SlipstreamJobsFresh Startup & VC-Backed Jobs

Data Privacy Manager

Zopa - London, United Kingdom - Hybrid - posted 2026-08-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Zopa is a fintech company founded in 2005 as the first peer-to-peer lending platform, now operating as Zopa Bank—a customer-centric digital bank redefining financial services. You'll join the Data Privacy function within Operational Risk & Compliance, serving the entire organization to help teams make confident decisions about customer data. As Data Privacy Manager, you will lead the data privacy team's strategic and day-to-day operations, managing a Data Privacy Associate and collaborating closely with product, technology, legal, risk, security, and commercial colleagues. Your role is to evolve a privacy capability that is rigorous where necessary and practical everywhere else. You'll also have the opportunity to help build the function's PCI DSS capability over time. Key responsibilities include: - Advising product and business teams on privacy implications of new products, changes, and customer journeys - Translating UK privacy law into clear, proportionate recommendations that enable responsible business decisions - Supporting development of the data privacy governance framework, including DPIAs, privacy by design, retention policies, ROPA, and third-party diligence - Managing complex privacy incidents, including regulatory notification and engagement with affected individuals - Overseeing high-quality, timely handling of DSARs, erasure requests, and objections - Building trusted partnerships across technology, legal, risk, security, and commercial functions - Developing your direct report and strengthening privacy awareness across the business - Contributing to the bank's approach to data risk across business activities The role is hybrid, requiring 2-3 days per week in the London office, with flexibility to work abroad up to 120 days annually (subject to work authorization). REQUIREMENTS: - Deep practical knowledge of UK GDPR, the Data Protection Act 2018, and wider UK privacy regulation - Ability to apply privacy law proportionately in a commercial environment with pragmatic, business-enabling advice - Demonstrated ability to make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs actual privacy risk - Experience helping develop a data protection function in an organization with evolving privacy maturity - Proven ability to design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA, and third-party due diligence - Experience managing data breaches and privacy incidents end-to-end, including ICO notification where required - Track record of handling data-subject rights requests with quality, timeliness, and defensible decisions - Ability to build credibility with business, technology, legal, risk, and security stakeholders - Leadership experience developing high-performing teams with accountability and continuous improvement focus NICE TO HAVES: - Hands-on PCI DSS knowledge and interest in building this capability - Understanding of PCI DSS requirements and practical application in financial services or payments - Experience assessing cardholder-data flows, scope boundaries, and control gaps - Contribution to PCI DSS compliance programs - Understanding of regulated financial services and how privacy obligations interact with FCA and PRA expectations - Comfort influencing senior executives and handling challenging conversations - Exposure to another risk discipline such as compliance or operational risk - Experience using OneTrust to manage data privacy obligations

Similar roles