The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Privacy by Design Specialist (L2)
2-3 years at L2Skills to master
- Independently managing medium-risk privacy reviews, taking ownership of routine processes, identifying issues and proposing solutions, and beginning to informally guide new joiners.
You're ready to move on when
- Consistently delivers accurate and timely privacy assessments for standard projects.
- Proactively identifies and escalates complex privacy issues with well-reasoned analyses.
- Demonstrates a solid understanding of core privacy regulations and our internal policies.
- Has started to mentor junior colleagues or new team members informally.
- 2
Security Architect / Engineer (with privacy focus)
3-5 years in security, then 2-3 years focused on privacySkills to master
- Deep technical understanding of system architecture, security controls, and the SDLC, combined with a growing knowledge of privacy regulations and risk assessment methodologies. You'd need to bridge the gap between security and privacy.
You're ready to move on when
- Has a strong track record of designing and implementing security controls in complex environments.
- Has actively sought out opportunities to incorporate privacy into their security work (e.g., data minimisation in system design).
- Has completed privacy certifications (e.g., CIPT, CIPP/E) to formalise their privacy knowledge.
- Can articulate the differences and overlaps between security and privacy risks.
- 3
Legal Counsel (Privacy specialism)
3-5 years in privacy law, then 2-3 years in a more technical privacy roleSkills to master
- A deep understanding of privacy law and its application, coupled with a strong aptitude for technology and an ability to translate legal requirements into technical specifications. You'd need to get comfortable with system diagrams and engineering discussions.
You're ready to move on when
- Has provided clear, actionable legal advice on complex privacy matters.
- Has a keen interest in technology and understands how software is built and deployed.
- Has actively collaborated with engineering and product teams on privacy implementation.
- Can demonstrate an ability to move beyond purely advisory work to more hands-on design and implementation.