The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior GDPR Compliance Coordinator / Lead Privacy Analyst
5-8 years of experience in privacy roles, with 2-3 years at a senior level.Skills to master
- Mastering end-to-end DSAR and DPIA processes, leading complex compliance projects, mentoring junior colleagues, and demonstrating strong stakeholder management.
You're ready to move on when
- Successfully led multiple high-impact privacy projects independently.
- Consistently provided expert guidance to business units on complex privacy issues.
- Acted as an informal mentor to junior team members, helping them develop their skills.
- Demonstrated ability to influence cross-functional teams without direct authority.
- 2
Privacy Counsel (from Legal Department)
7-10 years post-qualification experience, with a focus on data protection law.Skills to master
- Translating legal advice into operational processes, understanding privacy technology, and developing a more business-centric approach to risk.
You're ready to move on when
- Provided clear, actionable legal advice on GDPR to business teams.
- Involved in the operationalisation of privacy policies and procedures.
- Demonstrated an interest in privacy programme management beyond pure legal advisory.
- 3
Information Security Manager (with strong privacy focus)
10-15 years in information security, with significant exposure to data privacy.Skills to master
- Deepening knowledge of privacy regulations beyond security controls, developing strong stakeholder management outside of technical teams, and understanding the 'why' behind privacy requirements.
You're ready to move on when
- Successfully managed security programmes with significant data protection components.
- Demonstrated understanding of privacy-by-design principles and their implementation.
- Proactively engaged with privacy teams on incident response and risk assessments.