LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Data Privacy Manager

ExperiencedNo visa sponsorship
Zopa logo

at Zopa

FinTech

Posted 12 days ago

No clicks

Data Privacy Manager: Lead Zopa's Data Privacy function, advising on UK GDPR & product changes. Manage team, incidents, DSARs, & build partnerships across tech, legal, risk & commercial teams. Drive privacy enforcement & PCI DSS, with deep UK privacy law knowledge. Requires strategic mindset & experience in evolving privacy maturity. Hybrid role, 2-3 days/week London.

Compensation
Not specified GBP

Currency: £ (GBP)

City
London
Country
United Kingdom

Full Job Description

Our Story
 
Hello there. Were Zopa.
 
We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank. A bank that listens to what our customers dont like about finance and does the opposite. Were redefining what it feels like to work in finance. Our vision for a new era of banking puts people front and centre weve built a business that empowers everyone to aim high, every day, to move finance forward. Find out more about our fantastic offerings at Zopa.com! 
 
Were incredibly proud of our achievements and none of it would be possible without the amazing team here. Its not just industry awards were winning, weve also been named in the top three UKs Most Loved Workplaces. 
 
If you embrace unconventional challenges, are unafraid to think differently and are driven to make an outsized impact, youll thrive here at Zopa, so join us, and make it count. Want to see us in action? Follow us on Instagram @zopalife

The Team

Youll join the Data Privacy function within Operational Risk & Compliance. The function serves the whole of Zopa, helping
teams across the business make confident, well-reasoned decisions about customer data. Within the wider function, the
Operational Risk & Compliance teams also support product and business activity including current accounts, savings,
investments and marketing.

The Role

As Data Privacy Manager, youll lead the teams strategic and day-to-day work, managing a Data Privacy Associate and
partnering closely with product, technology, legal, risk, security and commercial colleagues. Youll help evolve a privacy
capability that is rigorous where it needs to be and practical everywhere it can be. There is also an opportunity to help build
the functions PCI DSS capability over time.

Key Responsibilities

  • Advise product and business teams on privacy implications of new products, changes and customer journeys.
  • Translate UK privacy law into clear, proportionate recommendations that enable responsible decisions.
  • Support the development of the data privacy governance framework, from DPIAs and privacy by design to retention, ROPA and third-party diligence.
  • Manage complex privacy incidents, including regulatory notification and engagement with affected individuals where required.
  • Oversee high-quality, timely handling of DSARs, erasure requests and objections.
  • Build trusted partnerships across technology, legal, risk, security and commercial functions.
  • Develop your direct report and strengthen privacy awareness across the business.
  • Contribute to the Banks approach to data risk across a broad range of business activity
  • Experience

  • Bring deep practical knowledge of UK GDPR, the Data Protection Act 2018 and wider UK privacy regulation.
  • Apply privacy law proportionately in a commercial environment and give pragmatic, business-enabling advice.
  • Make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs the actual privacy risk.
  • Have helped develop a data protection function in an organisation with evolving privacy maturity.
  • Design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA and third-party due diligence.
  • Manage data breaches and privacy incidents end-to-end, including ICO notification where required.
  • Handle data-subject rights requests with quality, timeliness and defensible decisions.
  • Build credibility with business, technology, legal, risk and security stakeholders.
  • Lead and develop high-performing teams with accountability and continuous improvement.
  • Nice to haves

  • Bring hands-on PCI DSS knowledge and want to help build this capability across the function.
  • Know PCI DSS requirements and their practical application in financial services or payments.
  • Assess cardholder-data flows, scope boundaries and control gaps as part of broader data-risk reviews.
  • Have contributed to PCI DSS compliance programmes.
  • Understand regulated financial services and how privacy obligations interact with FCA and PRA expectations.
  • Comfortably influence senior executives and handle challenging conversations.
  • Bring exposure to another risk discipline, such as compliance or operational risk
  • Experience using OneTrust to manage data privacy obligations
  • #LI-JR1

    At Zopa we value flexible ways of working.

    We value face-to-face collaboration and a good work-life balance. This hybrid role requires you to come to our London office 2-3 days a week.

    You'll also have the option of working from abroad for up to 120 days a year!* But no matter where you are, well make sure youve got everything you need to thrive, both in your work and home life, from day one.

    *Subject to having the right to work in the country of choice

     

    Diversity Statement

    Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives, and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments. 

     

    Our approach to AI in interviews

    At Zopa, AI isn't something we're testing out it's part of how we work every day. As a proud partner of Jobs 2030, we're committed to building AI fluency across our workforce, and we expect Zopians to use AI as part of how they do their jobs. 

    Because of that, we want to be transparent about how we think about AI use during our hiring process. 

    Behavioural and competency-based interviews: please don't use AI. These conversations are designed to understand you  your experiences, your judgment, and how you've approached real situations. An AI-generated answer can't tell us that. What it can do is get in the way of us finding out whether we're the right fit for each other. 

    Technical interviews: it depends on the role. Some technical stages actively welcome AI use, others don't. Your Talent Partner will let you know what's expected at each stage. Where AI is part of the assessment, we'll be interested not just in the outcome, but in how you used it the tools you chose, your reasoning, and the decisions you made along the way. 

    Data Privacy Manager

    Compensation

    Not specified GBP

    City: London

    Country: United Kingdom

    Zopa logo
    FinTech

    12 days ago

    No clicks

    at Zopa

    ExperiencedNo visa sponsorship

    Data Privacy Manager: Lead Zopa's Data Privacy function, advising on UK GDPR & product changes. Manage team, incidents, DSARs, & build partnerships across tech, legal, risk & commercial teams. Drive privacy enforcement & PCI DSS, with deep UK privacy law knowledge. Requires strategic mindset & experience in evolving privacy maturity. Hybrid role, 2-3 days/week London.

    Full Job Description

    Our Story
     
    Hello there. Were Zopa.
     
    We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank. A bank that listens to what our customers dont like about finance and does the opposite. Were redefining what it feels like to work in finance. Our vision for a new era of banking puts people front and centre weve built a business that empowers everyone to aim high, every day, to move finance forward. Find out more about our fantastic offerings at Zopa.com! 
     
    Were incredibly proud of our achievements and none of it would be possible without the amazing team here. Its not just industry awards were winning, weve also been named in the top three UKs Most Loved Workplaces. 
     
    If you embrace unconventional challenges, are unafraid to think differently and are driven to make an outsized impact, youll thrive here at Zopa, so join us, and make it count. Want to see us in action? Follow us on Instagram @zopalife

    The Team

    Youll join the Data Privacy function within Operational Risk & Compliance. The function serves the whole of Zopa, helping
    teams across the business make confident, well-reasoned decisions about customer data. Within the wider function, the
    Operational Risk & Compliance teams also support product and business activity including current accounts, savings,
    investments and marketing.

    The Role

    As Data Privacy Manager, youll lead the teams strategic and day-to-day work, managing a Data Privacy Associate and
    partnering closely with product, technology, legal, risk, security and commercial colleagues. Youll help evolve a privacy
    capability that is rigorous where it needs to be and practical everywhere it can be. There is also an opportunity to help build
    the functions PCI DSS capability over time.

    Key Responsibilities

  • Advise product and business teams on privacy implications of new products, changes and customer journeys.
  • Translate UK privacy law into clear, proportionate recommendations that enable responsible decisions.
  • Support the development of the data privacy governance framework, from DPIAs and privacy by design to retention, ROPA and third-party diligence.
  • Manage complex privacy incidents, including regulatory notification and engagement with affected individuals where required.
  • Oversee high-quality, timely handling of DSARs, erasure requests and objections.
  • Build trusted partnerships across technology, legal, risk, security and commercial functions.
  • Develop your direct report and strengthen privacy awareness across the business.
  • Contribute to the Banks approach to data risk across a broad range of business activity
  • Experience

  • Bring deep practical knowledge of UK GDPR, the Data Protection Act 2018 and wider UK privacy regulation.
  • Apply privacy law proportionately in a commercial environment and give pragmatic, business-enabling advice.
  • Make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs the actual privacy risk.
  • Have helped develop a data protection function in an organisation with evolving privacy maturity.
  • Design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA and third-party due diligence.
  • Manage data breaches and privacy incidents end-to-end, including ICO notification where required.
  • Handle data-subject rights requests with quality, timeliness and defensible decisions.
  • Build credibility with business, technology, legal, risk and security stakeholders.
  • Lead and develop high-performing teams with accountability and continuous improvement.
  • Nice to haves

  • Bring hands-on PCI DSS knowledge and want to help build this capability across the function.
  • Know PCI DSS requirements and their practical application in financial services or payments.
  • Assess cardholder-data flows, scope boundaries and control gaps as part of broader data-risk reviews.
  • Have contributed to PCI DSS compliance programmes.
  • Understand regulated financial services and how privacy obligations interact with FCA and PRA expectations.
  • Comfortably influence senior executives and handle challenging conversations.
  • Bring exposure to another risk discipline, such as compliance or operational risk
  • Experience using OneTrust to manage data privacy obligations
  • #LI-JR1

    At Zopa we value flexible ways of working.

    We value face-to-face collaboration and a good work-life balance. This hybrid role requires you to come to our London office 2-3 days a week.

    You'll also have the option of working from abroad for up to 120 days a year!* But no matter where you are, well make sure youve got everything you need to thrive, both in your work and home life, from day one.

    *Subject to having the right to work in the country of choice

     

    Diversity Statement

    Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives, and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments. 

     

    Our approach to AI in interviews

    At Zopa, AI isn't something we're testing out it's part of how we work every day. As a proud partner of Jobs 2030, we're committed to building AI fluency across our workforce, and we expect Zopians to use AI as part of how they do their jobs. 

    Because of that, we want to be transparent about how we think about AI use during our hiring process. 

    Behavioural and competency-based interviews: please don't use AI. These conversations are designed to understand you  your experiences, your judgment, and how you've approached real situations. An AI-generated answer can't tell us that. What it can do is get in the way of us finding out whether we're the right fit for each other. 

    Technical interviews: it depends on the role. Some technical stages actively welcome AI use, others don't. Your Talent Partner will let you know what's expected at each stage. Where AI is part of the assessment, we'll be interested not just in the outcome, but in how you used it the tools you chose, your reasoning, and the decisions you made along the way.