Caravan and Motorhome Club
Data Protection Officer (DPO)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Key Tasks / Accountabilities
Serve as statutory DPO under UK data protection law for the Club and Alan Rogers Travel Group, acting as primary liaison for the Information Commission’s Office (ICO), other regulators and data subjects.
- Monitor regulatory change, ICO guidance, legislative updates and technology trends to keep data security policies and operational standards current.
- Own the Privacy Policy suite and maintain privacy governance, including the Master Record of Privacy Statements, Records of Processing Activities (ROPAs), Legitimate Interest Assessments (LIAs) and Data Protection Impact Assessments (DPIAs).
- Act as the final escalation and approval point for data subject requests, law enforcement (and other) disclosures and data protection complaints, ensuring timely and compliant resolution, completed to a high standard.
- Oversee the continued development, implementation and maintenance of data security policies, procedures and standards across the organisation.
- Provide, or oversee the provision of, data protection advice for projects and initiatives, ensuring Privacy by Design is applied and DPIAs are completed where necessary.
- Using the ICO Accountability Tracker, ensure the DSCT monitors data protection compliance, advising and supporting the Club to meet its legal duties, implement proportionate safeguards and protect data subjects' rights.
- Lead, motivate and develop the DSCT team members with personal development plans, career growth support, opportunities and task delegation, and performance management.
- Manage recruitment and onboarding processes for permanent and contract team members, as required.
- Continue to develop a culture of continuous learning and proactive compliance across all departments.
- Provide strategic direction for all data protection and data security training and awareness programs.
- Oversee all data security incident management, directly handling incidents when necessary, and ensure adherence to legal and regulatory reporting timelines. Report breaches to the Club’s Directors, the ICO and/or relevant law enforcement agencies as required.
- Report data security activities, data subject request completion statistics, breach investigations and risk posture to the Directors and members of the Senior Leadership Team (SLT) via the quarterly meeting of the Data Security Protection Group (DSPG).
- Promote an open, 'no-blame' reporting culture while ensuring corrective solutions and post-incident improvements are implemented.
- Maintain strategic oversight of PCI DSS compliance, collaborating closely with the Information Systems (IS) Security Specialist, the Club’s acquiring bank and the external Qualified Security Assessor (QSA), as required.
- Ensure IS teams schedule and remediate regular vulnerability and ASV scans, and that penetration tests are carried out annually or when significant change occurs.
- Be responsible for the completion, sign off and submission of annual PCI DSS Self-Assessment Questionnaires (SAQs) to the Club’s acquiring bank, ensuring evidence of compliance is maintained and documented.
- Ensure all payment channels are PCI DSS compliant and that new channels or changes to existing channels are assessed and appropriate security controls introduced.
- Partner with the Club’s Procurement team and external legal counsel to ensure robust data protection, PCI DSS and data security clauses are embedded in supplier contracts and non-disclosure agreements.
- Drive privacy and data security requirements developed by the DSCT to be embedded in all relevant projects and initiatives, as well as considered for changes to existing processes.
- Have responsibility for the continued improvement of ‘light touch’ business continuity frameworks, ensuring alignment between data protection requirements, data security policies, IS disaster recovery and business continuity plans.
- Oversee the management and documentation of team representation on Gold and Silver Business Continuity groups.
- Actively push for robust privacy and data security standards by authoring Club-wide communications and presenting at departmental and team meetings.
- Manage budgets and contractual agreements for third-party vendors supporting the DSCT’s activities, such as consultants.
- Maintain active membership in key organisational forums, including the Club's Google User Group, AI Governance Board and Cross Functional Board, to maintain continuous awareness of upcoming initiatives, emerging risks and business change.
- Serve as the primary point of contact for the team's third-party Privacy Management System, tracking updates and ensuring thorough pre-release testing.
- Act as the Product Owner for the Club's secure email product, overseeing contract management, cost controls and feature rollouts to license holders.
- Attend relevant external industry meetings and conferences to keep knowledge current and stay up to date with legislation, best practice and emerging threats.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Skills And Experience Required


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Proven track record in a senior data protection, privacy, information security or compliance leadership role, with demonstrable experience of managing and mentoring a team.
- Expert knowledge of UK data protection legislation (e.g. UK GDPR, Data Use and Access Act 2025, DPA 2018, PECR) and ICO guidance.
- Direct experience of liaising with regulatory bodies such as the ICO.
- Solid awareness of ISO 27001 information security best practice and controls.
- One or more recognised professional privacy and/or information security qualifications (e.g. CIPP/E, CIPM, UK GDPR Practitioner, Practitioner Certificate in Data Protection (PC.dp), CISM, CISSP).
- Strong commercial awareness, sound negotiation skills and the ability to influence organisational dynamics at all levels.
- Substantial experience of managing privacy risks associated with complex IT systems, and contract negotiations.
- First rate attention to detail, coupled with an ability to interpret regulations, standards and privacy and security best practice and implement them pragmatically across the Club.
- Exceptional written and verbal communication skills, with proven ability to deliver clear messages and advice under pressure, at all levels and with third parties.
- Quick learner with extremely confident general IT skills, including the use of Google Workspace (Gmail, Drive and Sheets etc.) and/or Microsoft Office (Outlook, Word and Excel etc.)
- Passionate, committed and enthusiastic with a strong desire to drive change.
Desirable Skills And Experience Required
- Experience of working with or managing corporate business continuity frameworks.
- Hands-on experience with privacy management platforms, such as OneTrust, working with AI tools and using redaction software such as Adobe Acrobat.
- Awareness of Financial Conduct Authority (FCA) regulations.
About the Employer
The Caravan and Motorhome Club is committed to employing a diverse workforce. All applications are treated equally and we recruit purely on the basis of skills and experience. We know our greatest strength is our people, so differences are celebrated, and we strive to create an environment where colleagues feel respected and valued for their unique potential.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London