SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Zopa is a fintech company founded in 2005 as the first peer-to-peer lending platform, now operating as Zopa Bank—a customer-centric digital bank redefining financial services. You'll join the Data Privacy function within Operational Risk & Compliance, serving the entire organization to help teams make confident decisions about customer data.
As Data Privacy Manager, you will lead the data privacy team's strategic and day-to-day operations, managing a Data Privacy Associate and collaborating closely with product, technology, legal, risk, security, and commercial colleagues. Your role is to evolve a privacy capability that is rigorous where necessary and practical everywhere else. You'll also have the opportunity to help build the function's PCI DSS capability over time.
Key responsibilities include:
- Advising product and business teams on privacy implications of new products, changes, and customer journeys
- Translating UK privacy law into clear, proportionate recommendations that enable responsible business decisions
- Supporting development of the data privacy governance framework, including DPIAs, privacy by design, retention policies, ROPA, and third-party diligence
- Managing complex privacy incidents, including regulatory notification and engagement with affected individuals
- Overseeing high-quality, timely handling of DSARs, erasure requests, and objections
- Building trusted partnerships across technology, legal, risk, security, and commercial functions
- Developing your direct report and strengthening privacy awareness across the business
- Contributing to the bank's approach to data risk across business activities
The role is hybrid, requiring 2-3 days per week in the London office, with flexibility to work abroad up to 120 days annually (subject to work authorization).
REQUIREMENTS:
- Deep practical knowledge of UK GDPR, the Data Protection Act 2018, and wider UK privacy regulation
- Ability to apply privacy law proportionately in a commercial environment with pragmatic, business-enabling advice
- Demonstrated ability to make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs actual privacy risk
- Experience helping develop a data protection function in an organization with evolving privacy maturity
- Proven ability to design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA, and third-party due diligence
- Experience managing data breaches and privacy incidents end-to-end, including ICO notification where required
- Track record of handling data-subject rights requests with quality, timeliness, and defensible decisions
- Ability to build credibility with business, technology, legal, risk, and security stakeholders
- Leadership experience developing high-performing teams with accountability and continuous improvement focus
NICE TO HAVES:
- Hands-on PCI DSS knowledge and interest in building this capability
- Understanding of PCI DSS requirements and practical application in financial services or payments
- Experience assessing cardholder-data flows, scope boundaries, and control gaps
- Contribution to PCI DSS compliance programs
- Understanding of regulated financial services and how privacy obligations interact with FCA and PRA expectations
- Comfort influencing senior executives and handling challenging conversations
- Exposure to another risk discipline such as compliance or operational risk
- Experience using OneTrust to manage data privacy obligations