As a leading, global financial information services provider, Fitch Group delivers vital credit and risk insights, robust data, and dynamic tools to champion more efficient, transparent financial markets. With over 100 years of experience and colleagues in over 30 countries, Fitch Group’s culture of credibility, independence, and transparency is embedded throughout its structure, which includes Fitch Ratings, one of the world’s top three credit ratings agencies, and Fitch Solutions, a leading provider of insights, data and analytics. With dual headquarters in London and New York, Fitch Group is owned by Hearst.
Fitch's Technology & Data Team is a dynamic department where innovation meets impact. Our team includes the Chief Data Office, Chief Software Office, Chief Technology Office, Emerging Technology, Shared Technology Services, Technology, Risk and the Executive Program Management Office (EPMO). Driven by our investment in cutting-edge technologies like AI and cloud solutions, we’re home to a diverse range of roles and backgrounds united by a shared passion for leveraging modern technology to drive projects that matter to our organization and clients. We are also proud to be recognized by Built In as a Best Place to Work in Technology 3 years in a row. Whether you're an experienced professional or just starting your career, we offer an exciting and supportive environment where you can grow, innovate, and make a difference.
Want to learn more about a career in technology and data at Fitch? Visit: https://careers.fitch.group/content/Technology-and-Data/?locale=en_US
Fitch Group is currently seeking a Director, Data Privacy with strong experience in global privacy compliance, customer-facing digital products and services, online tracking technologies, and privacy support for digital business models.
The Fitch Group Data Privacy Office is responsible for developing, implementing, and maintaining data privacy policies, procedures, and initiatives across all departments and subsidiaries of the organization. This dynamic team ensures compliance with global data protection regulations while fostering a culture of privacy and data protection awareness. This role will provide senior-level privacy support for customer-facing digital products and services, acquired businesses, digital initiatives, and online tracking compliance across multiple jurisdictions.
What We Offer
- Opportunity to expand your technical and legal knowledge in the global world of data privacy.
- Contribute to meaningful projects and initiatives that impact Fitch’s global operations and compliance with global data protection regulations.
- Working with a diverse and inclusive Company that values collaboration, innovation, and respect for individual perspectives and intercultural experience.
We’ll Count On You To
- Lead and provide senior-level privacy guidance for customer-facing digital products and services, acquired entities, online products and services, and other digital initiatives requiring tailored privacy support, working collaboratively with cross-functional stakeholders to identify issues, align on practical solutions, and drive matters forward independently.
- Provide practical, risk-based privacy advice, research, and recommendations to business, product, marketing, technology, Compliance, Risk, and Legal stakeholders, including the ability to suggest proportionate controls that address privacy requirements while supporting business objectives and operational feasibility.
- Report to the Fitch Group Data Privacy Manager to advise the Chief Information Security Officer and support senior stakeholders by monitoring privacy compliance trends, emerging regulatory requirements, and implementation impacts across global digital business activities.
- Manage privacy assessments and compliance activities, including vendor and supplier privacy reviews, privacy-related contract reviews, data processing agreements, cross-border data transfer analysis, transfer impact assessments, and region-specific compliance considerations for regions where Fitch is subject to privacy requirements.
- Own and support website and online tracking compliance, including cookie and similar technology governance, consent collection for account creation and contact forms, coordination with shared technology platforms, and ongoing maintenance of related privacy controls.
- Establish, maintain, and improve privacy programs for customer-facing digital products and services and acquired businesses, including privacy-by-design support for product, marketing, customer engagement, and digital transformation initiatives.
- Provide senior-level support for U.S.-based stakeholders and team members across time zones, including business partnership during U.S. business hours, proactive collaboration with stakeholders, independent problem solving on complex privacy matters, and guidance to junior team members on implementation questions.
How You’ll Make An Impact
- Global privacy advisory, with the ability to provide practical, risk-based guidance across multiple jurisdictions, including EU/UK GDPR, U.S. state privacy laws, and other international privacy frameworks.
- Digital products and online tracking compliance, including privacy support for customer-facing digital services, websites, consent management, cookies, similar tracking technologies, and marketing-related data use.
- Privacy-by-design and implementation, with the ability to translate legal and regulatory requirements into practical controls, workflows, and implementation steps for product, technology, marketing, and business teams.
- Commercial and cross-functional judgment, including the ability to balance privacy requirements with business objectives, operational feasibility, customer experience, and proportionate risk management.
- Stakeholder management and influence, with the ability to build trusted relationships and collaborate effectively with Legal, Compliance, Risk, Technology, Product, Marketing, and business stakeholders.
- Independent problem solving and senior-level leadership, including sound judgment on complex privacy matters, ability to drive work forward across time zones, and willingness to guide on implementation questions.
You May Be a Good Fit If
- Strong understanding of global privacy laws and regulatory expectations, including EU/UK GDPR, US State and other privacy frameworks relevant to customer-facing digital products and services and cross-border business activities.
- Ability to work independently, exercise sound judgment, solve complex and ambiguous privacy problems with limited direction, and translate legal and regulatory requirements into practical, risk-based privacy implementation steps and controls for business and technology teams.
- Experience advising privacy compliance for online products and services, website tracking technologies, consent management, marketing activities, customer-facing digital journeys, and privacy-by-design processes.
- Experience with cross-border data transfer compliance, transfer impact assessments, and privacy requirements in key international regions, including APAC markets and China-related compliance considerations.
- Risk assessment experience with AI processing of personal data and sensitive personal data
- Experience