
How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Data Protection Officer | Manchester
Monex specialises in FX risk management and international payments, helping corporate and institutional clients design tailored FX solutions to navigate currency volatility with confidence. Our team of FX specialists implement well-considered currency strategies, offering dedicated support to help clients manage their payment needs – whether for goods, services, or direct investments.
In 2023, Monex facilitated $309 billion in FX turnover, managed $10.7 billion in assets, and processed 8.5 million transactions. With offices across North America (Canada, the US, and Mexico), Asia (Singapore), and Europe (the UK, Spain, and the Netherlands), we serve over 66,000 clients worldwide.
By combining global reach with deep local market expertise, Monex enhances businesses with a suite of financial solutions and FX market analysis to help optimise efficiency, mitigate currency risk, and protect margins in an increasingly complex financial landscape. Our corporate client experience is further enhanced by our dedicated sector expertise across a range of industries.
Department Overview
The Information Security and Data Protection Governance function supports Monex in protecting client, employee, supplier, and business information and maintaining compliance with applicable data protection, privacy, information security, and financial services regulatory requirements.
The function works across legal entities and jurisdictions to embed privacy by design, maintain data governance records, support data subject rights, oversee personal data breach response, advise on lawful processing, and provide assurance that personal data is handled responsibly and securely.
The role partners closely with Legal, Compliance, Information Security, IT, HR, Risk, Procurement, Operations, Product, and regional business teams to ensure that data protection requirements are understood, documented, implemented, and evidenced across Monex’s global operations.
Job Overview
As Data Protection Officer, you will provide independent, expert data protection oversight and practical guidance across Monex’s international operations. The role is based in Manchester, UK, with a global remit covering the UK, EU, Canada, USA, and Singapore, and is expected to be capable of being formally notified or registered as the DPO with relevant supervisory authorities, including the Spanish AEPD where required.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
You will own and mature the data protection governance framework, including DPIAs, Records of Processing Activities (ROPAs), data subject rights, data breach governance, data protection policies, training, regulatory liaison, and risk-based assurance.
Key Responsibilities & Accountabilities
- Act as the appointed Data Protection Officer for relevant Monex entities, maintaining independence, professional judgement, and direct access to senior management where required.
- Provide expert advice on UK GDPR, EU GDPR, the UK Data Protection Act 2018, PECR, Spanish LOPDGDD requirements, Dutch privacy requirements, Canadian privacy requirements including PIPEDA and Quebec Law 25, applicable US privacy requirements, and Singapore PDPA obligations.
- Be eligible and willing to be notified or registered with relevant supervisory authority registers, including the ICO and Spanish AEPD, and support equivalent DPO/contact-point requirements in other jurisdictions where applicable.
- Own and improve the global data protection governance framework, including policies, standards, procedures, registers, templates, guidance notes, and evidence packs.
- Lead, review, and advise on Data Protection Impact Assessments (DPIAs), Privacy Impact Assessments, Legitimate Interest Assessments, and Transfer Risk Assessments for new suppliers, systems, products, AI use cases, projects, and material changes to processing.
- Create, maintain, and periodically review Records of Processing Activities (ROPAs), data inventories, data-flow maps, lawful basis records, retention references, and records of international data transfers across relevant business areas and entities.
- Support privacy by design and default by engaging early with technology, product, change, procurement, and operational initiatives, ensuring data protection requirements are built into design decisions before go-live.
- Advise on and oversee global personal data breach governance, including assessment of risk to individuals, regulatory notification requirements, data subject communications, evidence retention, and post-incident lessons learned.
- Maintain and improve data subject rights procedures, including access, erasure, rectification, restriction, portability, objection, consent withdrawal, and rights related to automated decision-making/profiling, coordinating responses across jurisdictions.
- Review and advise on supplier data protection due diligence, Data Processing Agreements, controller/processor assessments, subprocessor governance, international transfer mechanisms, and contract clauses in cooperation with Legal, Procurement, and Information Security.
- Monitor internal compliance with data protection laws and Monex data protection policies through risk-based reviews, audits, control testing, issue tracking, and management reporting.
- Design and deliver staff awareness, role-based training, and targeted guidance for teams handling personal data, including HR, Sales, Operations, Compliance, IT, Product, Procurement, and support functions.
- Act as a point of contact for data subjects and supervisory authorities, coordinating with Legal, Compliance, and regional specialists where local regulatory nuance or external counsel input is required.
- Maintain a data protection risk register, track remediation actions, and provide clear, risk-based reporting to senior management, relevant committees, and governance forums.
- Keep up to date with changes in privacy law, regulator guidance, enforcement trends, and industry practice, translating changes into practical actions for Monex.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Business Knowledge / Technical Skills
- Significant hands-on experience in data protection, privacy governance, regulatory compliance, or information governance in a regulated or complex international environment.
- Deep working knowledge of UK GDPR and EU GDPR, including Articles 30, 35, 37, 38, and 39, and practical experience applying these requirements in business operations.
- Strong practical experience completing DPIAs, ROPAs, LIAs, DSRs, privacy notices, data breach assessments, data transfer assessments, and supplier data protection reviews.
- Proven ability to draft, review, and implement data protection policies, procedures, training, and governance reporting at a global level.
- Good understanding of information security, third-party risk management, data classification, retention, access management, incident management, and privacy-by-design principles.
- Ability to interpret legal and regulatory requirements and translate them into clear operational controls, pragmatic guidance, and business-friendly recommendations.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills