Byoma
Privacy & Data Governance Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Hi, we’re BYOMA 👋 We’re one of the world’s fastest-growing beauty brands. We have applied the research, science, and credibility of dermatologist-backed brands and supercharged it with the efficiency and results of clinically effective, ingredient-led brands. We’re on a mission to democratize and demystify beauty by empowering consumers to make smart, informed and educated choices. BYOMA was built on four fundamental principles; Efficacy, Accessibility, Education, Engagement, and these inform, inspire and underpin everything we do. We’re committed to delivering the most efficacious products to our consumer and our dedication to accessibility and education have led to us becoming the #1 fastest-growing skincare brand in the world, and a top 10 skincare brand across all our key retail partners. As a people-powered business, none of this would have been possible without our incredible team who are committed to achieving our BYOMA vision: to build better beauty and inspire positive change. Join us as we build an inclusive community, because let’s face it, barriers aren’t beneficial for anything other than your skin.
Job Title
Privacy & Data Governance Manager
Department
IT, Data & Business Intelligence
Reporting Manager
Head of Data & BI / Data Protection Officer
Role Banding
3
Location
Glasgow, UK Head Office
Direct Reports (Number + Title)
0
BYOMA is growing quickly across multiple markets, systems and customer touchpoints. That makes privacy and data governance more than a compliance requirement. It is part of how we protect customer trust, make better decisions and scale responsibly. BYOMA’s data function is young and growing. Although small, we deliver enterprise-grade capability and transformation and were recently nominated for Data Team of the Year at the British Data Awards. As we scale, we need a hands-on Privacy & Data Governance Manager to take operational ownership of our privacy programme and help build the governance framework around our growing data estate. This is a delivery role, not a purely advisory one. You will own the day-to-day running of our privacy compliance, including our Record of Processing Activities, data subject and consumer rights requests, privacy notices, DPIAs, vendor due diligence and core privacy documentation. Alongside this, you will help define and maintain the governance standards that shape how BYOMA classifies, retains, accesses and controls data across the business. The role works closely with the Head of Data & BI, who is also BYOMA’s Data Protection Officer. The DPO sets direction and retains statutory responsibility. You make the programme run. Privacy and data governance are closely connected at BYOMA. A good ROPA, clear data maps and a useful data catalogue all depend on understanding what data we hold, where it moves, who has access to it, how long we keep it and why. This role brings those activities together, so our documentation, controls and ways of working stay current as the business grows.
Records, Data Mapping and Privacy Documentation
- Own and maintain BYOMA’s Record of Processing Activities, ensuring it reflects how the business uses personal data.
- Maintain associated registers, including the sub-processor register and data protection documentation.
- Map personal data flows across business areas, systems, vendors and jurisdictions.
- Document what data we hold, where it is processed, who it is shared with, the lawful basis for processing and any international transfer considerations.
- Keep documentation to the standard expected under UK GDPR Article 30 and equivalent consumer privacy disclosure expectations in relevant US markets.
- Work with business teams so privacy documentation is updated as systems, vendors, processes and marketing activities change.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Data Governance
- Own and maintain BYOMA’s data classification approach, ensuring the sensitivity of key data assets is documented and understood.
- Develop and maintain retention schedules, working with system owners to ensure they are practical and applied.
- Coordinate periodic access reviews across key platforms so permissions reflect current business roles and responsibilities.
- Work with the DPO to define governance standards for classification, retention, access control, data ownership and documentation, and own them day to day once agreed.
- Support the development of Microsoft Purview, or equivalent tooling, as the backbone for classification, retention, eDiscovery, DLP and data governance.
- Coordinate a lightweight data governance forum so decisions about data are made deliberately and consistently.
- Work closely with data engineering so governance requirements are understood and built into how the data platform operates.
User Rights and Consumer Requests
- Own the end-to-end handling of data subject access requests and consumer rights requests.
- Manage requests relating to access, deletion, correction, restriction, objection and relevant US consumer rights.
- Ensure requests are handled within statutory timeframes and in line with BYOMA’s documented processes.
- Verify requester identity and manage authorised agent requests appropriately.
- Build and refine repeatable processes so request handling remains consistent as volumes grow.
- Keep records of requests, decisions and outcomes.
Policies, Notices and Assessments
- Maintain and update BYOMA’s privacy policies, notices and disclosures across the UK, EU and US, keeping them accurate as law and practice evolve.
- Keep cookie notices, consent records and marketing consent documentation aligned with how the business operates.
- Conduct DPIAs and legitimate interests assessments for new systems, tools, products, campaigns and processing activities.
- Translate privacy requirements into practical business actions.
- Work with the DPO and external advisers where specialist legal advice is required.
Vendors, Contracts and Third Parties
- Conduct privacy and data protection due diligence on vendors and processors.
- Review data processing agreements and support contract review from a privacy and governance perspective.
- Maintain oversight of processors and sub-processors.
- Work with legal, procurement and business owners to ensure vendor processing is documented, risk-assessed and appropriately controlled.
- Support international transfer assessments where relevant.
US Privacy Developments
- Track US state privacy developments that may affect BYOMA, including CCPA/CPRA and other relevant consumer privacy laws.
- Coordinate with the DPO and external advisers to understand the practical implications for BYOMA.
- Translate US privacy requirements into practical process updates, notices and disclosures, working with the DPO and external advisers where needed.
- Support a risk-based approach to reducing privacy, regulatory and customer trust risks.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Training, Awareness and Business Partnership
- Work with teams across marketing, e-commerce, customer service, sales, operations, IT and data to embed privacy and good data practice into day-to-day work.
- Design and deliver practical privacy and data-handling training.
- Help colleagues understand when to involve privacy, how to handle personal data and how to escalate issues.
- Promote a culture where personal data and business data are managed responsibly.
Risk, Incidents and Regulatory Change
- Support breach and incident response, including logging, initial assessment, evidence gathering and escalation to the DPO.
- Assist the DPO with notification assessments and documentation.
- Monitor relevant developments in UK, EU and US privacy law.
- Flag changes that could affect BYOMA’s processes, policies, vendors or customer-facing disclosures.
- Support audit readiness and ongoing improvement of BYOMA’s privacy and governance controls.
What we’re looking for:
Essential
- Three or more years’ experience in a privacy, data protection, information governance or compliance role.
- Strong working knowledge of UK GDPR, EU GDPR and PECR.
- Practical experience handling DSARs or equivalent rights requests end to end.
- Experience maintaining a ROPA, data inventory, processing register or equivalent documentation.
- Experience documenting how data moves through a business — systems, vendors, teams and purposes — rather than working from documentation someone else produced.
- Ability to turn legal, technical or policy requirements into practical business processes.
- Comfortable working with vendors, reviewing DPAs and coordinating privacy input into supplier assessments.
Desirable
- Experience with US privacy law, particularly CCPA/CPRA.
- Awareness of other US state consumer privacy laws or biometric privacy requirements.
- CIPP/E, CIPM or CIPP/US certification, or actively working towards one.
- Practical data governance experience — cataloguing, classification, retention scheduling, access reviews or governance forums.
- Experience working in a Microsoft 365 environment, including SharePoint and Teams.
- Experience with Microsoft Purview for classification, retention, eDiscovery, DLP or data governance.
- Experience in e-commerce, retail, FMCG, beauty, consumer goods or a consumer brand.
- Familiarity with analytics and marketing technology — GA4, consent management platforms, advertising pixels or CRM.
- Data analysis knowledge, or confidence working alongside data engineers and technical teams.
- Experience delivering training or awareness programmes.
- Exposure to a multi-entity or international group structure.
Equal opportunities for everyone
BYOMA is an equal opportunity employer. We value a culture of inclusion and diversity within our team. We are committed to maintaining a workplace free from prohibited employment conduct, including discrimination based on age, color, disability, marital or parental status, national origin, race, religion, sex, sexual orientation, gender identity, veteran status or any other legally protected status in accordance with applicable federal, state and local laws. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage. 😊
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills