Freshfields Bruckhaus Deringer Logo

Freshfields Bruckhaus Deringer

Senior Privacy Analyst

Reposted Yesterday
Be an Early Applicant
In-Office
London, Greater London, England, GBR
Senior level
In-Office
London, Greater London, England, GBR
Senior level
Supports the Privacy Office by conducting privacy impact assessments, vendor and technology due diligence, managing data subject rights requests, maintaining privacy documentation, investigating data incidents, and promoting privacy by design. The role provides day-to-day data protection guidance, manages compliance improvement initiatives, produces reporting, and mentors junior team members while supporting UK and European privacy compliance.
The summary above was generated by AI

Role summary/purpose of job

We are seeking an experienced Senior Privacy Analyst to join the Firm’s Privacy Office supporting the Firm’s practice groups and business services teams. You will play a critical part in delivering core privacy operation services to support our global data protection compliance program.

As a senior analyst, you will work closely with Senior Privacy Manager and other Privacy Office team members to operationalise privacy requirements, maintain key privacy documentation, conduct privacy assessments, administer data subject rights and contribute to privacy-by-design initiatives across the firm.

Key responsibilities

  • Completion of privacy impact assessments and DPIAs, undertaking vendor and technology due diligence, in particular for AI and innovative legal tech tools.

  • Coordinate and manage data subject rights requests, including DSARs, rights of erasure and other rights requests.

  • Maintain Privacy Office template documentation, communications and records.

  • Assist with data incident investigation and reporting.

  • Provide pragmatic day-to-day guidance to colleagues, supporting projects, and business change initiatives while promoting privacy by design.

  • Project manage internal initiatives aimed at improving internal processes to meet data protection compliance aims.

  • Work with the Senior Privacy Manager to mentor less experienced team members.

Skills, Qualifications and Experience

  • Substantial experience working in a privacy operations function, preferably within a top tier global law firm or banking and finance industry.

  • Proven experience applying UK and European data protection requirements in a business environment.

  • Experience supporting and/or coordinating Data Subject Access Requests (DSARs) and other data subject rights requests.

  • Strong organisational skills with the ability to work autonomously and manage multiple priorities and deadlines effectively.

  • Excellent written and verbal communication skills, with the ability to explain complex data protection requirements succinctly to a range of stakeholders.

  • Collaborative team player with ability to maintain working relationships and influence stakeholders across different teams.

  • Confident AI user with strong skills in Microsoft Office applications, particularly Outlook, Word, Excel and PowerPoint.

  • Experience producing reports, dashboards, metrics or management information would be advantageous.

Desirable

  • German language skills.

  • Knowledge of  data protection laws outside of UK/Europe.

  • IAPP (CIPP/E, CIPM, CIPT) or similar privacy certification.

  • Experience with legal tech, AI, or data ethics frameworks.

Department Overview

The Legal Department is mad up of both qualified lawyers and non-lawyers, exists to manage the firm’s risk exposure and to provide advice to the partners on a range of legal and compliance issues.

The role of the Legal Department is to support partners and staff in pursing the effective management of regulatory, legal, operational, and information security risk to preserve and maximise the value of the firm over the long term. We do this by taking responsibility for a range of actions, by sharing in the performance of others and by assisting partners and staff to manage risk themselves through training, awareness raising and the provision of relevant intelligence, services and materials.

Our vision is for our department to be recognised as a leader amongst comparable, elite, law firms. That means being acknowledged internally as providing an excellent service in a commercial and empathetic manner. It means adequately meeting the needs of the firm while remaining agile and cost effective; constantly refining our techniques, objectives and ways of working to respond to changes in the business and the threats we face.

Inclusion

Freshfields is an equal opportunities employer and all applications received by the firm will be considered on the basis of their merit alone. We welcome applications from all suitably qualified individuals regardless of background. All offers of employment will be conditional on the candidate having/securing the right to work in the UK in the role in question and providing the firm with evidence of that right (as required by the Immigration, Asylum and Nationality Act 2006) prior to employment commencing.

Freshfields is a Ban the Box employer. We ask applicants to disclose criminal convictions only if and when a conditional job offer is made. A conviction does not automatically lead to withdrawal of the offer: we make decisions on a case-by-case basis and take a number of relevant factors into account (e.g. the role you are applying for and the circumstances of the offence). You would have the opportunity to discuss the matter with us before we make a decision.

HQ

Freshfields Bruckhaus Deringer London, England Office

100 Bishopsgate, London, United Kingdom, EC2P 2SR

Similar Jobs

One Month Ago
In-Office
London, Greater London, England, GBR
Senior level
Senior level
Fintech • Payments • Financial Services
Manage day-to-day privacy processes (RoPA, DPIA, DSRs), administer OneTrust and Jira, drive AI governance rollout, advise on data protection and consent, codify guidance and training, automate privacy operations, reassess high/medium-risk processing, and support data protection agreements with cross-functional stakeholders.
Top Skills: JIRAOnetrust
One Month Ago
In-Office
London, England, GBR
Senior level
Senior level
Automotive • Software • Financial Services
Manage Alfa's day-to-day data privacy programme: draft and review policies and DPAs, run DPIAs, compile Records of Processing Activities, support international data transfers, lead audits, perform privacy risk assessments, and collaborate with Information Security, legal and client teams to ensure GDPR compliance and remediation tracking.
Top Skills: Alfa SystemsDpaDpiaEu GdprRecords Of Processing ActivitiesUk Gdpr
One Month Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Analytics
The Senior Privacy Analyst will enhance Verisk's privacy programme, ensuring compliance with UK and EU regulations, coordinating assessments, and managing data subject requests.
Top Skills: Eu GdprPrivacy Management PlatformsProductivity ToolsUk Gdpr

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account