Jobs

Data Protection Officer


Job details
  • The Restaurant Group
  • Greater London
  • 2 weeks ago

About us:

We're The Restaurant Group (TRG for short) and we're one of the UK's biggest hospitality businesses. Were a significant player in the UK casual dining market, operating over 400 restaurants and pubs including Wagamama,Barburrito + Brunning & Price. Our diverse portfolio of brands provides something for everyone, and we are proud to be TRG.


The Role

Working independently, the role of the Privacy Officer is to build and manage TRG and its business divisions privacy programme, to develop privacy policies for internal use and privacy statements for internal and external use, and to describe privacy requirements for business partners and service providers. The Privacy Officer will facilitate regulatory compliance by establishing and coordinating TRG’s Privacy Council. Knowing how to persuade and enable the business, while maintaining integrity, the Privacy Officer closely collaborates with business stakeholders to control risk from potential procedural or technology changes that affect privacy.


The Privacy Officer conducts privacy risk assessments, focused on specific business processes or applications. They identify and suggest prioritization of privacy risk treatment for the organisation, and determines how to maintain and improve adherence to regulatory requirements and corporate policies. The Privacy Officer will develop and maintain privacy training and awareness programmes, and set up a personal data breach response plan.

As the internal representation of regulatory authorities on the matter of privacy, the Privacy Officer is a neutral position. As a result, the role will have dual reporting into the Director of Technology and the Legal team.

The Privacy Officer may not have any conflict of interest, e.g., be responsible for business outcomes, simultaneous to the privacy officer function. It may also not be responsible for executing (parts of) the privacy programme, as such impacts the privacy officer’s neutrality.


Key Responsibilities:


  • Governance: Maintain, develop and implement TRG and its business divisions privacy programme and the resulting privacy policies, procedures and documentation for the processing of personal data in coordination with appropriate members of the organisation
  • Monitor continuous adherence to the privacy programme’s requirements
  • Establish and work with a multidisciplinary team, including audit and risk, compliance, HR, legal, business process owners, IT, Cyber Security and other internal stakeholders to ensure enterprise-wide coverage of the privacy discipline.
  • Work with procurement, supplier management and the legal department to ensure that third-party suppliers' contracts and operating-level agreements meet [international] privacy requirements.
  • Implement and maintain an internal reporting mechanism for intended (new or changed) personal data processing activities, to which business unit/process owners must adhere.
  • Notify data protection authorities of the organisation's processing activities and/or obtain guidance where required.
  • Lead the TRG's response to privacy-related emergencies and other potentially damaging events.
  • Communicate with regulatory authorities and the public concerning privacy issues (for example, answering data subject access related questions and requests).
  • Determine TRG’s specific privacy-related requirements and potential vulnerabilities.
  • Develop, improve and manage the privacy impact assessment process, in close collaboration with business stakeholders.
  • Conduct regular privacy policy compliance assessments to ensure that TRG’s privacy policies are being adhered to.
  • Ensure that business units, technology teams and third parties (service providers) follow TRG's privacy programme, implement measuring procedures to verify the extent in which these stakeholders meet privacy policy requirements and address privacy concerns.
  • Collaborate with and assist business units and technology areas to develop corrective action plans for identified privacy compliance issues..
  • Conduct frequent compliance report monitoring activities on collaborating partners, third-party service providers' and other data processors' levels of privacy compliance.
  • Support the creation of an inventory that documents how and why TRG collects, shares and uses personal data.
  • Influence TRG’s retention programme to facilitate deletion or anonymisation of personal data that is no longer needed for identified purpose(s), and in accordance with applicable requirements.
  • Serve as the internal advisor to the CIO and Technology Director to interpret privacy-policy-related questions.
  • Work closely with the technology service teams to anticipate potential privacy problems embedded in the use of emerging technologies.
  • Liaise with the Head of Service Operations and the Infrastructure and Cyber Security Manager in matters relating to data breaches
  • Conduct or oversee privacy awareness campaigns, training and orientation for all employees



Requirements

A successful Privacy Officer candidate will have the expertise and skills described below.

Education and Training

Bachelor's degree or higher in business administration, law, finance, accounting, computer science or a related discipline isrequired.

An advanced degree in law, business (M.B.A.), information science (MIS), information security or a related field ispreferred.

The ideal candidate will have a combination of a legal or business degree with a technical or computer science degree.

The candidate has obtained two or more of the following certifications for the relevant region(s): one or more of: Certified Information Privacy Professional (CIPP), Certified Information Privacy Management (CIPM), and/or Certified Information Privacy Technologist (CIPT), and one or more of: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) and Certified Information Systems Auditor (CISA).

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Data Protection Officer - Qualified Lawyer

Data Protection Officer / Qualified Lawyer - Telecoms - 6- 9 month contractLocation:Reading (Hybrid - 2-3 days per week in the office)Role falls inside IR35Are you a qualified solicitor with a strong background in data protection within regulated industries? We are partnering with a leading telecoms company to find an...

Project People Reading

Data Protection Officer

Your new company A leading public service employer with a fantastic reputation across North Wales. My client provides vital services and is looking for an experienced Data Protection Officer to join them on a permanent basis. Your new role As a DPO for the organisation, you will be in a...

Hays Business Support Conwy

Data Protection Officer

Data Protection Officer/ Lawyer6-9 Months day rate contract/ FTCReading/Hybrid- 2-3 days per week onsiteWe are looking for an individual who has a genuine love of data protection, can think innovative and provide practical and commercial advice in relation to data protection. Reporting to the Director of Compliance, the Data Protection...

Project People Reading

Data Protection Officer

3 x Data Protection Officer Vacancies:2 x Part time DPO (Permanent contract, 2 days per week – flexibility with working pattern)1 x Part time DPO (Fixed Term Contract - 1 year maternity cover, 1.5 days per week – flexibility with working pattern)Applications are invited for any combination of the above...

Hefestis Limited Glasgow

Data Protection Officer

We are seeking a highly skilled and motivated Data Protection Officer (DPO) to join our team. The DPO will be responsible for overseeing our data protection strategy and implementation to ensure compliance with GDPR and other relevant data protection laws. This role involves conducting regular audits, risk assessments, and data...

Venn Group

Data Protection Officer

Join the Data Protection Revolution at Victorian PlumbingAre you a data privacy champion with a passion for online retail?Victorian Plumbing, the UK's leading online bathroom retailer, is seeking a talentedData Protection Officer (DPO)to join our dynamic team.As our DPO, you'll play a pivotal role in safeguarding customer data and ensuring...

Victorian Plumbing Leyland