About this Head of Data Protection role at DC Thomson
At DC Thomson we are a business with a purpose – to make a positive impact on the communities we serve. We are home to some of the world’s best loved media brands, organised around local news and radio, companionship, kids, advocacy, energy, puzzles and hobbies. The Courier, The Press & Journal, The Sunday Post, Beano, Stylist, Puzzler, The People’s Friend, My Weekly, Original 106, Bunkered, Energy Voice, Findmypast and Brightsolid are just some of the brands you might know us for.
Deeply rooted in our communities, we are investing in data, technology and talent to unlock a new level of understanding about what really matters to our customers. This is how we are shaping the future of media.
Our HQ is in Dundee and we have bases around the UK employing over 1,200 extraordinarily creative colleagues working in a mix of office/home/hybrid. They’re passionate about being part of the story of so many well-loved brands and they’re crucial to our ambitions for the company.
Why join us now?
DC Thomson is on an exciting transformation journey to growth, diversifying our revenues and building a sustainable, subscription-driven business. Our brands matter to people and we are passionate about sustaining meaningful relationships with the communities these brands serve.
About the role:
This role forms part of Group Risk & Compliance, a team under the oversight of our Group Company Secretary. Group Risk & Compliance is leading the development and delivery of the Group’s risk management framework and policy framework. These initiatives will play an important role in our transformation journey, supporting colleagues to assess and mitigate risks so we can take full advantage of the opportunities ahead.
One of our greatest opportunities is to harness the full potential of our customer data. As a highly diversified business, we have a huge variety of customers – from subscribers to our newspapers and magazines, to kids browsing Beano, to online genealogists, and more. We have both UK and international compliance obligations and a dynamic array of systems and suppliers, which we continue to develop as we embrace new digital technologies.
The Head of Data Protection’s role will be to accelerate improvements to our Data Protection framework and build a stronger privacy culture, by designing, delivering and embedding new policies, procedures, training and awareness activities across the Group. This is an exciting opportunity to shape and deliver change that will protect our customers, our colleagues, and our wider stakeholder community.
What will you be doing as Head of Data Protection?
Building capability
- Developing, communicating and embedding a comprehensive suite of Data Protection-related policies and procedures across the Group
- Developing simple tools and processes, with digitisation where appropriate, for reporting of personal data breaches and completion of Data Protection Impact Assessments
- Building and delivering a programme of Data Protection training across the Group, including tailored provision for specific roles or colleague populations
Leading and influencing
- Establishing a community of ‘Data Protection Champions’ across the Group to ensure proper accountability for Data Protection at a local level
- Leading the assessment and implementation of Data Protection-related regulatory change, providing practical and pragmatic advice to stakeholders
- Leading the investigation and remediation of personal data breaches, liaising with external counsel where needed and notifying the ICO and data subjects if necessary
- Representing Group Risk & Compliance in project Steering and Working Groups to ensure Data Protection considerations arising through business change are identified and addressed
Delivering strong operational performance
- Leading the identification, assessment, mitigation and reporting of day-to-day Data Protection related risks and issues, working proactively to deliver continuous improvement
- Establishing consistent, commercially aware practices across the Group for obtaining and managing marketing permissions from customers and prospects
- Overseeing the continuous development and improvement of the Group’s privacy policies
Directing, supervising and supporting
- Directing and supervising the work of the Data Protection Manager
- Guiding and overseeing the activities of the Data Protection Champion population
- Coaching and supporting the Data Protection Manager and Data Protection Champions to enable their personal development
- Supporting the Data Governance Council and Artificial Intelligence working group
Setting high professional standards
- Maintaining a strong working knowledge of current and developing Data Protection legislation, supporting guidance and best practices that affect the Group’s activities
- Developing a network of external contacts, for example the ICO and among industry peers, to gain insights into ‘hot topics’ and emerging issues and share knowledge with internal stakeholders where relevant
Requirements
Essential experience:
- A demonstrable track record of performing managerial-level advisory roles in which you have acted as a subject matter expert on GDPR or UK GDPR, Data Protection Act, and PECR
- At least one professional qualification relevant to UK Data Protection legislation, for example CIPP/E or CIPM
- Experience of line managing and developing more junior colleagues
- Experience of designing, developing and continuously improving Data Protection-related policies, procedures and processes
- Experience of leading and influencing Data Protection-related regulatory change
- Experience of reviewing and completing Data Protection-related contractual documents such as DPAs or the UK IDTA (note, a legal background or qualification is not necessary)
- Experience of leading and guiding the business if a data protection breach has been identified
- Experience of dealing with children's data and control frameworks and regulatory requirements
Desirable experience:
- Experience in the use of Artificial Intelligence and Large Language Models
- Experience of Data/Information Governance frameworks and responsibilities
- Experience of records management and protocols
- Experience of delivering Data Protection training and awareness activities to colleagues, whether face-to-face or using alternative solutions (such as e-learning tools)
- Experience of implementing and/or operating Data Protection software tools for the creation of Registers of Processing Activity or data breach reporting
- A working knowledge of international developments in Data Protection regulation and/or overseas regulation such as CPRA or COPPA
The skills you’ll need
- Excellent written and verbal communication skills, with the ability to produce concise and well-structured reports (for example, for management committees)
- Strong stakeholder management and interpersonal skills, with the ability to influence and develop good relationships with colleagues, including senior managers and business leaders
- A can-do, collaborative approach to working with others, with the ability to build effective teams both within and across different functions in the business
- Sound judgment and reasoning, with the ability to find practical, pragmatic ways and solutions for the organisation to meet its Data Protection obligations
- Strong attention to detail, with the ability to set and maintain high quality standards
- The ability to work independently and be ‘hands-on’, in the absence of a large or well-established team
To apply for this role, please follow our online application process and submit a CV and cover letter.
Closing date for applications: 21st August at 12noon.