At a Glance
- Tasks: Lead data protection initiatives and ensure compliance while enabling business growth.
- Company: Join a fast-growing FinTech revolutionising small business finance.
- Benefits: Enjoy private healthcare, generous holiday, and a supportive work culture.
- Other info: Diverse and inclusive workplace with excellent career development opportunities.
- Why this job: Make a real impact in data protection using cutting-edge technology.
- Qualifications: Deep knowledge of UK data protection laws and experience in tech or finance.
The predicted salary is between 70000 - 90000 € per year.
We’re Capital on Tap. Capital on Tap started because small businesses were underserved. Big banks were slow, their products weren’t fit for purpose, and small business owners often couldn’t access what they needed. We set out to fix that. Today we’re a financial platform – not just a credit card company. We offer a best‑in‑class business credit card, SME‑focused spend management platform, a savings product that reached £1 billion in funds within its first year, and a growing suite of tools and financial products that make running a small business easier. 1,000+ employees, £20 bn in annual card spend, 200,000+ customers, 17,000+ Trustpilot reviews averaging 4.7 stars. We’re profitable and just getting started!
Why Join Us? We empower you to be innovative and solve complex problems. Take ownership, make an impact, and thrive in our scaling and agile environment.
The Data Protection Team at Capital on Tap The Data Protection team plays a crucial role in enabling Capital on Tap’s commercial objectives while ensuring full compliance with global data protection regulations. As our Data Protection Officer, you’ll lead a team that includes Data Protection Analysts and Administrators, working at the intersection of technology, compliance, and business enablement.
The Role We’re looking for an exceptional Data Protection Officer to join our FinTech in London. This is a strategic leadership role for someone who thrives on using cutting‑edge technology and AI to transform data protection from a compliance function into a business enabler. You’ll protect the company by finding innovative ways to achieve commercial goals while maintaining the highest standards of data protection compliance.
What you’ll be doing
- Strategic Leadership: Serve as the primary data protection authority (act as the designated DPO under Article 37 of the UK GDPR and UK data protection law), providing strategic guidance to senior leadership on privacy risks and opportunities across all business functions.
- Business Enablement: Work closely with Product, Engineering, Marketing, and Commercial teams to find compliant pathways for new initiatives, ensuring data protection accelerates rather than hinders business goals.
- Technology & Automation: Lead the implementation of state‑of‑the‑art AI technologies and automation tools to streamline data protection activities, from DPIA automation to intelligent data discovery and rights fulfillment.
- Regulatory Compliance: Ensure full compliance with UK GDPR, DPA 2018, PECR, DUAA, CCPA/CPRA and emerging regulations, while staying ahead of regulatory developments and their business implications.
- Risk Management: Conduct and oversee Data Protection Impact Assessments (DPIAs), manage data breach responses, and implement privacy‑by‑design principles across all technology platforms.
- Monitoring: Monitor and assess data processing activities to ensure ongoing compliance. Assess the lawful basis for processing activities and ensure appropriate documentation is in place. Maintain and regularly review the organisation’s Record of Processing Activities (ROPA) to ensure completeness and accuracy.
- Stakeholder Management: Act as the primary contact point for regulators (ICO), work closely with internal and external legal counsel, and represent the company in privacy‑related matters.
- Team Development: Build and lead a high‑performing data protection team, fostering a culture of innovation, urgency, and business partnership.
- International Expansion: Support the company’s US operations and international growth by navigating complex cross‑border data transfer requirements and multi‑jurisdictional compliance.
- Vendor Management: Lead privacy due diligence for third‑party vendors and partnerships, ensuring contractual protections align with business risk appetite.
- Training & Culture: Drive privacy awareness across the organisation through targeted training programmes and embed privacy considerations into business‑as‑usual processes.
We’re looking for
- Deep Regulatory Expertise: Comprehensive knowledge and hands‑on experience with UK data protection regulations (GDPR, DPA 2018, PECR, DUAA), with the ability to interpret complex requirements and provide pragmatic business guidance.
- FinTech / Tech Background: Proven experience in financial services or technology companies, understanding the unique privacy challenges of regulated financial products (including an understanding of consumer duty and vulnerability) and high‑growth tech environments.
- Technical Fluency: Strong technical acumen with experience using data protection tools, privacy management platforms, and automation technologies to streamline compliance processes.
- AI & Innovation: Experience with or strong willingness to adopt cutting‑edge AI technologies for privacy operations, from automated risk assessments to intelligent data processing.
- Problem‑Solving Mindset: Pragmatic approach to complex privacy challenges, with a track record of finding creative solutions that balance compliance requirements with customer outcomes and business objectives.
- Urgency & Business Focus: Demonstrated ability to work at pace in fast‑moving environments, with a philosophy that compliance should enable rather than block business progress.
- Leadership Experience: Proven ability to lead cross‑functional initiatives, influence senior stakeholders, and build high‑performing teams.
- Strategic Thinking: Experience translating regulatory requirements into business strategy, with the ability to anticipate future privacy challenges and opportunities.
- Professional Qualifications: A recognised data protection qualification such as IAPP’s CIPP/E, CIPM, CIPT, C‑DPO, or a BCS Practitioners certificate in Data Protection.
- US Privacy Expertise: Knowledge of CCPA/CPRA, state‑level US privacy laws, and experience managing multi‑jurisdictional compliance programmes.
- Professional Qualifications: AIGP – a certified AI Governance Professional would be highly desirable.
- Regulatory Relationships: Existing relationships with privacy regulators or experience managing regulatory inquiries.
- International Experience: Experience with international data transfers, adequacy decisions, and global privacy frameworks.
- Experience: Minimum of 2 years experience acting in a DPO capacity within a financial services or technology organisation.
Diversity & Inclusion We welcome, consider and encourage applications from anyone who shares our commitment to inclusivity. Join us in creating a space where authenticity thrives, and everyone can do their best work.
Great Work Deserves Great Perks
- Private Healthcare including dental and opticians services through Vitality.
- Worldwide travel insurance through Vitality.
- Anniversary Rewards (£250, £500, £750, 4‑week fully paid sabbatical).
- Salary Sacrifice Pension Scheme up to 7% match.
- 28 days holiday (plus bank holidays).
- Annual Learning and Wellbeing Budget.
- Enhanced Parental Leave.
- Cycle to Work Scheme.
- Season Ticket Loan.
- 6 free therapy sessions per year.
- Dog Friendly Offices.
- Free drinks and snacks in our offices.
Data Protection Officer New London employer: Capital on Tap
At Capital on Tap, we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to innovate and make impactful contributions. As a Data Protection Officer in London, you will benefit from a competitive salary, comprehensive private healthcare, and a generous holiday allowance, all while working in a fast-paced FinTech environment that prioritises professional growth and cutting-edge technology. Join us to be part of a team that values your expertise and encourages you to thrive as we redefine financial services for small businesses.
StudySmarter Expert Advice🤫
We think this is how you could land Data Protection Officer New London
✨Tip Number 1
Network like a pro! Get out there and connect with people in the industry. Attend events, join online forums, and don’t be shy about reaching out to current employees at Capital on Tap. A friendly chat can open doors you didn’t even know existed!
✨Tip Number 2
Show off your skills! Prepare a portfolio or case studies that highlight your experience with data protection and compliance. When you get the chance to chat with hiring managers, share how you've tackled challenges in the past – it’ll make you stand out!
✨Tip Number 3
Be ready for the interview! Research Capital on Tap’s products and their approach to data protection. Think about how your expertise aligns with their goals and be prepared to discuss how you can help them innovate while staying compliant.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at Capital on Tap. Don’t miss out on this opportunity!
We think you need these skills to ace Data Protection Officer New London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Data Protection Officer role. Highlight your experience with UK data protection regulations and any relevant tech skills. We want to see how you can bring your unique expertise to our team!
Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for Capital on Tap. Share specific examples of how you've enabled business goals through data protection in the past. We love a good story that showcases your problem-solving mindset!
Show Off Your Tech Savvy:Since we’re all about innovation, don’t forget to mention any experience you have with AI technologies or data protection tools. We’re looking for someone who can leverage cutting-edge tech to streamline compliance processes, so let us know what you’ve got!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re keen on joining our awesome team at Capital on Tap!
How to prepare for a job interview at Capital on Tap
✨Know Your Regulations
Make sure you brush up on UK data protection regulations like GDPR and DPA 2018. Be ready to discuss how these laws impact business operations and how you can ensure compliance while enabling growth.
✨Showcase Your Tech Savvy
Since this role involves using cutting-edge technology, be prepared to talk about your experience with data protection tools and AI technologies. Share specific examples of how you've used tech to streamline compliance processes in the past.
✨Demonstrate Strategic Thinking
Think about how you can translate regulatory requirements into actionable business strategies. Be ready to discuss how you've previously balanced compliance with business objectives and what innovative solutions you've implemented.
✨Engage with Stakeholders
Highlight your experience in managing relationships with various stakeholders, including regulators and internal teams. Prepare to share examples of how you've effectively communicated complex privacy issues to non-technical audiences.