The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Privacy Analyst (L3)
3-5 years as a Senior AnalystSkills to master
- You'd need to have truly mastered leading complex DPIAs, managing significant DSARs, and mentoring junior team members. You'd also need to show initiative in identifying and proposing new programme areas, rather than just executing existing ones.
You're ready to move on when
- Consistently delivering high-quality, impactful privacy project work with minimal supervision.
- Proactively identifying systemic privacy risks and proposing solutions.
- Demonstrating strong leadership potential and a desire to manage programmes and people.
- Successfully navigating complex stakeholder relationships and influencing outcomes.
- 2
Legal Counsel (Privacy Focus)
5-8 years in a privacy-focused legal roleSkills to master
- You'd need to move beyond purely legal advice to understanding the operationalisation of privacy. This means getting hands-on with privacy tech, understanding data flows, and being able to design practical, implementable programmes, not just interpret the law.
You're ready to move on when
- A strong desire to move from an advisory role to a hands-on programme management role.
- Demonstrable understanding of privacy technology platforms and their capabilities.
- Ability to translate complex legal requirements into clear, actionable business processes.
- Experience in managing projects and coordinating cross-functional teams.
- 3
Information Security Lead with Privacy Experience
6-10 years in InfoSec, with a strong privacy componentSkills to master
- You'd need to deepen your understanding of privacy regulations beyond just security controls. This means focusing on data subject rights, legal bases, and the broader compliance landscape, not just technical safeguards. You'd also need to develop strong stakeholder management skills outside of IT.
You're ready to move on when
- Proven experience in implementing security controls that also address privacy requirements.
- A clear understanding of the regulatory differences between security and privacy.
- Strong communication skills to engage with non-technical business units on privacy matters.
- A desire to lead dedicated privacy programmes and a team.