Zopa Bank Logo

Zopa Bank

Data Privacy Manager

Posted 13 Days Ago
Be an Early Applicant
Hybrid
London, Greater London, England, GBR
Entry level
Hybrid
London, Greater London, England, GBR
Entry level
Lead Zopa’s data privacy function, advising on privacy implications for products and customer journeys, translating UK privacy law into practical guidance, and developing governance frameworks covering DPIAs, privacy by design, retention, ROPA, and third-party diligence. Manage privacy incidents, data-subject rights requests, regulatory notifications, stakeholder partnerships, and a direct report. Contribute to PCI DSS capability, data-risk management, privacy awareness, and compliance across regulated financial services.
The summary above was generated by AI
Our Story
 
Hello there. We’re Zopa.
 
We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank. A bank that listens to what our customers don’t like about finance and does the opposite. We’re redefining what it feels like to work in finance. Our vision for a new era of banking puts people front and centre — we’ve built a business that empowers everyone to aim high, every day, to move finance forward. Find out more about our fantastic offerings at Zopa.com! 
 
We’re incredibly proud of our achievements and none of it would be possible without the amazing team here. It’s not just industry awards we’re winning, we’ve also been named in the top three UK’s Most Loved Workplaces. 
 
If you embrace unconventional challenges, are unafraid to think differently and are driven to make an outsized impact, you’ll thrive here at Zopa, so join us, and make it count. Want to see us in action? Follow us on Instagram @zopalife

The Team

You’ll join the Data Privacy function within Operational Risk & Compliance. The function serves the whole of Zopa, helping
teams across the business make confident, well-reasoned decisions about customer data. Within the wider function, the
Operational Risk & Compliance teams also support product and business activity including current accounts, savings,
investments and marketing.
The Role

As Data Privacy Manager, you’ll lead the team’s strategic and day-to-day work, managing a Data Privacy Associate and
partnering closely with product, technology, legal, risk, security and commercial colleagues. You’ll help evolve a privacy
capability that is rigorous where it needs to be and practical everywhere it can be. There is also an opportunity to help build
the function’s PCI DSS capability over time.

Key Responsibilities

  • Advise product and business teams on privacy implications of new products, changes and customer journeys.
  • Translate UK privacy law into clear, proportionate recommendations that enable responsible decisions.
  • Support the development of the data privacy governance framework, from DPIAs and privacy by design to retention, ROPA and third-party diligence.
  • Manage complex privacy incidents, including regulatory notification and engagement with affected individuals where required.
  • Oversee high-quality, timely handling of DSARs, erasure requests and objections.
  • Build trusted partnerships across technology, legal, risk, security and commercial functions.
  • Develop your direct report and strengthen privacy awareness across the business.
  • Contribute to the Bank’s approach to data risk across a broad range of business activity

Experience

  • Bring deep practical knowledge of UK GDPR, the Data Protection Act 2018 and wider UK privacy regulation.
  • Apply privacy law proportionately in a commercial environment and give pragmatic, business-enabling advice.
  • Make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs the actual privacy risk.
  • Have helped develop a data protection function in an organisation with evolving privacy maturity.
  • Design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA and third-party due diligence.
  • Manage data breaches and privacy incidents end-to-end, including ICO notification where required.
  • Handle data-subject rights requests with quality, timeliness and defensible decisions.
  • Build credibility with business, technology, legal, risk and security stakeholders.
  • Lead and develop high-performing teams with accountability and continuous improvement.

Nice to haves

  • Bring hands-on PCI DSS knowledge and want to help build this capability across the function.
  • Know PCI DSS requirements and their practical application in financial services or payments.
  • Assess cardholder-data flows, scope boundaries and control gaps as part of broader data-risk reviews.
  • Have contributed to PCI DSS compliance programmes.
  • Understand regulated financial services and how privacy obligations interact with FCA and PRA expectations.
  • Comfortably influence senior executives and handle challenging conversations.
  • Bring exposure to another risk discipline, such as compliance or operational risk
  • Experience using OneTrust to manage data privacy obligations

#LI-JR1

At Zopa we value flexible ways of working.

We value face-to-face collaboration and a good work-life balance. This hybrid role requires you to come to our London office 2-3 days a week.

You'll also have the option of working from abroad for up to 120 days a year!* But no matter where you are, we’ll make sure you’ve got everything you need to thrive, both in your work and home life, from day one.

*Subject to having the right to work in the country of choice


Diversity Statement

Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives, and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments. 


Our approach to AI in interviews

At Zopa, AI isn't something we're testing out — it's part of how we work every day. As a proud partner of Jobs 2030, we're committed to building AI fluency across our workforce, and we expect Zopians to use AI as part of how they do their jobs. 

Because of that, we want to be transparent about how we think about AI use during our hiring process. 

Behavioural and competency-based interviews: please don't use AI. These conversations are designed to understand you — your experiences, your judgment, and how you've approached real situations. An AI-generated answer can't tell us that. What it can do is get in the way of us finding out whether we're the right fit for each other. 

Technical interviews: it depends on the role. Some technical stages actively welcome AI use, others don't. Your Talent Partner will let you know what's expected at each stage. Where AI is part of the assessment, we'll be interested not just in the outcome, but in how you used it – the tools you chose, your reasoning, and the decisions you made along the way. 

HQ

Zopa Bank London, England Office

Tooley Street, London, United Kingdom, SE1 2QG

Similar Jobs

12 Days Ago
Hybrid
Mid level
Mid level
Financial Services
Oversee data privacy and protection as a second-line risk function, advising stakeholders, reviewing DPIAs, managing data breaches and subject rights requests, producing privacy MI and governance reports, monitoring regulatory changes, supporting training, and improving the privacy framework. The role requires strong UK GDPR expertise, risk management, investigation, analytical, stakeholder engagement, and compliance skills within a regulated environment.
Top Skills: Data Protection Act 2018Data Protection Impact Assessments (Dpias)PecrUk Gdpr
24 Days Ago
In-Office
London, Greater London, England, GBR
Senior level
Senior level
Legal Tech • Financial Services
Lead privacy and AI governance across EMEAPAC: implement and improve compliance frameworks, monitor regulation (including EU AI Act), manage DPIAs/RoPAs/DSARs, advise business and technical teams, run incident response, draft vendor data terms, deliver training, and support the Head of Regulatory Risk and DPO.
Top Skills: AI
Yesterday
Hybrid
Entry level
Entry level
eCommerce • Fashion • Retail • Sales • Wearables • Design
Assist customers with product selection and personal styling, provide product knowledge and complete-look recommendations, guide purchase decisions, and deliver seamless checkout experiences. Drive sales through customer engagement, storytelling, and brand expertise while maintaining stockroom organization and operational excellence. The role requires flexibility for nights, weekends, holidays, and high-traffic retail periods, along with collaboration, multitasking, and willingness to learn omni-channel selling techniques.
Top Skills: Omni-Channel Selling ToolsPos Systems

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account