SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Affirm is reinventing credit to make it more honest and friendly, offering buy-now-pay-later solutions without hidden fees or compounding interest. The Legal, Compliance, and Public Affairs team combines legal, compliance, and policy expertise to guide growth, shape products, and build trust across the ecosystem.
This Manager role leads UK regulatory compliance and privacy oversight for Affirm's UK entity. You will serve as the operational lead for UK privacy compliance and act as the designated Data Protection Officer (DPO), subject to organizational and regulatory approvals. Key responsibilities include:
- Lead and oversee UK privacy governance activities including Data Protection Impact Assessments (DPIAs), privacy risk assessments, incident and breach governance, data subject rights processes, retention and deletion governance, and regulatory documentation.
- Develop and maintain the firm's Privacy Compliance Monitoring Programme (CMP), ensuring alignment with risk appetite, regulatory landscape, and market conditions.
- Lead the regulatory input of the firm's Management Information (MI) dashboard for Privacy, tracking consumer outcomes and privacy requirement compliance.
- Support enterprise-wide compliance risk assessment and control inventory, identifying opportunities and working with internal and external partners.
- Translate legal and regulatory requirements into compliance standards, governance routines, and program requirements for first-line stakeholders.
- Design, implement, and continuously improve the UK regulatory compliance framework across privacy, conduct, and consumer protection areas, including vulnerable customer protections.
- Provide second-line challenge and oversight of first-line control environments, reviewing control design, identifying gaps, and tracking remediation.
- Maintain governance processes for UK compliance issues management, risk assessments, control oversight, and reporting.
- Support internal audit, external audit, regulatory inquiries, and external partner reviews.
- Prepare recurring management reporting and governance materials for senior leadership.
- Partner with Legal, Product, Engineering, Operations, and Risk to operationalize UK privacy and regulatory requirements effectively.
- Coordinate with regional and global Compliance partners to ensure consistency in governance standards and documentation.
- Identify and implement improvements to compliance processes, governance routines, and oversight tools.