At a Glance
- Tasks: Lead the charge in creating a robust data privacy programme across multiple jurisdictions.
- Company: Join Enstar, a global leader in re/insurance with a focus on innovation.
- Benefits: Enjoy competitive pay, wellness perks, and automatic pension enrolment.
- Other info: Be part of a supportive team that values inclusivity and career growth.
- Why this job: Make a real impact by embedding a culture of privacy awareness in a dynamic environment.
- Qualifications: 4-6 years of data privacy experience and relevant professional qualifications required.
The predicted salary is between 60000 - 80000 € per year.
The Data Privacy Manager will be a key member of Enstar's Data Privacy function, working closely with the Head of Data Privacy to design, implement and maintain a robust, multi-jurisdictional data privacy programme. The role holder will be instrumental in embedding a culture of privacy awareness across the business, ensuring compliance with applicable data protection laws across all territories in which Enstar operates, and supporting the business in managing privacy risk in a fast-moving regulatory environment. This is a technically demanding role requiring an experienced privacy professional who is performance driven and comfortable operating across both legal and operational dimensions of data privacy. The role requires strong communication and collaboration across all functional areas within Enstar and the ability to support delivery of an effective privacy program and solutions that balance regulatory requirements and business objectives.
What you will be doing
- Regulatory Compliance and Governance: Support the Head of Data Privacy in maintaining compliance with applicable data protection legislation across all operating jurisdictions (UK GDPR, EU GDPR, US privacy laws and Australian Privacy Act), managing the maintenance and updating of the ROPA, monitor regulatory developments as part of the Horizon Scanning Framework and manage regulatory registrations and filings.
- Privacy by Design: Manage the initiative to embed privacy by design default principles across the organisation.
- Data Subject Rights: Manage the end-to-end handling and recording of data subject rights requests across all jurisdictions.
- Privacy Assessments: Manage the end-to-end privacy assessment processes for PIAs, DPIAs and LIAs.
- Third-Party and Vendor Management: Ensure Data Processing Agreements (DPAs) are in place with all relevant data processors, manage privacy due diligence on third-party suppliers as part of the Supplier Engagement Framework.
- Data Breach Management: Support the management of personal data incidents from identification to resolution, if required, support the DPO in the assessment and management of notifiable breaches across jurisdictions, manage the testing of the Data Breach Response Plan, and liaise with Information Security to align incident management processes.
- Training, Awareness and Culture: Design and manage the delivery of data privacy training programmes for employees/contractors at all levels, monitor training completion rates, champion privacy awareness across the business. Assist with the design of the Data Privacy Champions Programme and manage the deployment and development of the Champions Programme.
- Privacy Risk Management: Manage the maintenance and development of the data privacy risk register within the Group’s ERM framework and GRC platform across all jurisdictions. To proactively identify and assess privacy risks, develop proportionate mitigation plans, processes and controls, track and report on risk mitigation actions and collaborate with relevant business functions.
- Policies, Procedures and Documentation: Develop, maintain and review data protection policies and procedures across all jurisdictions, manage the policy review schedule, prepare management information and reporting on the status of the privacy programme for the Head of Data Privacy and relevant stakeholders.
- International Data Transfers: Manage all international data transfer mechanisms across all operating jurisdictions, ensure all transfer mechanisms are current, properly documented and subject to regular review; manage the production of TIAs or TRAs where required; and maintain oversight of cross-border data flows arising from third-party arrangements.
What you will bring
- A minimum of four to six years of substantive, hands-on data privacy experience, ideally gained within a regulated financial services, insurance, or professional services environment.
- Relevant professional qualification CIPP/E, CIPM or equivalent.
- Demonstrable expertise in UK GDPR and the Data Protection Act 2018, with solid working knowledge of EU GDPR and at least one of: US privacy law (GLBA, CCPA/CPRA, state privacy laws), or Australian privacy law (Privacy Act 1988, APPs, NDB scheme).
- Practical experience of managing data subject rights programmes at volume, including SARs in a regulated sector context.
- Proven experience of conducting DPIAs and providing Privacy by Design advice to business stakeholders.
- Experience of negotiating and reviewing Data Processing Agreements and international data transfer mechanisms.
- Demonstrable experience of managing personal data breaches and advising on regulatory notification obligations.
- Experience in the insurance or reinsurance sector, with familiarity with insurance-specific data processing activities (claims, underwriting, fraud prevention databases, actuarial processing).
- Knowledge of the NAIC Insurance Data Security Model Law and state insurance commissioner notification requirements.
- Familiarity with the California Insurance Information and Privacy Protection Act (IIPPA) and its 2023 amendments.
- Experience of working within a multi-jurisdictional privacy programme spanning EEA, UK, US and/or Australian operations simultaneously.
- Legal qualification (solicitor, barrister or overseas equivalent) or privacy law academic background.
Who we are
We are a trusted global re/insurance group and the leading provider of retrospective solutions, with specialist underwriting capabilities. We help our clients manage risk, unlock capital and create the financial freedom to grow. With operations across the world’s major insurance hubs and a global network of close to 800 talented professionals, we bring expertise and fresh thinking to some of the industry’s biggest challenges.
Why Enstar
Learning and development are a fundamental part of every employee's career journey with Enstar. Supporting growth and career progression is key to how we engage our people - helping them to learn, grow and succeed at Enstar. We offer a range of initiatives and resources to support our people throughout their careers:
- Professional Qualifications and Study Support: We support employees who wish to take professional qualifications aligned to their role and career development.
- Training, Conferences & Seminars: As a global organisation, we work with many professional bodies to provide access to training programmes, conferences, seminars and continuing professional development (CPD) opportunities.
- Digital Learning Hub: Our digital learning hub, LinkedIn Learning, offers a wide range of self-serve resources, including courses, videos, eBooks, and audio books, to help employees build new skills and deepen their knowledge.
We also invest in physical, mental and financial wellbeing initiatives for our employees. Supportive teams, inspiring work and a positive working environment all contribute to our collective wellbeing. Beyond the workplace, we strive to make a positive influence in our communities and to continuously reduce our impact on the environment.
Enstar Inclusivity Policy: Our annual Inclusivity Index puts Enstar ahead of the industry in terms of promoting an inclusive and welcome working environment. We’re an equal opportunity employer and believe that our inclusive environment creates an authentic working culture. We don’t discriminate on the basis of age, physical or mental disability, gender reassignment, marriage and civil partnership, pregnancy and carer status, race (including colour, nationality, and ethnic or national origin), religion or belief, sex and sexual orientation. Enstar is committed to providing an accessible recruitment experience for all those interested in working with us. Please let your Enstar Recruitment Partner know if you require any reasonable accommodation during the application process due to a disability to enable you to fully participate in our recruitment process.
Data Privacy Manager employer: Enstar Group
Enstar is an exceptional employer, offering a dynamic work environment that prioritises employee growth and wellbeing. With a strong commitment to professional development, including support for qualifications and access to a wealth of training resources, employees are empowered to thrive in their careers. The inclusive culture fosters collaboration and innovation, making Enstar a rewarding place to work for those passionate about data privacy in the global re/insurance sector.
StudySmarter Expert Advice🤫
We think this is how you could land Data Privacy Manager
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their data privacy practices and be ready to discuss how your experience aligns with their needs. Show them you're not just another candidate!
✨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online platforms to get comfortable answering common questions. The more you practice, the more confident you'll feel when it’s time to shine.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Data Privacy Manager
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your relevant experience in data privacy. We want to see how your skills align with the specific requirements of the Data Privacy Manager role, so don’t hold back on showcasing your expertise!
Showcase Your Achievements:When detailing your past roles, focus on your accomplishments rather than just responsibilities. Use metrics where possible to demonstrate your impact, like how you improved compliance rates or successfully managed data subject rights requests.
Be Clear and Concise:Keep your application clear and to the point. We appreciate well-structured documents that are easy to read. Avoid jargon unless it’s relevant to the role, and make sure your passion for data privacy shines through!
Apply Through Our Website:We encourage you to apply directly through our careers site. This ensures your application is received promptly and allows us to process it efficiently. Plus, you’ll find all the details about the role and our company culture there!
How to prepare for a job interview at Enstar Group
✨Know Your Data Privacy Laws
Make sure you brush up on the UK GDPR, EU GDPR, and any relevant US or Australian privacy laws. Being able to discuss these regulations confidently will show that you're not just familiar with the basics but can also navigate the complexities of data privacy in a multi-jurisdictional context.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've successfully managed data subject rights requests or conducted DPIAs. This will help demonstrate your hands-on experience and how it aligns with the responsibilities of the Data Privacy Manager role.
✨Communicate Clearly
Since this role requires strong communication skills, practice articulating complex privacy concepts in simple terms. Think about how you would explain privacy by design principles to someone without a legal background—this will be crucial for collaborating across different functional areas.
✨Emphasise Collaboration
Be ready to discuss how you've worked with various teams to embed a culture of privacy awareness. Highlight any training programmes you've designed or delivered, as well as how you've engaged stakeholders to ensure compliance and mitigate privacy risks effectively.