The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Information Compliance Analyst (L2) to Senior Information Compliance Director (L3)
3-5 years as an AnalystSkills to master
- Mastering end-to-end DSAR processing, conducting initial policy reviews, identifying compliance gaps, and starting to mentor junior colleagues informally.
You're ready to move on when
- Consistently delivering high-quality work with minimal supervision on routine tasks.
- Proactively identifying issues and proposing practical solutions, not just pointing out problems.
- Demonstrating strong communication skills when dealing with cross-functional peers.
- Taking initiative to learn new regulations and tools beyond immediate job requirements.
- 2
Legal Counsel / Paralegal to Senior Information Compliance Director (L3)
4-7 years in a legal role with a focus on data privacy or information lawSkills to master
- Translating legal theory into operational processes, understanding technology's role in compliance, and developing project management skills.
You're ready to move on when
- A strong desire to move from advisory to implementation and operational roles.
- Demonstrated ability to work collaboratively with non-legal business and technical teams.
- Experience in project-based work, even if not formal project management.
- A clear understanding of how legal risks manifest in information systems.
- 3
IT Security Analyst / Architect to Senior Information Compliance Director (L3)
5-8 years in a security role with exposure to governanceSkills to master
- Deepening knowledge of data privacy regulations, understanding the legal implications of technical controls, and developing strong policy writing skills.
You're ready to move on when
- A keen interest in the 'why' behind security controls (i.e., the regulatory drivers).
- Experience implementing technical controls related to data protection (e.g., DLP, access management).
- Ability to articulate technical concepts to non-technical audiences.
- A desire to move into a more policy and process-focused role, rather than purely technical operations.