The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Head of Data Protection / Data Protection Officer (DPO)
You'd typically spend 5-8 years in a DPO or Head of role, overseeing a significant privacy programme, before stepping into a Director-level position. You'd have managed a team and dealt with regulatory bodies.Skills to master
- Deep regulatory interpretation, incident response leadership, stakeholder management across all levels, programme budget management, team leadership and development.
You're ready to move on when
- Successfully led multiple regulatory inquiries or audits with positive outcomes.
- Built and scaled a privacy programme from scratch or significantly matured an existing one.
- Consistently met or exceeded privacy KPIs and demonstrated clear risk reduction.
- Received strong feedback on your ability to influence and advise executive leadership.
- 2
Senior Legal Counsel (Privacy Specialisation)
A move from Senior Legal Counsel (with a strong privacy focus) could take 10-15 years, where you'd have advised on complex data protection matters, managed litigation, and influenced policy from a legal perspective.Skills to master
- Translating legal advice into operational strategy, programme management, team leadership, risk quantification, and business enablement.
You're ready to move on when
- Moved beyond purely advisory work to actively shaping operational privacy programmes.
- Demonstrated ability to build and lead non-legal teams.
- Developed a strong commercial acumen alongside legal expertise.
- Proven capability to manage budgets and drive strategic initiatives.
- 3
Director of Information Security / GRC
Coming from an Information Security or GRC Director role, you'd need 12-18 years of experience, with a strong emphasis on how security controls directly support privacy objectives and managing enterprise-wide risk.Skills to master
- Deep dive into GDPR and other privacy regulations, understanding data subject rights, privacy by design principles, and building relationships with privacy-specific regulatory bodies.
You're ready to move on when
- Expanded your focus beyond security to encompass specific privacy legal requirements and rights.
- Demonstrated strong collaboration with privacy teams in previous roles.
- Developed expertise in privacy-specific tools and methodologies (e.g., DPIAs, DSARs).
- Shown a passion for data ethics and responsible data use beyond just security.