UK remote
Head of Compliance and Data Privacy - 12 month FTC
About this role
At ASOS, data and trust are fundamental to how we serve millions of customers around the world. As our Head of Compliance and Data Privacy, you'll lead our global privacy and compliance agenda, acting as ASOS's Data Protection Officer (DPO) and trusted advisor to senior leaders across the business. This is a high-profile leadership role with responsibility for ensuring our approach to privacy, data protection and compliance is commercially focused, practical and fit for a fast-moving global retailer.
You'll partner with teams across Technology, Data, Marketing, Supply Chain, Procurement, People and Commercial functions, helping them navigate complex regulatory requirements while enabling innovation and growth. Alongside leading our Privacy team, you'll oversee the Compliance function, shaping frameworks, governance and policies that support ASOS's continued success. The Details Act as the independent Data Protection Officer (DPO) for UK and EU operations, ensuring global privacy compliance.
Provide expert guidance on current and emerging privacy legislation and regulatory changes. Advise the business on privacy implications of strategic and commercial initiatives. Support the management and mitigation of privacy risks across the organisation. Design and deliver privacy programmes that demonstrate compliance and enhance customer trust. Lead responses to data breaches and critical incidents, including stakeholder and executive communications.
Develop and maintain privacy governance frameworks, policies, standards and training programmes. Advise on specialist privacy topics such as data retention, transfers, analytics and data usage. Maintain Records of Processing Activities (ROPA), lawful basis governance and accountability evidence. Oversee international data transfers, transfer risk assessments and localisation requirements. Conduct privacy due diligence on third parties and ensure ongoing contract and processor compliance.
Manage relationships with regulators, supervisory authorities, employees and customers on privacy matters. Lead data subject rights processes, including access requests and information disclosures. Manage privacy audits, compliance reviews and remediation activities. Draft and advise on privacy and security provisions within contracts and commercial agreements. Maintain Data Protection Impact Assessment (DPIA) frameworks and advise on privacy risk mitigations.