfortable working with vendors, reviewing DPAs and coordinating privacy input into supplier assessments.
Desirable
  • Experience with US privacy law, particularly CCPA/CPRA.
  • Awareness of other US state consumer privacy laws or biometric privacy requirements.
  • CIPP/E, CIPM or CIPP/US certification, or actively working towards one.
  • Practical data governance experience — cataloguing, classification, retention scheduling, access reviews or governance forums.
  • Experience working in a Microsoft 365 environment, including SharePoint and Teams.
  • Experience with Microsoft Purview for classification, retention, eDiscovery, DLP or data governance.
  • Experience in e‑commerce, retail, FMCG, beauty, consumer goods or a consumer brand.
  • Familiarity with analytics and marketing technology — GA4, consent management platforms, advertising pixels or CRM.
  • Data analysis knowledge, or confidence working alongside data engineers and technical teams.
  • Experience delivering training or awareness programmes.
  • Exposure to a multi‑entity or international group structure.
Equal opportunities for everyone

BYOMA is an equal opportunity employer. We value a culture of inclusion and diversity within our team. We are committed to maintaining a workplace free from prohibited employment conduct, including discrimination based on age, color, disability, marital or parental status, national origin, race, religion, sex, sexual orientation, gender identity, veteran status or any other legally protected status in accordance with applicable federal, state and local laws.

If you have a preferred name, please use it to apply. We don’t need full or birth names at application stage.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Project Manager, Operations
Project Manager, Operations

Byoma • Glasgow

On-site
GBP 45,000 - 65,000
Privacy & Data Governance Lead
Privacy & Data Governance Lead

Byoma • Glasgow

On-site
GBP 65,000 - 100,000
Data Privacy & AI Governance Senior Analyst
Data Privacy & AI Governance Senior Analyst

Teya Services Ltd • Greater London

On-site
GBP 65,000 - 95,000
GymPass health support
Enhanced maternity/paternity leave
Cycle-to-Work Scheme
+5
Data Privacy Manager
Data Privacy Manager

Zopa • Greater London

On-site
GBP 70,000 - 88,000
Hybrid work in London
Senior Data Privacy Consultant
Senior Data Privacy Consultant

Bynd Limited • Manchester

Hybrid
GBP 50,000 - 70,000
Competitive base salary
Matching pension scheme
Discretionary company bonus
+3
Data Protection Compliance Analyst
Data Protection Compliance Analyst

Playtech • Greater London

On-site
GBP 40,000 - 60,000
Hybrid work pattern
Head of Data Privacy and Compliance - 12 month FTC
Head of Data Privacy and Compliance - 12 month FTC

ASOS.com • Greater London

Hybrid
GBP 120,000 - 170,000
ASOS discount
Employee sample sales
25 days leave + celebratory day
+3
Data Privacy Manager
Data Privacy Manager

Zopa Bank • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid work model
Work abroad up to 120 days
Interim Privacy Legal Advisor
Interim Privacy Legal Advisor

Gofractional • Greater London

Hybrid
GBP 90,000 - 135,000
Annual learning & development budget
Private medical insurance
Dental insurance
+5
Data Protection & Privacy Consultant
Data Protection & Privacy Consultant

Addition • Greater London

Hybrid
GBP 60,000 - 70,000
Hybrid work model
Travel opportunities