Jobs and Careers
AR

Group Data Protection Advisor

Arriva Group
Lacon House, United Statesfull_timeVerifiedPosted 4 Jul 2024

About the role

Arriva is one of the leading providers of passenger transport in Europe, delivering nearly two billion passenger journeys across ten European countries each year. 

We have a fantastic opportunity to join our Group Information Security Team as Data Protection Advisor reporting to the Head of Data Protection and Group Data Protection Officer.

The Data Protection Advisor will be responsible for providing expert advice and guidance on data protection, GDPR and Privacy by Design. The role will also support on the deployment of the privacy compliance strategy and framework across the Group, and its individual businesses within the UK and Europe.

In addition, the Data Protection Advisor will be responsible for assisting and enabling the business to maintain and further develop data protection compliance initiatives in support of separation activities, working across Europe.

The role can be based in either our Sunderland, London or Leicester offices, a minimum of 2 days per week with the rest focusing on where you can best deliver, whilst still allowing for the required work life balance. The role operates Monday to Friday, 35 hours per week with 1 hour lunch per day.

Acting as a liaison across Arriva business, the Group Data Protection Advisor will be working on the following activities:

  • Supporting the Head of Data Protection and Group Data Protection Officer in all matters relating to the protection of Arriva’s customer or employee personal data, as well as that of any relevant third parties.
  • Providing subject matter expertise across all of Arriva to guide our business to be compliant to relevant data protection laws at all times.
  • Leading our business wide network of data champions to ensure our best practice guidance and Group data protection policies and standards are followed.
  • Coordinating a business wide review of Records of Processing Activities (ROPA), educating all legal entities to ensure they are able to keep up to date documentation that accurately reflects the personal data they process, as required by law.
  • Communicating any identified data protection risk with stakeholders, clearly articulating potential ways forward, their associated risk, and appropriate remedial activities, all the while providing a subject matter expert view of best practice.
  • Supporting procurement and due diligence activities across both supplier and system reviews, providing data protection assurance as required, in line with the Cyber Security and Information Assurance (CSIA Policy Framework). Including the review of relevant data protection schedules within supplier contracts, providing internal stakeholders with subject matter expert advice during contract reviews.
  • Supporting group stakeholders in conducting privacy impact assessments (PIA) and other relevant data protection risk assessments, ensuring all processing of personal data with a high impact has been fully assessed and documented.
  • Supporting group stakeholders and the Head of Data Protection and Group Data Protection Officer in investigating data breaches including advising on breach resolution, in accordance with established organisational processes.
  • Providing operational support across the business for the response to Data Subject Requests, manage responses to Subject Access Requests in some sensitive cases.
  • Developing and delivering tailored training sessions and workshops to improve the business understanding and application of data protection requirements.
  • Developing and maintaining effective tools to assist business areas with ongoing GDPR compliance activities, including supporting the Head of Data Protection and Group Data Protection Officer in strategic activities such as the definition of data protection key performance indicators and targets, and creation of associated reporting dashboards.
  • Supporting the Head of Data Protection and Group Data Protection Officer in carrying out data protection compliance assessments and improvements plans, including the production of compliance reports for senior stakeholders.
  • Supporting the Head of Data Protection and Group Data Protection Officer in assessing any opportunity to obtain accreditation under certification schemes due to be issued by the European Data Protection Board.

What we'd like from you!

We’re looking for candidates who can demonstrate experience in a dedicated Data protection/privacy role within a complex corporate environment, with a valid CIPP/E certification. A CIPP/M certification is desirable but not essential.

We’re also looking for candidates who:

  • Are comfortable and confident in delivering training and awareness programs, including in a face-to-face environment.
  • Have robust understanding and demonstrable interest in data protection including relevant

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Arriva Group

View company profile →