Cognisys
Data Protection Consultant - UK

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location: Leeds (Hybrid - but flexible to discuss)
Salary: £55k per annum + benefits
About Us
At Cognisys, we help organisations build confidence in their cyber security, governance and compliance. Through our specialist teams, we provide Penetration Testing, Governance, Risk & Compliance (GRC) consultancy and Managed Security Services that enable our clients to operate securely and confidently.
Our people are trusted advisors who work in partnership with clients to solve real business challenges. We pride ourselves on delivering pragmatic, commercially focused advice that creates lasting value, underpinned by our values of Together, Ownership, Momentum, and Excellence.
As we continue to grow, we're looking for an experienced Data Protection Consultant (Virtual DPO) to join our expanding GRC team.
About The Role
As a Data Protection Consultant, you'll act as a trusted privacy advisor, delivering Virtual Data Protection Officer (DPO) services and data protection consultancy to a diverse portfolio of approximately 10–15 clients.
You'll help organisations strengthen their privacy governance, navigate complex regulatory requirements and build practical compliance programmes that support their wider business objectives. Working across multiple industries and organisations, no two days will be the same.
This is a highly client-facing consultancy role, requiring someone who enjoys variety, can quickly build trusted relationships with senior stakeholders and thrives in a fast-paced environment where balancing multiple client priorities is the norm.
Alongside supporting our clients, you'll also play a key role in maintaining and enhancing Cognisys' own internal privacy programme, ensuring we continue to uphold the high standards we deliver to our clients.
Key Responsibilities
Virtual Data Protection Officer Services
- Act as the appointed Virtual Data Protection Officer for a portfolio of clients.
- Build trusted relationships with senior stakeholders and leadership teams.
- Provide strategic advice on privacy, governance and regulatory compliance.
- Attend governance meetings and represent Cognisys as a trusted advisor.
Data Protection & Privacy Consultancy
- Advise clients on UK GDPR, the Data Protection Act 2018, PECR and wider privacy legislation.
- Translate regulatory requirements into practical, commercially balanced solutions.
- Develop, review and improve privacy policies, procedures and governance documentation.
- Support organisations in embedding Privacy by Design across projects and business processes.
Privacy Risk & Compliance
- Conduct privacy health checks, compliance reviews and gap assessments.
- Lead or support Data Protection Impact Assessments (DPIAs) and Legitimate Interest Assessments (LIAs).
- Review Records of Processing Activities (RoPA) and data retention practices.
- Identify privacy risks and recommend pragmatic mitigation strategies.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Incident & Regulatory Support
- Advise clients during personal data breaches and security incidents.
- Support breach assessments and regulatory notification decisions.
- Assist organisations with enquiries from the Information Commissioner's Office (ICO).
Data Subject Rights
- Advise clients on Subject Access Requests (SARs) and wider data subject rights.
- Review complex requests and provide practical guidance.
- Support clients with privacy complaints and regulatory enquiries.
Client Consultancy
- Deliver consultancy engagements remotely and on client sites.
- Produce high-quality reports, recommendations and action plans.
- Present findings and recommendations confidently to senior stakeholders.
- Identify opportunities to introduce additional Cognisys cyber security and GRC services where appropriate.
Supporting Data Protection at Cognisys
In addition to client consultancy, you'll help shape and maintain Cognisys' own internal privacy programme.
You'll:
- Act as the internal Data Protection subject matter expert.
- Maintain and improve Cognisys' data protection framework, policies and procedures.
- Lead internal Data Protection Impact Assessments (DPIAs).
- Maintain and review our Records of Processing Activities (RoPA).
- Support internal data subject rights requests and privacy enquiries.
- Advise on supplier due diligence, data sharing arrangements and new business initiatives.
- Support the investigation and management of personal data incidents.
- Deliver internal privacy awareness training.
- Monitor regulatory developments and recommend improvements.
- Collaborate with Information Security, People and Legal teams to embed privacy across the business.
Training & Knowledge Sharing
- Deliver engaging privacy awareness workshops and training sessions.
- Help clients foster a positive culture of accountability and privacy.
- Share best practice and support colleagues across the wider GRC team.
Continuous Improvement
- Stay up to date with developments in privacy legislation and industry best practice.
- Contribute to the continued development of Cognisys' privacy consultancy services.
- Support the ongoing growth of the GRC practice.
Requirements
You'll combine strong technical expertise with excellent consultancy, communication and stakeholder management skills.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
You'll enjoy building long-term client relationships, balancing multiple priorities and delivering pragmatic advice that helps organisations improve their privacy maturity.
Essential
- Minimum of five years' experience delivering data protection consultancy or privacy advisory services within a consultancy or professional services environment.
- Experience acting as, or supporting, an internal or outsourced Data Protection Officer.
- Excellent knowledge of UK GDPR, the Data Protection Act 2018 and PECR.
- Experience conducting privacy compliance reviews, gap assessments and Data Protection Impact Assessments (DPIAs).
- Experience advising senior stakeholders on privacy risks and regulatory obligations.
- Excellent written communication and report writing skills.
- Strong presentation and stakeholder management skills.
- Excellent organisational skills with the ability to manage multiple client engagements simultaneously.
- A pragmatic, commercially focused approach to problem solving.
Desirable
- IAPP (CIPP/E, CIPM or CIPT), BCS or equivalent privacy qualification.
- Knowledge of ISO 27001 and ISO 27701.
- Experience working alongside Cyber Security or Information Security teams.
- Experience delivering privacy training and awareness sessions.
- Knowledge of international privacy legislation.
Why Join Us?
Joining Cognisys means becoming part of a collaborative team that's passionate about delivering exceptional outcomes for clients while supporting one another's success.
In return, we offer:
- Hybrid and flexible working.
- 25 days annual leave plus public holidays.
- An additional day off to celebrate your birthday.
- Professional development with dedicated learning and certification support.
- Employee Wellness Hub through Kara Connect.
- The opportunity to work alongside industry experts across Cyber Security and GRC.
- A collaborative culture where you'll be empowered to make a meaningful impact and continue developing your career.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Senior Recruiter, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.group
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location