Data Protection Consultant - UK
Location: Leeds (Hybrid - but flexible to discuss)
Salary: £55k per annum + benefits
About Us
At Cognisys, we help organisations build confidence in their cyber security, governance and compliance. Through our specialist teams, we provide Penetration Testing, Governance, Risk & Compliance (GRC) consultancy and Managed Security Services that enable our clients to operate securely and confidently.
Our people are trusted advisors who work in partnership with clients to solve real business challenges. We pride ourselves on delivering pragmatic, commercially focused advice that creates lasting value, underpinned by our values of Together, Ownership, Momentum, and Excellence.
As we continue to grow, we're looking for an experienced Data Protection Consultant (Virtual DPO) to join our expanding GRC team.
About the Role
As a Data Protection Consultant, you'll act as a trusted privacy advisor, delivering Virtual Data Protection Officer (DPO) services and data protection consultancy to a diverse portfolio of approximately 10–15 clients.
You'll help organisations strengthen their privacy governance, navigate complex regulatory requirements and build practical compliance programmes that support their wider business objectives. Working across multiple industries and organisations, no two days will be the same.
This is a highly client-facing consultancy role, requiring someone who enjoys variety, can quickly build trusted relationships with senior stakeholders and thrives in a fast-paced environment where balancing multiple client priorities is the norm.
Alongside supporting our clients, you'll also play a key role in maintaining and enhancing Cognisys' own internal privacy programme, ensuring we continue to uphold the high standards we deliver to our clients.
Key Responsibilities
Virtual Data Protection Officer Services
Act as the appointed Virtual Data Protection Officer for a portfolio of clients.
Build trusted relationships with senior stakeholders and leadership teams.
Provide strategic advice on privacy, governance and regulatory compliance.
Attend governance meetings and represent Cognisys as a trusted advisor.
Data Protection & Privacy Consultancy
Advise clients on UK GDPR, the Data Protection Act 2018, PECR and wider privacy legislation.
Translate regulatory requirements into practical, commercially balanced solutions.
Develop, review and improve privacy policies, procedures and governance documentation.
Support organisations in embedding Privacy by Design across projects and business processes.
Privacy Risk & Compliance
Conduct privacy health checks, compliance reviews and gap assessments.
Lead or support Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs).
Review Records of Processing Activities (RoPA) and data retention practices.
Identify privacy risks and recommend pragmatic mitigation strategies.
Incident & Regulatory Support
Advise clients during personal data breaches and security incidents.
Support breach assessments and regulatory notification decisions.
Assist organisations with enquiries from the Information Commissioner's Office (ICO).
Data Subject Rights
Advise clients on Subject Access Requests (SARs) and wider data subject rights.
Review complex requests and provide practical guidance.
Support clients with privacy complaints and regulatory enquiries.
Client Consultancy
Deliver consultancy engagements remotely and on client sites.
Produce high-quality reports, recommendations and action plans.
Present findings and recommendations confidently to senior stakeholders.
Identify opportunities to introduce additional Cognisys cyber security and GRC services where appropriate.
Supporting Data Protection at Cognisys
In addition to client consultancy, you'll help shape and maintain Cognisys' own internal privacy programme.
You'll:
Act as the internal Data Protection subject matter expert.
Maintain and improve Cognisys' data protection framework, policies and procedures.
Lead internal Data Protection Impact Assessments (DPIAs).
Maintain and review our Records of Processing Activities (RoPA).
Support internal data subject rights requests and privacy enquiries.
Advise on supplier due diligence, data sharing arrangements and new business initiatives.
Support the investigation and management of personal data incidents.
Deliver internal privacy awareness training.
Monitor regulatory developments and recommend improvements.
Collaborate with Information Security, People and Legal teams to embed privacy across the business.
Training & Knowledge Sharing
Deliver engaging privacy awareness workshops and training sessions.
Help clients foster a positive culture of accountability and privacy.
Share best practice and support colleagues across the wider GRC team.
Continuous Improvement
Stay up to date with developments in privacy legislation and industry best practice.
Contribute to the continued development of Cognisys' privacy consultancy services.
Support the ongoing growth of the GRC practice.
Requirements
You'll combine strong technical expertise with excellent consultancy, communication and stakeholder management skills.
You'll enjoy building long-term client relationships, balancing multiple priorities and delivering pragmatic advice that helps organisations improve their privacy maturity.
Essential
Minimum of five years' experience delivering data protection consultancy or privacy advisory services within a consultancy or professional services environment.
Experience acting as, or supporting, an internal or outsourced Data Protection Officer.
Excellent knowledge of UK GDPR, the Data Protection Act 2018 and PECR.
Experience conducting privacy compliance reviews, gap assessments and Data Protection Impact Assessments (DPIAs).
Experience advising senior stakeholders on privacy risks and regulatory obligations.
Excellent written communication and report writing skills.
Strong presentation and stakeholder management skills.
Excellent organisational skills with the ability to manage multiple client engagements simultaneously.
A pragmatic, commercially focused approach to problem solving.
Desirable
IAPP (CIPP/E, CIPM or CIPT), BCS or equivalent privacy qualification.
Knowledge of ISO 27001 and ISO 27701.
Experience working alongside Cyber Security or Information Security teams.
Experience delivering privacy training and awareness sessions.
Knowledge of international privacy legislation.
Why Join Us?
Joining Cognisys means becoming part of a collaborative team that's passionate about delivering exceptional outcomes for clients while supporting one another's success.
In return, we offer:
Hybrid and flexible working.
25 days annual leave plus public holidays.
An additional day off to celebrate your birthday.
Professional development with dedicated learning and certification support.
Employee Wellness Hub through Kara Connect.
The opportunity to work alongside industry experts across Cyber Security and GRC.
A collaborative culture where you'll be empowered to make a meaningful impact and continue developing your career.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Senior Recruiter, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.group
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
- Department
- Governance, Risk and Compliance (GRC)
- Locations
- Leeds HQ
- Remote status
- Hybrid