The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Mid-Level Privacy Analyst (internal promotion)
2-3 years as a Privacy AnalystSkills to master
- You'd need to have mastered end-to-end DSAR fulfilment, independently conducted multiple DPIAs for medium-risk projects, and consistently contributed to RoPA accuracy. Basically, you're reliably owning processes.
You're ready to move on when
- Consistently delivering high-quality work without significant supervision.
- Proactively identifying and solving routine privacy issues.
- Demonstrating strong communication skills with business stakeholders.
- Showing initiative in taking on more complex tasks.
- 2
Legal Counsel (with privacy specialisation)
5-7 years post-qualification in a law firm or in-house legal teamSkills to master
- You'd have deep legal interpretation skills, experience advising clients on privacy law, and a good grasp of commercial contracts. You'd need to learn the operational side of privacy programmes.
You're ready to move on when
- Strong academic background in law, particularly data protection.
- Experience in a legal practice advising on GDPR/DPA.
- Desire to move into a more operational, hands-on privacy role.
- IAPP CIPP/E certification is usually a must.
- 3
Information Security Specialist (with privacy focus)
5-7 years in InfoSec, moving into privacySkills to master
- You'd have a strong technical background in security controls, risk management, and incident response. You'd need to build up your knowledge of privacy law and its specific applications, beyond just security.
You're ready to move on when
- Proven track record in information security roles.
- Strong understanding of technical controls and their application.
- Demonstrated interest in privacy regulations and their impact.
- Often holds certifications like CISM or CISSP alongside IAPP CIPT.