Rodeo
Get started

Fortius Clinic

Data Protection Officer

London
Posted 26 days ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Affidea UK and Fortius Clinic are looking for an experienced and highly motivated Data Protection Officer (DPO) to act as our organisation’s designated DPO under the UK GDPR and Data Protection Act 2018.

This is a key leadership role with independent oversight, direct access to senior leadership, and functional alignment with the Group Data Protection Officer. You will play a critical role in embedding a culture of data protection excellence across the organisation, ensuring the consistent implementation of Affidea’s group data protection framework within the UK.

Key Responsibilities

Governance & Compliance

  • Act as the named DPO under UK GDPR and the Data Protection Act 2018
  • Develop, maintain, and continuously improve data protection policies, frameworks, and procedures
  • Monitor compliance, including NHS Data Security and Protection (DSP) Toolkit requirements
  • Maintain and oversee the Record of Processing Activities (ROPA)
  • Lead and oversee Data Protection Impact Assessments (DPIAs)
  • Ensure implementation of data protection standards, privacy notices, retention frameworks, and local controls
  • Maintain clear documentation and escalate significant risks to senior leadership and Group DPO

Regulatory Engagement

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

  • Serve as the primary contact for the Information Commissioner’s Office (ICO)
  • Manage regulatory audits, investigations, and enquiries
  • Track regulatory developments and provide expert guidance

Data Subject Rights & Incidents

  • Oversee responses to DSARs and other data subject rights requests
  • Lead data breach response, including assessment and notification where required
  • Maintain and report on incident and breach logs

Third Parties & Contracts

  • Advise on data processing agreements, data sharing agreements, and international data transfers
  • Conduct due diligence on third-party processors
  • Provide data protection input into procurement, contracts, and technology implementation

Culture, Training & Advisory

  • Deliver and oversee tailored data protection training across the organisation
  • Advise clinical, operational, and digital teams on data protection matters
  • Promote privacy by design and default
  • Support governance around AI use and emerging technologies
  • Participate in or chair Information Governance forums

Qualifications

About You

  • Recognised data protection qualification (e.g. CIPP/E, BCS Certificate in Data Protection, IAPP)
  • Full UK driving licence
  • Willingness to travel regularly across UK sites

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Experience

  • Strong expertise in UK GDPR and Data Protection Act 2018
  • Experience engaging with the ICO
  • Hands-on experience managing:
    • DPIAs
    • ROPAs
    • DSARs
    • Data breaches
  • Experience working in a regulated environment (healthcare preferred)
  • Knowledge of NHS information governance standards (DSP Toolkit, Data Security Standards)
  • Proven ability to influence senior stakeholders
  • Experience embedding privacy in digital, IT, or AI-driven projects

Skills & Competencies

  • Strong communication and stakeholder management skills
  • Ability to translate legal requirements into practical, risk-based advice
  • High attention to detail with strong documentation capabilities
  • Proactive, solutions-focused mindset
  • Solid understanding of IT systems and cybersecurity fundamentals
  • Proficiency in Microsoft 365 and digital tools

Why Join Us?

  • Play a strategic, high-impact role in a leading healthcare organisation
  • Work closely with senior leadership and contribute to organisational governance
  • Influence how data protection supports innovation, including digital and AI initiatives
  • Be part of a collaborative environment committed to high standards of care and compliance
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

UK GDPR
Data Protection Act 2018
DPIA
ROPA
DSAR
Stakeholder Management
Regulatory Compliance
Information Governance
Privacy By Design
Risk Management
Cybersecurity Fundamentals
Microsoft 365
Third-Party Due Diligence
Data Breach Management
Policy Development
Legal Translation

Location

London, England, United Kingdom

Sign up to applySee more jobs like this