Sourced directly from Collinson's own careers page
Data Governance, Privacy & Enablement Counsel (12m FTC)
Collinson
London, England, United Kingdom["FULL_TIME"]
Thinking of applying? Check your CV against this job first.
See your match score, your strongest skills for this role, and what's missing — before you spend time on an application.
Your real match score
Free CareerPilot account · Takes about 2 minutes
Collinson is a global loyalty and benefits company.
We use our expertise and products to craft customer experiences which enable some of the world’s best-known brands to acquire, engage and retain the most demanding and choice-rich customers. In particular, our unique expertise and insight into high earning, frequent travellers allow us to create products and solutions for our clients that inspire greater customer engagement to drive more profitable relationships, enrich their travel experiences, protect what matters, and assist in in times of need.
While specialising in Financial Services, Travel and Retail, we also support clients in multiple sectors. We have worked with over ninety airlines, twenty hotel groups and more than six hundred financial institutions and banks, with clients including Accor Hotels, Air France KLM, American Express, British Airways, Cathay Pacific, Diners Club, Mandarin Oriental, Mastercard, Radisson Hotel Group, Sephora, Visa and Vhi.
We take our 30 years’ experience working with these kinds of household names in over 170 countries and help our clients to deliver the smarter experiences it takes to differentiate their propositions and help them win deeper devotion with their customers.
Collinson is a privately-owned entrepreneurial business with 2,000 passionate people working in twenty locations worldwide. Our solutions include Priority Pass, the world’s best known airport experiences programme, while we are also the trusted partner behind many of the leading financial services, airline and hotel brand’s reward programmes and loyalty initiatives.
Purpose of the job
The role provides expert legal advice and strategic support on all aspects of data protection, privacy and information governance across the Group. The role ensures that the organisation's data strategy, governance framework and commercial initiatives are underpinned by robust legal and regulatory compliance while enabling the responsible and innovative use of data.
As a member of the wider legal team, the role will be working closely with the Data Enablement Officer, Data Protection, Information Security, Compliance, Technology and Business teams, the role embeds privacy by design, supports enterprise data governance, facilitates secure data sharing, and provides day-to-day legal advice on privacy and contractual data protection matters across our operating companies.
The role acts as a trusted legal partner to the business, enabling commercial initiatives through practical, solutions-oriented advice.
Key Responsibilities
Support the Group Data Enablement Framework
Provide legal support in the development and maintenance of the Group Data Enablement Framework.
Ensure legal and privacy requirements are embedded within enterprise data governance standards, policies and processes.
Advise on accountability obligations, lawful processing principles and privacy-by-design requirements across data initiatives.
Support governance committees and decision-making forums on legal aspects of data management.
Review Contracts and Commercial Arrangements
Review, draft and negotiate contracts involving the processing or sharing of personal data.
Ensure contractual arrangements appropriately allocate privacy obligations and regulatory responsibilities.
Provide legal support on supplier, customer and technology agreements involving personal data.
Provide Day-to-Day Legal and Data Protection Advice
Act as the primary legal contact for operational data protection and privacy queries from business stakeholders.
Provide timely advice on subject access requests, retention, lawful basis, marketing, customer complaints, employee data and operational privacy issues.
Support business projects by providing practical legal solutions to day-to-day data protection matters.
Support Enterprise Data Architecture and Data Pipelines
Provide legal advice on new data flows, system integrations and enterprise data architecture initiatives.
Advise on privacy implications relating to data minimisation, purpose limitation, retention, security and lawful processing.
Review new technologies and transformation programmes to ensure privacy risks are appropriately managed.
Support Data Cataloguing and Accountability
Advise on legal requirements relating to Records of Processing Activities (ROPAs), data inventories and data classification.
Support documentation of ownership, lawful basis, retention periods and processing purposes for key business data assets.
Ensure accountability obligations under GDPR are appropriately embedded within enterprise data cataloguing initiatives.
Support Customer Insight and Commercial Opportunities
Provide legal advice on the lawful use of customer data for analytics, profiling, segmentation, AI and commercial initiatives.
Advise on consent requirements, legitimate interests’ assessments and direct marketing obligations.
Support responsible innovation while protecting customer rights and maintaining regulatory compliance.
Advise on AI and Emerging Technology Initiatives
Provide privacy and data protection legal advice on the Group's AI initiatives, including generative AI tools, machine learning models and automated decision-making systems.
Advise on the lawfulness of AI-driven processing.
Support the development of internal AI governance frameworks and policies, ensuring privacy-by-design principles are embedded from the outset.
Monitor developments in AI regulation and advise on their implications for the Group's activities.
Manage Data Breach and Incident Response
Lead the legal response to personal data incidents and breaches, including severity assessment and advising on regulatory notification obligations.
Manage notifications to the ICO within statutory timeframes and coordinate any required communications to affected data subjects.
Coordinate breach response with Information Security, Compliance and Communications teams to ensure a timely and legally robust response.
Manage proactive and reactive engagement with the ICO, including regulatory investigations and formal inquiries.
Deliver Privacy Training and Awareness
Design and deliver privacy training and awareness programmes tailored to business stakeholders across the Group.
Support embedding a culture of data protection across the organisation through accessible, practical guidance and communications.
Knowledge, skills, and experience required
Knowledge
The successful candidate will demonstrate extensive knowledge of:
UK GDPR and the Data Protection Act 20
18. The Data (Use and Access) Act 2025 and its implications for data sharing, smart data schemes and research exemptions.
Privacy and Electronic Communications Regulations (PECR).
UK Information Commissioner's Office (ICO) guidance and regulatory expectations.
EU GDPR and international privacy frameworks where applicable.
Data Processing Agreements, International Data Transfer Agreements (IDTAs) and Standard Contractual Clauses (SCCs).
Records of Processing Activities (ROPAs), Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs).
Customer data governance, profiling, marketing permissions and consent management.
Emerging technologies including Artificial Intelligence, automated decision-making and data ethics.
Enterprise data governance frameworks and the interaction between legal, compliance, technology and business functions.
Skills
The successful candidate will be able to:
Provide pragmatic, commercially focused legal advice on complex data protection issues.
Draft, review and negotiate contracts involving personal data processing and sharing.
Interpret legislation and regulatory guidance and translate it into practical business solutions.
Influence senior stakeholders and communicate complex legal concepts in a simple and accessible manner.
Build collaborative relationships across Legal, Data Protection, Technology, Information Security, Compliance and Commercial teams.
Analyse complex data processing activities and identify legal and privacy risks.
Support strategic data governance initiatives and privacy-by-design programmes.
Manage multiple priorities and provide responsive legal support across a diverse business.
Exercise sound judgement when advising on new or high-risk data initiatives. Demonstrate a solutions-first mindset, identifying compliant pathways to commercial objectives.
Experience
The successful candidate will have:
Essential
Qualified Solicitor (England & Wales) or equivalent legal qualification.
Minimum 5 years' post-qualification experience advising on UK data protection and privacy law.
Strong experience leading or supporting enterprise data transformation or digital transformation programmes.
Significant experience reviewing and negotiating commercial contracts involving personal data in multiple jurisdictions (ideally, with considerable APAC experience).
Significant experience leading the drafting and negotiation of:
Data Processing Agreements
Data Sharing Agreements
International Data Transfer Agreements
Standard Contractual Clauses
Technology and outsourcing agreements
Transfer Risk Assessments
Experience advising on customer data, marketing, profiling and consent management.
Experience responding to day-to-day operational privacy queries from business stakeholders.
Deep experience in providing advice under pressure on breach assessment, notification thresholds, ICO/Regulatory reporting, data subject communications, internal investigations, remediation and post-incident governance.
Substantial experience gained within an in-house legal function.
Experience advising on personal data breach response, including regulatory notification obligations to the ICO and management of third-party and data subject notifications.
Desirable
Experience advising on AI governance, machine learning or automated decision-making.
Experience supporting international organisations and cross-border data transfers.
Experience implementing or supporting enterprise data governance frameworks.
Experience working with data cataloguing tools, metadata management or Records of Processing Activities (ROPAs).
Experience training non-lawyers, influencing stakeholders and embedding privacy controls into business processes.
Experience engaging with the ICO or other data protection regulators, including managing regulatory investigations or formal inquiries.
Relevant privacy certification such as CIPP/E (IAPP) or equivalent.
Collinson is an equal opportunity employer and welcomes differences in all their forms including: colour, race, ethnicity, gender identity, sexual orientation, neurodivergence, family status, age, individuals with disabilities and people from all backgrounds, cultures and experiences as we strongly believe this contributes to our on-going success.
We are focused on continually evolving our purpose driven, high performing culture, providing an environment where our people have the opportunity to achieve their full potential and do interesting and meaningful work. Our company values are: Take Action, Do the right thing, One team and Be insight led. These help guide everything we do internally in terms of how we think, act and interact, right through to how we deliver value to our customers and clients.
In your application, please feel free to note which pronouns you use (For example - she/her/hers, he/him/his, they/them/theirs, etc).
If you need any extra support throughout the interview process, then please email us at ukrecruitment@collinsongroup.com