Zopa
Zopa1d ago
New
GBP 70000–88000/yr

Data Privacy Manager

United KingdomUnited Kingdom·LondonEmployee - Permanentmid
Legal & ComplianceData Protection Officer
0 views0 saves0 applied

Quick Summary

Overview

Our Story Hello there. We’re Zopa. We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank.

Technical Tools
Legal & ComplianceData Protection Officer
Our Story
 
Hello there. We’re Zopa.
 
We started our journey back in 2005, building the first ever peer-to-peer lending company. Fast forward to 2020 and we launched Zopa Bank. A bank that listens to what our customers don’t like about finance and does the opposite. We’re redefining what it feels like to work in finance. Our vision for a new era of banking puts people front and centre — we’ve built a business that empowers everyone to aim high, every day, to move finance forward. Find out more about our fantastic offerings at Zopa.com
 
We’re incredibly proud of our achievements and none of it would be possible without the amazing team here. It’s not just industry awards we’re winning, we’ve also been named in the top three UK’s Most Loved Workplaces. 
 
If you embrace unconventional challenges, are unafraid to think differently and are driven to make an outsized impact, you’ll thrive here at Zopa, so join us, and make it count. Want to see us in action? Follow us on Instagram @zopalife

The Team

You’ll join the Data Privacy function within Operational Risk & Compliance. The function serves the whole of Zopa, helping
teams across the business make confident, well-reasoned decisions about customer data. Within the wider function, the
Operational Risk & Compliance teams also support product and business activity including current accounts, savings,
investments and marketing.

The Role

As Data Privacy Manager, you’ll lead the team’s strategic and day-to-day work, managing a Data Privacy Associate and
partnering closely with product, technology, legal, risk, security and commercial colleagues. You’ll help evolve a privacy
capability that is rigorous where it needs to be and practical everywhere it can be. There is also an opportunity to help build
the function’s PCI DSS capability over time.
  • Advise product and business teams on privacy implications of new products, changes and customer journeys.
  • Translate UK privacy law into clear, proportionate recommendations that enable responsible decisions.
  • Support the development of the data privacy governance framework, from DPIAs and privacy by design to retention, ROPA and third-party diligence.
  • Manage complex privacy incidents, including regulatory notification and engagement with affected individuals where required.
  • Oversee high-quality, timely handling of DSARs, erasure requests and objections.
  • Build trusted partnerships across technology, legal, risk, security and commercial functions.
  • Develop your direct report and strengthen privacy awareness across the business.
  • Contribute to the Bank’s approach to data risk across a broad range of business activity
  • Bring deep practical knowledge of UK GDPR, the Data Protection Act 2018 and wider UK privacy regulation.
  • Apply privacy law proportionately in a commercial environment and give pragmatic, business-enabling advice.
  • Make and defend risk-based decisions, including challenging interpretations where commercial impact outweighs the actual privacy risk.
  • Have helped develop a data protection function in an organisation with evolving privacy maturity.
  • Design and implement governance frameworks covering DPIAs, privacy by design, retention, ROPA and third-party due diligence.
  • Manage data breaches and privacy incidents end-to-end, including ICO notification where required.
  • Handle data-subject rights requests with quality, timeliness and defensible decisions.
  • Build credibility with business, technology, legal, risk and security stakeholders.
  • Lead and develop high-performing teams with accountability and continuous improvement.
  • Bring hands-on PCI DSS knowledge and want to help build this capability across the function.
  • Know PCI DSS requirements and their practical application in financial services or payments.
  • Assess cardholder-data flows, scope boundaries and control gaps as part of broader data-risk reviews.
  • Have contributed to PCI DSS compliance programmes.
  • Understand regulated financial services and how privacy obligations interact with FCA and PRA expectations.
  • Comfortably influence senior executives and handle challenging conversations.
  • Bring exposure to another risk discipline, such as compliance or operational risk
  • Experience using OneTrust to manage data privacy obligations
  • #LI-JR1

    We value face-to-face collaboration and a good work-life balance. This hybrid role requires you to come to our London office 2-3 days a week.

    You'll also have the option of working from abroad for up to 120 days a year!* But no matter where you are, we’ll make sure you’ve got everything you need to thrive, both in your work and home life, from day one.

    *Subject to having the right to work in the country of choice

     

    Zopa is proud to offer a workplace free from discrimination. Diversity of experience, perspectives, and backgrounds leads to better products for our customers and a unique company culture for our people. We are made up of nearly 50 nationalities, have a DE&I forum made up of Zopians wanting to make a difference and we are proud of our culture where everyone can bring their full self to work. Our approach to DE&I is reflected in our hiring process so please let us know if you require any reasonable adjustments. 

     

    At Zopa, AI isn't something we're testing out — it's part of how we work every day. As a proud partner of Jobs 2030, we're committed to building AI fluency across our workforce, and we expect Zopians to use AI as part of how they do their jobs. 

    Because of that, we want to be transparent about how we think about AI use during our hiring process. 

    Behavioural and competency-based interviews: please don't use AI. These conversations are designed to understand you — your experiences, your judgment, and how you've approached real situations. An AI-generated answer can't tell us that. What it can do is get in the way of us finding out whether we're the right fit for each other. 

    Technical interviews: it depends on the role. Some technical stages actively welcome AI use, others don't. Your Talent Partner will let you know what's expected at each stage. Where AI is part of the assessment, we'll be interested not just in the outcome, but in how you used it – the tools you chose, your reasoning, and the decisions you made along the way. 

    Location & Eligibility

    Where is the job
    London, United Kingdom
    Hybrid — some on-site time required
    Who can apply
    GB

    Listing Details

    Posted
    August 24, 2026
    First seen
    August 24, 2026
    Last seen
    August 25, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    81%
    Scored at
    August 24, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Zopa
    Zopa
    lever

    We’re Zopa, and we want to make money work better for you.

    Employees
    750
    Founded
    2005
    Domain
    zopa.com
    View company profile
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    ZopaData Privacy ManagerGBP 70000–88000