Rodeo
Get started

Medloop Ltd.

Data Protection Officer - Digital Health (part-time, retainer)

United Kingdom
Posted about 12 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Medloop

With prevention as its core focus, Medloop is a tech-enabled provider, on a mission to transform the relationship between patients and doctors. By leveraging patient data and best preventive practices, Medloop offers a smart cloud-based doctor desktop and patient mobile application to enrich the relationship between doctors and patients. Medloop has raised over €8M from Kamet and the AXA group.

Role Overview

As our Data Protection Officer, you will be the guardian of patient privacy and the primary architect of our data governance framework. You will bridge the gap between complex healthcare regulations (like GDPR, or local equivalents) and agile product development. Your mission is to ensure that "Privacy by Design" is baked into every feature we ship.

Key Responsibilities

  • Compliance Leadership: Act as the primary point of contact for supervisory authorities and data subjects. Ensure the venture remains compliant with GDPR and other relevant digital health regulations.
  • Privacy by Design: Collaborate with Product and Engineering teams during the SDLC (Software Development Life Cycle) to ensure privacy controls are integrated into new health features, AI models, and data integrations.
  • Risk Assessment: Lead and manage Data Protection Impact Assessments (DPIAs), Data Protection Agreements, IDTA, TRA for high-risk processing activities, particularly those involving sensitive clinical or genetic data.
  • Policy Management: Create, maintain, and enforce internal data protection policies, including data retention schedules, subject access request (SAR) protocols, and incident response plans.
  • Monitoring & Auditing: Conduct regular internal audits to ensure data processing activities align with the Record of Processing Activities (RoPA).
  • Vendor Due Diligence: Evaluate the security and privacy posture of third-party partners (e.g., cloud providers, EHR integrations, and wearable device manufacturers).
  • Training & Culture: Foster a privacy-first culture by providing engaging, role-specific training for clinical, technical, and marketing staff.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Required Qualifications

  • Experience: 5+ years in privacy/data protection, with at least 2 years specifically within Digital Health, MedTech, or BioTech.
  • Legal & Regulatory Mastery: Deep expertise in GDPR and data processing activities including processing of special category data, offshore.
  • Technical Literacy: Comfort discussing encryption, anonymization/pseudonymization techniques, and API security with engineers.
  • Certifications: CIPP/E, CIPM, or CIPT (IAPP) are highly preferred.
  • Communication: The ability to translate "legalese" into actionable requirements for developers and clear value propositions for stakeholders.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Attributes

  • Experience scaling a startup through Series B or beyond.
  • Familiarity with AI/ML ethics and the regulatory landscape for "Software as a Medical Device" (SaMD).
  • Proactive problem-solver who views privacy as a competitive advantage rather than a roadblock.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

United Kingdom

Sign up to applySee more jobs like this