The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Data Protection Manager / Principal
3-5 years as a Manager/PrincipalSkills to master
- Moving from managing a team and specific workstreams to defining the strategic direction for a larger function. This means developing stronger executive presence, budget management, and cross-functional influence.
You're ready to move on when
- Successfully led a major privacy initiative from conception to completion.
- Consistently delivered on strategic objectives and managed a significant team.
- Demonstrated strong leadership potential and ability to influence senior stakeholders.
- Took ownership of complex regulatory interactions or incident responses.
- 2
From Senior Legal Counsel (Privacy Focus)
5-8 years in a dedicated privacy legal role, often in-houseSkills to master
- Transitioning from providing legal advice to leading an operational privacy programme. This requires developing strong people management skills, budget oversight, and a more pragmatic, business-focused approach to risk management.
You're ready to move on when
- Provided strategic legal advice on complex privacy matters that directly impacted business outcomes.
- Managed significant regulatory inquiries or litigation related to privacy.
- Demonstrated an understanding of operationalising legal requirements within a business context.
- Exhibited leadership potential beyond purely advisory functions.
- 3
From Head of Compliance (with strong privacy remit)
3-6 years as a Head of ComplianceSkills to master
- Deepening specialisation in data protection, moving from a broad compliance remit to a dedicated privacy focus. This involves mastering the nuances of global privacy laws and privacy-specific technologies.
You're ready to move on when
- Successfully managed a significant part of an organisation's compliance function, including privacy.
- Demonstrated ability to build and manage a compliance team.
- Proven track record of navigating complex regulatory environments.
- Showed a particular aptitude and interest in data protection over other compliance areas.